A Systematic Literature Review: Information Security Culture

被引:0
作者
Mahfuth, Amjad [1 ]
Yussof, Salman [1 ]
Abu Baker, Asmidar [1 ]
Ali, Nor'ashikin [1 ]
机构
[1] Univ Tenaga Nas, Coll Comp Sci & Informat Technol, Putrajaya, Malaysia
来源
2017 5TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS 2017): SOCIAL TRANSFORMATION THROUGH DATA SCIENCE | 2017年
关键词
Attitudes; Security knowledge; Information Security culture; Human Behavior; FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations.
引用
收藏
页数:6
相关论文
共 50 条
[41]   Employee security perception in cultivating information security culture [J].
Zakaria, O .
Security Management, Integrity, and Internal Control in Information Systems, 2005, 193 :83-92
[42]   Information security culture - state-of-the-art review between 2000 and 2013 [J].
Karlsson, Fredrik ;
Astrom, Joachim ;
Karlsson, Martin .
INFORMATION AND COMPUTER SECURITY, 2015, 23 (03) :246-285
[43]   Critical Success Factors Analysis on Effective Information Security Management: A Literature Review [J].
Tu, Zhiling ;
Yuan, Yufei .
AMCIS 2014 PROCEEDINGS, 2014,
[44]   A framework and tool for the assessment of information security risk, the reduction of information security cost and the sustainability of information security culture [J].
Govender S.G. ;
Kritzinger E. ;
Loock M. .
Personal and Ubiquitous Computing, 2021, 25 (05) :927-940
[45]   Information security culture: A management perspective [J].
Van Niekerk, J. F. ;
Von Solms, R. .
COMPUTERS & SECURITY, 2010, 29 (04) :476-486
[46]   Key Factors of Information Security Culture [J].
Arbanas, Krunoslav .
POLICIJA I SIGURNOST-POLICE AND SECURITY, 2020, 29 (04) :376-388
[47]   A systematic literature review of interoperability in the green Building Information Modeling lifecycle [J].
Muller, Marina Figueiredo ;
Esmanioto, Filipe ;
Huber, Natan ;
Loures, Eduardo Rocha ;
Canciglieri Junior, Osiris .
JOURNAL OF CLEANER PRODUCTION, 2019, 223 :397-412
[48]   Cultivating and Assessing an Organizational Information Security Culture; an Empirical Study [J].
Al Hogail, Areej .
INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (07) :163-178
[49]   A Conceptual Information Security Culture Framework for Higher Learning Institutions [J].
Ocloo, Charles Mawutor ;
da Veiga, Adele ;
Kroeze, Jan .
HUMAN ASPECTS OF INFORMATION SECURITY AND ASSURANCE, HAISA 2021, 2021, 613 :63-80
[50]   The effect of perceived organizational culture on employees' information security compliance [J].
Karlsson, Martin ;
Karlsson, Fredrik ;
Astrom, Joachim ;
Denk, Thomas .
INFORMATION AND COMPUTER SECURITY, 2022, 30 (03) :382-401