首页> 外文期刊>Computer law & security report >Information security culture and information protection culture: A validated assessment instrument
【24h】

Information security culture and information protection culture: A validated assessment instrument

机译:信息安全文化和信息保护文化:经过验证的评估工具

获取原文
获取原文并翻译 | 示例
           

摘要

A strong information protection culture is required in organisations where the confidentiality, sensitivity and privacy of information are understood and handled accordingly. This is necessary to reduce the risk of human behaviour to the protection of information as well as to uphold privacy requirements from a regulatory perspective. This research explores the concept of an information security culture and how information privacy can be incorporated to define an information protection culture. Next, the researchers explain information attributes relating to information security and information privacy to derive information attributes that can be considered when referring to an information protection culture. The information attributes are used to evaluate an existing information security culture assessment instrument that can potentially be used to assess an information protection culture. The research reveals that the information security culture assessment (ISCA) instrument can be used, but that it can be further improved by incorporating additional privacy concepts. An information protection culture assessment (IPCA) is conducted as part of a case study in an organisation. This allowed for a factor and reliability analysis to validate the IPCA. The analysis indicated that the IPCA is valid and reliable when grouping the items into the newly identified factors, but can further be enhanced by aligning it to information privacy attributes. (C) 2015 Adele Da Veiga &Nico Martins. Published by Elsevier Ltd. All rights reserved.
机译:在理解和处理信息的机密性,敏感性和隐私性的组织中,需要一种强有力的信息保护文化。这对于降低人类行为对信息保护的风险以及从法规角度维护隐私要求是必要的。这项研究探索了信息安全文化的概念,以及如何将信息隐私纳入定义信息保护文化的范围。接下来,研究人员解释与信息安全性和信息隐私有关的信息属性,以得出在提及信息保护文化时可以考虑的信息属性。信息属性用于评估现有的信息安全文化评估工具,该工具可以潜在地用于评估信息保护文化。研究表明,可以使用信息安全文化评估(ISCA)工具,但可以通过合并其他隐私概念来进一步改进它。信息保护文化评估(IPCA)是组织中案例研究的一部分。这允许进行因素和可靠性分析以验证IPCA。分析表明,IPCA在将项目归类为新确定的因素时是有效和可靠的,但是可以通过将其与信息隐私属性对齐来进一步增强。 (C)2015阿黛尔·达·韦加(Adele Da Veiga)和尼科·马丁斯(Nico Martins)。由Elsevier Ltd.出版。保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号