首页> 外文期刊>Computers & Security >Denning and identifying dominant information security cultures and subcultures
【24h】

Denning and identifying dominant information security cultures and subcultures

机译:定义和识别主要的信息安全文化和亚文化

获取原文
获取原文并翻译 | 示例
       

摘要

When considering an information security culture in an organisation, researchers have to consider the possibility of several information security subcultures that could be present in the organisation. This means that different geographical, ethnic or age groups of employees could have different assumptions, values and beliefs about the protection of information, resulting in unique information security subcultures. This research sets out to understand how dominant information security cultures and subcultures develop and how they can be influenced positively over time through targeted interventions. In support of this, a summary of the intrinsic and extrinsic factors that influence information security culture is presented. An empirical case study was conducted using a survey approach with a validated information security culture questionnaire to illustrate how to identify dominant information security cultures and subcultures. The survey was conducted at four intervals in the same organisation over a number of years to identify potential information security subcultures and to monitor the change, if targeted interventions for each are implemented. Using t-tests and ANOVA tests, a number of information security subcultures were identified, mostly evident across the organisation's office locations (which are separated geographically), as well as between employees that worked in the IT division compared to those who did not. The data indicate that the dominant information security culture and subcultures improved over time to a more positive information security culture after the implementation of targeted interventions. This illustrates how the identification and targeting of information security subcultures with customised interventions can influence the information security culture positively. By using information security interventions, organisations can target their high-risk subcultures and monitor the change over time through continuous assessment, thereby minimising the risk to information protection from a human perspective.
机译:在考虑组织中的信息安全文化时,研究人员必须考虑组织中可能存在的几种信息安全子文化的可能性。这意味着不同的地理,种族或年龄段的员工对于信息保护可能具有不同的假设,价值观和信念,从而形成独特的信息安全亚文化。这项研究旨在了解主导的信息安全文化和亚文化如何发展,以及如何通过有针对性的干预措施随着时间的推移对其产生积极影响。为此,对影响信息安全文化的内在因素和外在因素进行了总结。使用调查方法和经过验证的信息安全文化问卷调查进行了案例研究,以说明如何识别主导的信息安全文化和亚文化。多年来,该调查是在同一组织中以四个间隔进行的,以识别潜在的信息安全亚文化并监视变更(如果针对每个实施了针对性的干预措施)。使用t检验和ANOVA检验,可以识别出许多信息安全亚文化,在整个组织的办公室位置(在地理位置上是分开的)以及在IT部门工作的员工与未在办公室工作的员工之间,最为明显。数据表明,在实施有针对性的干预措施后,占主导地位的信息安全文化和亚文化随着时间的推移逐渐改善为更积极的信息安全文化。这说明了通过定制干预措施识别和确定信息安全亚文化如何能够对信息安全文化产生积极影响。通过使用信息安全干预措施,组织可以针对其高风险亚文化群,并通过持续评估来监视随时间推移的变化,从而从人的角度将信息保护的风险降至最低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号