More than the individual: Examining the relationship between culture and Information Security Awareness

被引:80
作者
Wiley, Ashleigh [1 ]
McCormac, Agata [2 ]
Calic, Dragana [2 ]
机构
[1] Univ Adelaide, Adelaide, SA 5005, Australia
[2] Def Sci & Technol Grp, Third Ave, Edinburgh, SA 5111, Australia
关键词
Security culture; Organisational culture; Information Security Awareness (ISA); Information Security (InfoSec); Cyber security; Organisational behaviour; ORGANIZATIONAL CULTURE; QUESTIONNAIRE; BEHAVIOR; CLIMATE;
D O I
10.1016/j.cose.2019.101640
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The relationship between security culture and Information Security Awareness (ISA) has received preliminary support; however, its interplay with organisational culture is yet to be empirically investigated. Therefore, this study explored the relationship between ISA, organisational culture, and security culture. A total of 508 working Australians completed an online questionnaire. ISA was measured using the Human Aspects of Information Security Questionnaire (HAIS-Q); organisational culture was measured using the Denison Organisational Culture Survey (DOCS); and security culture was assessed through the Organisational Security Culture Measure. Our results showed that while organisational culture and security culture were correlated with ISA, security culture played an important mediating relationship between organisational culture and ISA. This suggests that organisations should focus on security culture rather than organisational culture to improve ISA, saving time and resources. Future research could further extend current findings by also considering national culture. Crown Copyright (C) 2019 Published by Elsevier Ltd. All rights reserved.
引用
收藏
页数:8
相关论文
共 48 条