Improving Organisational Information Security Management: The Impact of Training and Awareness

被引:13
作者
Waly, Nesren [1 ]
Tassabehji, Rana [1 ]
Kamala, Mumtaz [1 ]
机构
[1] Univ Bradford, Sch Comp Informat & Media, Bradford BD7 1DP, W Yorkshire, England
来源
2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS) | 2012年
关键词
Information security; awareness; compliance; security behaviour; training and awareness programme; quantitative research; CURRENT DIRECTIONS; SYSTEMS SECURITY; TECHNOLOGY; MODEL; ACCEPTANCE; CULTURE; SUCCESS; RISK;
D O I
10.1109/HPCC.2012.187
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Security breaches that affect personal data and organisational systems have become increasingly significant in the global technology (IT) industry. There is scope for research on the factors that influence user behaviour and attitudes toward this aspect of information security and their impact on organisation's network integrity. This research aims to study the critical success factors (CSF) for employees in order to comply with the organisational information security policy with a view to mitigating security breaches. Information security can be managed through three separate mechanisms: organisational factors, behavioural factors and training. Each of these elements impact differently on information security and comprehensive solutions include combinations of all three. The findings provide empirically evaluated information regarding the obstacles and the effective factors in employees' compliance with the implementation of the information security policy. The identified categories of factors are followed differently by employees working in Health, Business and Education. Questionnaire analysis as part of this study suggests that employees in the health sector comply the most in adhering with information security policy as compared to other sectors. One of the reasons for this is that health sector employees have better awareness, robust communication and and effective training programmes with reinforcement and satisfaction. Moreover, employees in the health sector believe in the norms of security policies and have a positive attitude, as they recognise the significance of security policies, unlike the business and education sectors.
引用
收藏
页码:1270 / 1275
页数:6
相关论文
共 32 条
[1]   Perceived behavioral control, self-efficacy, locus of control, and the theory of planned behavior [J].
Ajzen, I .
JOURNAL OF APPLIED SOCIAL PSYCHOLOGY, 2002, 32 (04) :665-683
[2]  
[Anonymous], SPORT PSYCHOL
[3]  
[Anonymous], EXPLORATORY INVESTIG
[4]  
[Anonymous], P CIB W65 S ORG MAN
[5]  
[Anonymous], 2010, 8 AUSTR INF SEC C BR
[6]  
[Anonymous], COMPUTERS SECURITY
[7]  
[Anonymous], SERIES CURRICULUM DE
[8]  
[Anonymous], PRINCIPLES COMPUTER
[9]  
[Anonymous], COMPUTERS HUMAN BEHA
[10]  
[Anonymous], NEW SEC PAR WORKSH