A systematic review of scales for measuring information security culture

被引:13
|
作者
Orehek, Spela [1 ]
Petric, Gregor [1 ]
机构
[1] Univ Ljubljana, Fac Social Sci, Ctr Methodol & Informat, Ljubljana, Slovenia
关键词
Information security culture; Information security; Measurement; Scales; Validity; Systematic review; Surveys; Assessments; Methodology; Meta-analysis; AWARENESS; IMPLEMENTATION; QUESTIONNAIRE; BEHAVIOR;
D O I
10.1108/ICS-12-2019-0140
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose - The concept of information security culture, which recently gained increased attention, aims to comprehensively grasp socio-cultural mechanisms that have an impact on organizational security. Different measurement instruments have been developed to measure and assess information security culture using survey-based tools. However, the content, breadth and face validity of these scales vary greatly. This study aims to identify and provide an overview of the scales that are used to measure information security culture and to evaluate the rigor of reported scale development and validation procedures. Design/methodology/approach - Papers that introduce a new or adapt an existing scale of information security culture were systematically reviewed to evaluate scales of information security culture. A standard search strategy was applied to identify 19 relevant scales, which were evaluated based on the framework of 16 criteria pertaining to the rigor of reported operationalization and the reported validity and reliability of the identified scales. Findings - The results show that the rigor with which scales of information security culture are validated varies greatly and that none of the scales meet all the evaluation criteria. Moreover, most of the studies provide somewhat limited evidence of the validation of scales, indicating room for further improvement. Particularly, critical issues seem to be the lack of evidence regarding discriminant and criterion validity and incomplete documentation of the operationalization process. Research limitations/implications - Researchers focusing on the human factor in information security need to reach a certain level of agreement on the essential elements of the concept of information security culture. Future studies need to build on existing scales, address their limitations and gain further evidence regarding the validity of scales of information security culture. Further research should also investigate the quality of definitions andmake expert assessments of the content fit between concepts and items. Practical implications - Organizations that aim to assess the level of information security culture among employees can use the results of this systematic review to support the selection of an adequate measurement scale. However, caution is needed for scales that provide limited evidence of validation. Originality/value - This is the first study that offers a critical evaluation of existing scales of information security culture. The results have decision-making value for researchers who intend to conduct survey-based examinations of information security culture.
引用
收藏
页码:133 / 158
页数:26
相关论文
共 50 条
  • [21] A Systematic Review of Information Security Frameworks in the Internet of Things
    Irshad, Mohammad
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 1270 - 1275
  • [22] Information Security and Privacy in Railway Transportation: A Systematic Review
    Lopez-Aguilar, Pablo
    Batista, Edgar
    Martinez-Balleste, Antoni
    Solanas, Agusti
    SENSORS, 2022, 22 (20)
  • [23] Information Availability as Driver of Information Security Investments: A Systematic Review Approach
    Dang, Duy
    Nkhoma, Mathews
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS MANAGEMENT AND EVALUATION (ICIME 2013), 2013, : 71 - 80
  • [24] Information security culture
    Martins, A
    Eloff, J
    SECURITY IN THE INFORMATION SOCIETY: VISIONS AND PERSPECTIVES, 2002, 86 : 203 - 214
  • [25] Analyzing information security culture: Increased trust by an appropriate information security culture
    Schlienger, T
    Teufel, S
    14TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2003, : 405 - 409
  • [26] Psychometric Properties of Scales Measuring Resilience in US Latinx Populations: A Systematic Review
    Cockroft, Joshua D.
    Rabin, Julia
    Yockey, R. Andrew
    Toledo, Isabella
    Fain, Susan
    Jacquez, Farrah
    Vaughn, Lisa M.
    Stryker, Shanna D.
    HEALTH EQUITY, 2023, 7 (01) : 148 - 160
  • [27] Evaluation of psychometric properties of scales measuring student academic satisfaction: A Systematic review
    Rahmatpour, Pardis
    Nia, Hamid Sharif
    Peyrovi, Hamid
    JOURNAL OF EDUCATION AND HEALTH PROMOTION, 2019, 8 (01)
  • [28] Information and cyber security maturity models: a systematic literature review
    Rabii, Anass
    Assoul, Saliha
    Ouazzani Touhami, Khadija
    Roudies, Ounsa
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 627 - 644
  • [29] Systematic Literature Review: Information security behaviour on smartphone users
    Dawie, Ferdinand Jilan
    Masrek, Mohamad Noorman
    Rahman, Safawi Abdul
    ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2022, 7 : 275 - 281
  • [30] Economic valuation for information security investment: a systematic literature review
    Schatz, Daniel
    Bashroush, Rabih
    INFORMATION SYSTEMS FRONTIERS, 2017, 19 (05) : 1205 - 1228