Institutional Repository

A Framework and Assessment Instrument for Information Security Culture

Show simple item record

dc.contributor.author Da Veiga, Adele
dc.contributor.author Eloff, Jan
dc.date.accessioned 2025-02-14T07:33:12Z
dc.date.available 2025-02-14T07:33:12Z
dc.date.issued 2010
dc.identifier.issn 0167-4048
dc.identifier.uri doi:10.1016/j.cose.2009.09.002
dc.identifier.uri https://hdl.handle.net/10500/32104
dc.description.abstract An organisation’s approach to information security should focus on employee behaviour, as the organisation’s success or failure effectively depends on the things that its employees do or fail to do. An information security-aware culture will minimise risks to information assets and specifically reduce the risk of employee misbehaviour and harmful interaction with information assets. Organisations require guidance in establishing an information security-aware or implementing an acceptable information security culture. They need to measure and report on the state of information security culture in the organisation. Various approaches exist to address the threats that employee behaviour could pose. However, these approaches do not focus specifically on the interaction between the behaviour of an employee and the culture in an organisation. Organisations therefore have need of a comprehensive framework to cultivate a security-aware culture. The objective of this paper is to propose a framework to cultivate an information security culture within an organisation and to illustrate how to use it. An empirical study is performed to aid in validating the proposed Information Security Culture Framework. en
dc.language.iso en en
dc.publisher Computers and Security en
dc.subject Information Security Culture en
dc.subject Organisational Culture en
dc.subject Framework en
dc.subject Organisational Behaviour en
dc.subject Human en
dc.subject Assessment Instrument en
dc.subject Measure en
dc.title A Framework and Assessment Instrument for Information Security Culture en
dc.type Article en
dc.description.department College of Engineering, Science and Technology en


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search UnisaIR


Browse

My Account

Statistics