Holistic framework for evaluating and improving information security culture

被引:3
作者
Arbanas, Krunoslav [1 ]
Spremic, Mario [2 ]
Zajdela Hrustek, Nikolina [3 ]
机构
[1] Croatian Energy Regulatory Agcy, Zagreb, Croatia
[2] Univ Zagreb, Fac Econ & Business, Zagreb, Croatia
[3] Univ Zagreb, Fac Org & Informat, Varazhdin, Croatia
关键词
Information security; Information security culture; Framework; Holistic approach; Measuring instrument; Validation; ORGANIZATIONAL CULTURE;
D O I
10.1108/AJIM-02-2021-0037
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose The objective of this research was to propose and validate a holistic framework for information security culture evaluation, built around a novel approach, which includes technological, organizational and social issues. The framework's validity and reliability were determined with the help of experts in the information security field and by using multivariate statistical methods. Design/methodology/approach The conceptual framework was constructed upon a detailed literature review and validated using a range of methods: first, measuring instrument was developed, and then content and construct validity of measuring instrument was confirmed via experts' opinion and by closed map sorting method. Convergent validity was confirmed by factor analysis, while the reliability of the measuring instrument was tested using Cronbach's alpha coefficient to measure internal consistency. Findings The proposed framework was validated based upon the results of empirical research and the usage of multivariate analysis. The resulting framework ultimately consists of 46 items (manifest variables), describing eight factors (first level latent variables), grouped into three categories (second level latent variables). These three categories were built around technological, organizational and social issues. Originality/value This paper contributes to the body of knowledge in information security culture by developing and validating holistic framework for information security culture evaluation, which does not observe information security culture in only one aspect but takes into account its organizational, sociological and technical component.
引用
收藏
页码:699 / 719
页数:21
相关论文
共 51 条
[1]  
AlHogail A., 2015, 2015 INT C SEC MAN, P286
[2]  
AlHogail A, 2014, 2014 WORLD CONGRESS ON COMPUTER APPLICATIONS AND INFORMATION SYSTEMS (WCCAIS)
[3]   Design and validation of information security culture framework [J].
AlHogail, Areej .
COMPUTERS IN HUMAN BEHAVIOR, 2015, 49 :567-575
[4]  
Alnatheer M.A., 2014, International Journal of Social Science and Humanity, V4, P104, DOI DOI 10.7763/IJSSH.2014.V4.327
[5]  
Amankwa E, 2014, INT CONF INTERNET, P248, DOI 10.1109/ICITST.2014.7038814
[6]  
Arbanas K, 2020, POLIC SIGUR, V29, P376
[7]   Key Success Factors of Information Systems Security [J].
Arbanas, Krunoslav ;
Hrustek, Nikolina Zajdela .
JOURNAL OF INFORMATION AND ORGANIZATIONAL SCIENCES, 2019, 43 (02) :131-144
[8]  
Babbie E.R., 2014, PRACTICE SOCIAL RES
[9]   Willingness to information security as a function of personality characteristics and threat assessment among adolescents [J].
Bouhnik, Dan ;
Reich, Nurit ;
Aharony, Noa .
ONLINE INFORMATION REVIEW, 2021, 45 (05) :912-929
[10]  
Brewerton P.M., 2001, ORGAN RES METHODS