Managing the introduction of information security awareness programmes in organisations
نویسندگان
چکیده
Received: 22 November 2011 Revised: 05 May 2012 2nd Revision: 30 November 2012 3rd Revision: 15 July 2013 Accepted: 15 August 2013 Abstract Several studies explore information security awareness focusing on individual and/ or organisational aspects. This paper argues that security awareness processes are associated with interrelated changes that occur at the organisational, the technological and the individual level. We introduce an integrated analytical framework that has been developed through action research in a public sector organisation, comprising actor-network theory (ANT), structuration theory and contextualism. We develop and use this framework to analyse and manage changes introduced by the implementation of a security awareness programme in the research setting. The paper illustrates the limitations of each theory (ANT, structuration theory and contextualism) to study multi-level changes when used individually, demonstrates the synergies of the three theories, and proposes how they can be used to study and manage awareness-related changes at the individual, organisational and technological level. European Journal of Information Systems advance online publication, 1 October 2013; doi:10.1057/ejis.2013.27
منابع مشابه
Measures for improving information security management in organisations: the impact of training and awareness programmes
Security breaches have attracted corporate attention and major organisations are now determined to stop security breaches as they are detrimental to their success. Users’ security awareness and cautious behaviour play an important role in information security both within and outside the organisation. Arguably the most common factor contributing to these breaches is that of human behaviour towar...
متن کاملImproving Security Awareness and Training through Computer-based Training
Security awareness is a critical issue for all organisations that depend upon information technology. However, significant survey evidence suggests that the issue is often given inadequate attention in modern organisations, leading to problems through security incidents. This paper considers various means that can be used to instil greater awareness, and argues that the most effective method is...
متن کاملExploring the Link Between Behavioural Information Security Governance and Employee Information Security Awareness
This paper explores the relation between a set of behavioural information security governance factors and employees’ information security awareness. To enable statistical analysis between proposed relations, data was collected from two different samples in 24 organisations: 24 information security executives and 240 employees. The results reveal that having a formal unit with explicit responsib...
متن کاملSmartphone information security awareness: A victim of operational pressures
Smartphone information security awareness describes the knowledge, attitude and behaviour thatemployeesapply to thesecurityof theorganisational information that theyaccess,process and store on their smartphone devices. The surge in the number of smartphone devices connecting to organisational systems and used to process organisational data has enabled a new levelof operational efficiency.Whilee...
متن کاملTowards an Intelligence-Driven Information Security Risk Management Process for Organisations
Three deficiencies exist in information security under prevailing practices: organisations tend to focus on compliance over protection; to estimate risk without investigating it; and to assess risk on an occasional (as opposed to continuous) basis. These tendencies indicate that important data is being missed and that the situation awareness of decision-makers in many organisations is currently...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- EJIS
دوره 24 شماره
صفحات -
تاریخ انتشار 2015