A Systematic Literature Review: Information Security Culture

被引:0
作者
Mahfuth, Amjad [1 ]
Yussof, Salman [1 ]
Abu Baker, Asmidar [1 ]
Ali, Nor'ashikin [1 ]
机构
[1] Univ Tenaga Nas, Coll Comp Sci & Informat Technol, Putrajaya, Malaysia
来源
2017 5TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS 2017): SOCIAL TRANSFORMATION THROUGH DATA SCIENCE | 2017年
关键词
Attitudes; Security knowledge; Information Security culture; Human Behavior; FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations.
引用
收藏
页数:6
相关论文
共 50 条
[31]   A Systematic Literature Review of Blockchain Technology: Security Properties, Applications and Challenges [J].
Tuan-Vinh Le ;
Hsu, Chien-Lung .
JOURNAL OF INTERNET TECHNOLOGY, 2021, 22 (04) :789-802
[32]   The hunt for computerized support in information security policy management A literature review [J].
Rostami, Elham ;
Karlsson, Fredrik ;
Kolkowska, Ella .
INFORMATION AND COMPUTER SECURITY, 2020, 28 (02) :215-259
[33]   The Influence of National Culture on Information Security Culture [J].
Govender, Sunthoshan ;
Kritzinger, Elmarie ;
Loock, Marianne .
2016 IST-AFRICA WEEK CONFERENCE, 2016,
[34]   What Is a Framework? - A Systematic Literature Review in the Field of Information Systems [J].
Stamer, Dirk ;
Zimmermann, Ole ;
Sandkuhl, Kurt .
PERSPECTIVES IN BUSINESS INFORMATICS RESEARCH, BIR 2016, 2016, 261 :145-158
[35]   The Role of Information Technology in Business Agility: Systematic Literature Review [J].
Setiawati, Rini ;
Eve, Jenniver ;
Syavira, Aisyah ;
Ricardianto, Prasadja ;
Nofrisel ;
Endri, Endri .
QUALITY-ACCESS TO SUCCESS, 2022, 23 (189) :144-149
[36]   Information security governance challenges and critical success factors: Systematic review [J].
AlGhamdi, Sultan ;
Khin Than Win ;
Vlahu-Gjorgievska, Elena .
COMPUTERS & SECURITY, 2020, 99
[37]   Holistic framework for evaluating and improving information security culture [J].
Arbanas, Krunoslav ;
Spremic, Mario ;
Zajdela Hrustek, Nikolina .
ASLIB JOURNAL OF INFORMATION MANAGEMENT, 2021, 73 (05) :699-719
[38]   Information Security Culture for Guiding Employee's Security Behaviour: A Pilot Study [J].
Nasir, Akhyari ;
Arshah, Ruzaini Abdullah ;
Ab Harnid, Mohd Rashid .
2020 THE 6TH IEEE INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT (ICIM 2020), 2020, :205-209
[39]   Information Security Service Culture - Information Security for End-users [J].
Rastogi, Rahul ;
von Solms, Rossouw .
JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2012, 18 (12) :1628-1642
[40]   Information security culture and information protection culture: A validated assessment instrument [J].
Da Veiga, Adele ;
Martins, Nico .
COMPUTER LAW & SECURITY REVIEW, 2015, 31 (02) :243-256