Managing the introduction of information security awareness programmes in organisations

نویسندگان

  • Aggeliki Tsohou
  • Maria Karyda
  • Spyros Kokolakis
  • Evangelos A. Kiountouzis
چکیده

Received: 22 November 2011 Revised: 05 May 2012 2nd Revision: 30 November 2012 3rd Revision: 15 July 2013 Accepted: 15 August 2013 Abstract Several studies explore information security awareness focusing on individual and/ or organisational aspects. This paper argues that security awareness processes are associated with interrelated changes that occur at the organisational, the technological and the individual level. We introduce an integrated analytical framework that has been developed through action research in a public sector organisation, comprising actor-network theory (ANT), structuration theory and contextualism. We develop and use this framework to analyse and manage changes introduced by the implementation of a security awareness programme in the research setting. The paper illustrates the limitations of each theory (ANT, structuration theory and contextualism) to study multi-level changes when used individually, demonstrates the synergies of the three theories, and proposes how they can be used to study and manage awareness-related changes at the individual, organisational and technological level. European Journal of Information Systems advance online publication, 1 October 2013; doi:10.1057/ejis.2013.27

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Measures for improving information security management in organisations: the impact of training and awareness programmes

Security breaches have attracted corporate attention and major organisations are now determined to stop security breaches as they are detrimental to their success. Users’ security awareness and cautious behaviour play an important role in information security both within and outside the organisation. Arguably the most common factor contributing to these breaches is that of human behaviour towar...

متن کامل

Improving Security Awareness and Training through Computer-based Training

Security awareness is a critical issue for all organisations that depend upon information technology. However, significant survey evidence suggests that the issue is often given inadequate attention in modern organisations, leading to problems through security incidents. This paper considers various means that can be used to instil greater awareness, and argues that the most effective method is...

متن کامل

Exploring the Link Between Behavioural Information Security Governance and Employee Information Security Awareness

This paper explores the relation between a set of behavioural information security governance factors and employees’ information security awareness. To enable statistical analysis between proposed relations, data was collected from two different samples in 24 organisations: 24 information security executives and 240 employees. The results reveal that having a formal unit with explicit responsib...

متن کامل

Smartphone information security awareness: A victim of operational pressures

Smartphone information security awareness describes the knowledge, attitude and behaviour thatemployeesapply to thesecurityof theorganisational information that theyaccess,process and store on their smartphone devices. The surge in the number of smartphone devices connecting to organisational systems and used to process organisational data has enabled a new levelof operational efficiency.Whilee...

متن کامل

Towards an Intelligence-Driven Information Security Risk Management Process for Organisations

Three deficiencies exist in information security under prevailing practices: organisations tend to focus on compliance over protection; to estimate risk without investigating it; and to assess risk on an occasional (as opposed to continuous) basis. These tendencies indicate that important data is being missed and that the situation awareness of decision-makers in many organisations is currently...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • EJIS

دوره 24  شماره 

صفحات  -

تاریخ انتشار 2015