A Systematic Literature Review: Information Security Culture

被引:0
作者
Mahfuth, Amjad [1 ]
Yussof, Salman [1 ]
Abu Baker, Asmidar [1 ]
Ali, Nor'ashikin [1 ]
机构
[1] Univ Tenaga Nas, Coll Comp Sci & Informat Technol, Putrajaya, Malaysia
来源
2017 5TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS 2017): SOCIAL TRANSFORMATION THROUGH DATA SCIENCE | 2017年
关键词
Attitudes; Security knowledge; Information Security culture; Human Behavior; FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations.
引用
收藏
页数:6
相关论文
共 50 条
[21]   Deriving the Relationship between Organizational Culture and Information Security Culture [J].
Hassan, Noor Hafizah ;
Ismail, Zuraini .
VISION 2020: INNOVATION, DEVELOPMENT SUSTAINABILITY, AND ECONOMIC GROWTH, VOLS 1-3, 2013, :926-932
[22]   Information overload research in accounting: a systematic review of the literature [J].
Hartmann, Maren ;
Weissenberger, Barbara E. .
MANAGEMENT REVIEW QUARTERLY, 2024, 74 (03) :1619-1667
[23]   Revisiting the information audit: A systematic literature review and synthesis [J].
Frost, Robert B. ;
Choo, Chun Wei .
INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2017, 37 (01) :1380-1390
[24]   Design and validation of information security culture framework [J].
AlHogail, Areej .
COMPUTERS IN HUMAN BEHAVIOR, 2015, 49 :567-575
[25]   A framework and assessment instrument for information security culture [J].
Da Veiga, A. ;
Eloff, J. H. P. .
COMPUTERS & SECURITY, 2010, 29 (02) :196-207
[26]   Information Security Culture Critical Success Factors [J].
Alnatheer, Mohammed A. .
2015 12TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY - NEW GENERATIONS, 2015, :731-735
[27]   Safety culture maturity measurement methods: A systematic literature review [J].
Ayob, Aida Normardiana ;
Hassan, Che Rosmani Che ;
Hamid, Mahar Diana .
JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2022, 80
[28]   The influence of organisational culture and information security culture on employee compliance behaviour [J].
Solomon, Grant ;
Brown, Irwin .
JOURNAL OF ENTERPRISE INFORMATION MANAGEMENT, 2021, 34 (04) :1203-1228
[29]   Information security management: A bibliographic review [J].
Cardenas-Solano, Leidy-Johanna ;
Martinez-Ardila, Hugo ;
Becerra-Ardila, Luis-Eduardo .
PROFESIONAL DE LA INFORMACION, 2016, 25 (06) :931-948
[30]   Improving Security Architecture of Internet of Medical Things: A Systematic Literature Review [J].
Mahmood, Mudasir ;
Khan, Muhammad Ijaz ;
Ziauddin ;
Hussain, Hameed ;
Khan, Inayat ;
Rahman, Shahid ;
Shabir, Muhammad ;
Niazi, Badam .
IEEE ACCESS, 2023, 11 :107725-107753