Holistic framework for evaluating and improving information security culture

被引:3
作者
Arbanas, Krunoslav [1 ]
Spremic, Mario [2 ]
Zajdela Hrustek, Nikolina [3 ]
机构
[1] Croatian Energy Regulatory Agcy, Zagreb, Croatia
[2] Univ Zagreb, Fac Econ & Business, Zagreb, Croatia
[3] Univ Zagreb, Fac Org & Informat, Varazhdin, Croatia
关键词
Information security; Information security culture; Framework; Holistic approach; Measuring instrument; Validation; ORGANIZATIONAL CULTURE;
D O I
10.1108/AJIM-02-2021-0037
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose The objective of this research was to propose and validate a holistic framework for information security culture evaluation, built around a novel approach, which includes technological, organizational and social issues. The framework's validity and reliability were determined with the help of experts in the information security field and by using multivariate statistical methods. Design/methodology/approach The conceptual framework was constructed upon a detailed literature review and validated using a range of methods: first, measuring instrument was developed, and then content and construct validity of measuring instrument was confirmed via experts' opinion and by closed map sorting method. Convergent validity was confirmed by factor analysis, while the reliability of the measuring instrument was tested using Cronbach's alpha coefficient to measure internal consistency. Findings The proposed framework was validated based upon the results of empirical research and the usage of multivariate analysis. The resulting framework ultimately consists of 46 items (manifest variables), describing eight factors (first level latent variables), grouped into three categories (second level latent variables). These three categories were built around technological, organizational and social issues. Originality/value This paper contributes to the body of knowledge in information security culture by developing and validating holistic framework for information security culture evaluation, which does not observe information security culture in only one aspect but takes into account its organizational, sociological and technical component.
引用
收藏
页码:699 / 719
页数:21
相关论文
共 51 条
[21]  
Hassan NH, 2015, PROC INT CONF COMP, P456
[22]   Human factor, a critical weak point in the information security of an organization's Internet of things [J].
Hughes-Lartey, Kwesi ;
Li, Meng ;
Botchey, Francis E. ;
Qin, Zhen .
HELIYON, 2021, 7 (03)
[23]   Information security culture - state-of-the-art review between 2000 and 2013 [J].
Karlsson, Fredrik ;
Astrom, Joachim ;
Karlsson, Martin .
INFORMATION AND COMPUTER SECURITY, 2015, 23 (03) :246-285
[24]   Enhancing employees information security awareness in private and public organisations: A systematic literature review [J].
Khando, Khando ;
Gao, Shang ;
Islam, Sirajul M. ;
Salman, Ali .
COMPUTERS & SECURITY, 2021, 106
[25]   MEASUREMENT OF OBSERVER AGREEMENT FOR CATEGORICAL DATA [J].
LANDIS, JR ;
KOCH, GG .
BIOMETRICS, 1977, 33 (01) :159-174
[26]   QUANTITATIVE APPROACH TO CONTENT VALIDITY [J].
LAWSHE, CH .
PERSONNEL PSYCHOLOGY, 1975, 28 (04) :563-575
[27]  
Lewis B. R., 1995, Journal of Management Information Systems, V12, P199
[28]   Sample size in factor analysis [J].
MacCallum, RC ;
Widaman, KF ;
Zhang, SB ;
Hong, SH .
PSYCHOLOGICAL METHODS, 1999, 4 (01) :84-99
[29]  
Mahfuth A., 2017, RES INNOVATION INFOR, P1, DOI 10.1109/ICRIIS.2017.80024
[30]  
Mahfuth A, 2017, INT J SECUR APPL, V11, P15, DOI 10.14257/ijsia.2017.11.5.02