dc.contributor.author |
Da Veiga, Adele
|
|
dc.contributor.author |
Eloff, Jan
|
|
dc.date.accessioned |
2025-02-14T07:33:12Z |
|
dc.date.available |
2025-02-14T07:33:12Z |
|
dc.date.issued |
2010 |
|
dc.identifier.issn |
0167-4048 |
|
dc.identifier.uri |
doi:10.1016/j.cose.2009.09.002 |
|
dc.identifier.uri |
https://hdl.handle.net/10500/32104 |
|
dc.description.abstract |
An organisation’s approach to information security should focus on employee behaviour,
as the organisation’s success or failure effectively depends on the things that its employees
do or fail to do. An information security-aware culture will minimise risks to information
assets and specifically reduce the risk of employee misbehaviour and harmful interaction
with information assets. Organisations require guidance in establishing an information
security-aware or implementing an acceptable information security culture. They need to
measure and report on the state of information security culture in the organisation.
Various approaches exist to address the threats that employee behaviour could pose.
However, these approaches do not focus specifically on the interaction between the
behaviour of an employee and the culture in an organisation. Organisations therefore have
need of a comprehensive framework to cultivate a security-aware culture. The objective of
this paper is to propose a framework to cultivate an information security culture within an
organisation and to illustrate how to use it. An empirical study is performed to aid in
validating the proposed Information Security Culture Framework. |
en |
dc.language.iso |
en |
en |
dc.publisher |
Computers and Security |
en |
dc.subject |
Information Security Culture |
en |
dc.subject |
Organisational Culture |
en |
dc.subject |
Framework |
en |
dc.subject |
Organisational Behaviour |
en |
dc.subject |
Human |
en |
dc.subject |
Assessment Instrument |
en |
dc.subject |
Measure |
en |
dc.title |
A Framework and Assessment Instrument for Information Security Culture |
en |
dc.type |
Article |
en |
dc.description.department |
College of Engineering, Science and Technology |
en |