Measuring organizational information security awareness in South Africa

被引:5
|
作者
Kritzinger, Elmarie [1 ]
Da Veiga, Adele [1 ]
van Staden, Wynand
机构
[1] Univ South Africa, Informat Syst Dept, Pretoria, South Africa
来源
INFORMATION SECURITY JOURNAL | 2023年 / 32卷 / 02期
关键词
HAIS-Q; information security awareness; validation; measuring; organizational culture; QUESTIONNAIRE; CULTURE; BEHAVIOR;
D O I
10.1080/19393555.2022.2077265
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information is a valuable resource that organization may utilize in the current business environment. It is critical to comprehend the importance of information protection, as it safeguards the lifeline of the organization. All employees within organization should be aware of the organizational information security culture. Organizations should promote an information security awareness culture, so as to secure data as part of their critical infrastructure. Organizations should monitor and measure information security awareness levels among employees, with a number of international instruments. However, the validity of those instruments has not yet been determined in the South African context. As a consequence, the aim of this article is to validate one internationally accepted measurement instrument - the Human Aspects of Information Security-Questionnaire (HAIS-Q) in South Africa. The research sought to determine employees' awareness levels, in order to make recommendations aimed at improving awareness in organizations. A survey was conducted whereby the data from 356 respondents were collected across industries, with a web-based questionnaire. To determine the factor structure of the scale under investigation, an exploratory factor analysis (EFA) and Cronbach's alpha was used to establish the internal reliability of the HAIS-Q. T-tests and ANOVAs were used to identify significant differences between demographic groups.
引用
收藏
页码:120 / 133
页数:14
相关论文
共 50 条
  • [1] Evaluating Cyber Security Awareness in South Africa
    Grobler, Marthie
    van Vuuren, Joey Jansen
    Zaaiman, Jannie
    PROCEEDINGS OF THE 10TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2011, : 113 - 121
  • [2] Information security education in South Africa
    Futcher L.
    Schroder C.
    Von Solms R.
    Information Management and Computer Security, 2010, 18 (05): : 366 - 374
  • [3] MEASURING OF THE INFORMATION SECURITY AWARENESS OF THE FRESHMEN STUDENTS IN SLOVAKIA
    Kiss, Gabor
    13TH INTERNATIONAL TECHNOLOGY, EDUCATION AND DEVELOPMENT CONFERENCE (INTED2019), 2019, : 8668 - 8674
  • [4] Lessons Learned from an Organizational Information Security Awareness Campaign
    Scrimgeour, Juan-Marc
    Ophoff, Jacques
    INFORMATION SECURITY EDUCATION: EDUCATION IN PROACTIVE INFORMATION SECURITY, WISE 12, 2019, 557 : 129 - 142
  • [5] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2017
    Flowerday, Stephen V.
    SAIEE AFRICA RESEARCH JOURNAL, 2018, 109 (02): : 84 - 84
  • [6] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2014
    von Solms, Rossouw
    SAIEE AFRICA RESEARCH JOURNAL, 2015, 106 (02): : 44 - 44
  • [7] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2015
    Flowerday, Stephen V.
    SAIEE AFRICA RESEARCH JOURNAL, 2016, 107 (02): : 52 - 52
  • [8] INFORMATION SECURITY SOUTH AFRICA (ISSA) 2018
    Ophoff, Jacques
    SAIEE AFRICA RESEARCH JOURNAL, 2019, 110 (02): : 52 - 52
  • [9] Cyber Security Awareness Initiatives in South Africa: A Synergy Approach
    Dlamini, Zama
    Modise, Mapule
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2012, : 98 - 107
  • [10] Measuring the Impact of E-Learning Platforms on Information Security Awareness
    Fertig, Tobias
    Schuetz, Andreas E.
    Weber, Kristin
    Mueller, Nicholas H.
    LEARNING AND COLLABORATION TECHNOLOGIES. DESIGNING LEARNING EXPERIENCES, LCT 2019, PT I, 2019, 11590 : 26 - 37