Information security culture and information protection culture: A validated assessment instrument

被引:52
作者
Da Veiga, Adele [1 ]
Martins, Nico [2 ]
机构
[1] Univ S Africa, Sch Comp, Coll Sci Engn & Technol, ZA-0003 Unisa, South Africa
[2] Univ S Africa, Dept Ind & Org Psychol, ZA-0003 Unisa, South Africa
关键词
Information security; Information security culture; Information protection culture; Privacy; Personal information; Assessment; Behaviour; Human; Questionnaire;
D O I
10.1016/j.clsr.2015.01.005
中图分类号
D9 [法律]; DF [法律];
学科分类号
0301 ;
摘要
A strong information protection culture is required in organisations where the confidentiality, sensitivity and privacy of information are understood and handled accordingly. This is necessary to reduce the risk of human behaviour to the protection of information as well as to uphold privacy requirements from a regulatory perspective. This research explores the concept of an information security culture and how information privacy can be incorporated to define an information protection culture. Next, the researchers explain information attributes relating to information security and information privacy to derive information attributes that can be considered when referring to an information protection culture. The information attributes are used to evaluate an existing information security culture assessment instrument that can potentially be used to assess an information protection culture. The research reveals that the information security culture assessment (ISCA) instrument can be used, but that it can be further improved by incorporating additional privacy concepts. An information protection culture assessment (IPCA) is conducted as part of a case study in an organisation. This allowed for a factor and reliability analysis to validate the IPCA. The analysis indicated that the IPCA is valid and reliable when grouping the items into the newly identified factors, but can further be enhanced by aligning it to information privacy attributes. (C) 2015 Adele Da Veiga &Nico Martins. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:243 / 256
页数:14
相关论文
共 36 条
[1]  
[Anonymous], REF DAT PROT LEG
[2]  
[Anonymous], J LAW INFORM SCI
[3]  
[Anonymous], ORG SURVEYS 7 STEP A
[4]  
[Anonymous], COST DAT BREACH STUD
[5]  
[Anonymous], 2009, KING COD GOV S AFR
[6]  
[Anonymous], 270022013 ISOIEC BSI
[7]  
[Anonymous], INFOSECURITY EUROPE
[8]  
[Anonymous], DATA SECURITY GROWIN
[9]  
[Anonymous], OECD PRIV PRINC
[10]  
[Anonymous], GLOB PRIV FRAM PRIV