Towards information security behavioural compliance

被引:226
作者
Vroom, C [1 ]
von Solms, R [1 ]
机构
[1] Port Elizabeth Technikon, Port Elizabeth, South Africa
关键词
IT auditing; IS security auditing; organizational culture; organizational behaviour; security compliance;
D O I
10.1016/j.cose.2004.01.012
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Auditing has always played an important rote in the business environment. With the introduction of information technology and the resulting security challenges that organizations face daily, it has become essential to ensure the security of the organization's information and other valuable assets. However, one aspect that auditing does not cover effectively is that of the behaviour of the employee, which is so crucial to any organization's security. The objective of this paper is to explore the potential problems concerning the attempt to audit the behaviour of the employee. It will be demonstrated that it is extremely difficult to audit human behaviour and so an alternative method to behavioural auditing needs to be found, where policing the employee is not necessary, but instead a softer, more informal approach is used to change the culture to a more information security conscious one. (C) 2004 Elsevier Ltd. All rights reserved.
引用
收藏
页码:191 / 198
页数:8
相关论文
共 13 条
  • [1] BRINEY A, 2001, 2001 INFORMATION SEC
  • [2] *BRIT STAND I, 1999, 0007 DISC PD
  • [3] UBIQUITOUS HALO
    COOPER, WH
    [J]. PSYCHOLOGICAL BULLETIN, 1981, 90 (02) : 218 - 244
  • [4] Deal T. E., 1982, CORPORATE CULTURE RI
  • [5] FRASER B, 1997, SITE SECURITY HDB
  • [6] HALLIDAY J, 1997, INFORMATION TECHNOLO, P12
  • [7] LANGELIER C, 2001, PLANNING GUIDE INFOR
  • [8] PALIOTTA A, 1999, PERSONAL VIEW WORLD
  • [9] SAWYER LB, 1996, SAWYERS INTERNAL AUG
  • [10] Schein E. H., 1999, The Corporate Culture Survival Guide