首页> 外文会议>International Conference on Information Technology, Computer and Electrical Engineering >Assessing information security culture: The case of Malaysia public organization
【24h】

Assessing information security culture: The case of Malaysia public organization

机译:评估信息安全文化:马来西亚公共组织的案例

获取原文

摘要

In line with the growing number of reported cases of information security breaches, there is also a growing interest among researchers to study information security culture. To this effect, researchers have developed various models and frameworks for assessing and developing information security culture. However, most of these models or frameworks are not a silver bullet which can be easily applied to all organizational settings. The requirements and the characteristics of information security culture differ from one organization to other organization. On the basis of this background, this study was conducted with the aim of identifying the dimensions of information security culture in the context of Malaysian public organizations. The framework for assessing the information security culture was developed through extensive literature review and verified through experts' interviews. The framework consists of six components, namely, management support, policy and procedures, compliance, awareness, budget and technology. A corresponding scale was also developed to assess the information security culture and administered to Malaysian public organizations of the federal ministries. The respondents were requested to indicate the aspects that are considered crucial and important in developing an information security culture. A total of 293 IT directors responded to the survey. The results showed that all of the aforementioned components were indeed crucial and significant in developing information security culture. The contribution of the study can be described in three-folds, namely theoretical, practical and empirical. From a theoretical standpoint, it has developed an empirical based framework for assessing information security culture. From a practical standpoint, the scale or instrument developed in the study can be used to gauge the level of information security culture and finally from the empirical standpoint, it has provided additional empirical evidence on the status of information security culture in the Malaysian context.
机译:符合越来越多的报告信息安全漏洞,研究人员越来越兴趣,以研究信息安全文化。为此,研究人员开发了用于评估和发展信息安全文化的各种模型和框架。但是,这些模型或框架中的大多数都不是银弹,可以轻松应用于所有组织设置。信息安全文化的要求和特征与其他组织的一个组织不同。在此背景的基础上,该研究是在马来西亚公共组织背景下识别信息安全文化的维度。通过广泛的文献综述,通过专家访谈进行了评估信息安全文化的框架。该框架包括六个组件,即管理支持,政策和程序,合规性,意识,预算和技术。还制定了相应的规模来评估信息安全文化,并管理联邦部长的马来西亚公共组织。要求受访者表示在制定信息安全文化方面被认为是至关重要的,重要的方面。共有293项IT董事对调查作出回应。结果表明,所有上述组件在发展信息安全文化方面确实至关重要。该研究的贡献可以用三倍,即理论,实用和经验的三倍描述。从理论上的角度来看,它开发了一个基于经验的评估信息安全文化的框架。从实际的角度来看,研究中开发的规模或仪器可用于衡量信息安全文化水平,最后从经验主义的角度来看,它为马来西亚语境中信息安全文化的地位提供了额外的实证证据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号