| dc.contributor.advisor |
Da Veiga, Adele
|
en |
| dc.contributor.author |
Lekhuleni, Sakhile Charity Dories
|
en |
| dc.date.accessioned |
2026-08-14T13:06:08Z |
|
| dc.date.available |
2026-08-14T13:06:08Z |
|
| dc.date.issued |
2026 |
|
| dc.identifier.uri |
https://ir.unisa.ac.za/handle/10500/32937 |
|
| dc.description.abstract |
Employees’ non-adherence causes most security breaches in both private and public organisations to information security policies (ISPs). The purpose of this research is to develop a framework for end-user compliance with ISPs in government departments. A framework that integrates all factors that enhance end-user compliance will assist organisations and information security managers in understanding the elements that affect end-user compliance. A systematic literature review was conducted using the PRISMA method to identify the factors and components contributing to the development of the framework. Moreover, semi-structured interviews were conducted with government officials from two Mpumalanga departments and with experts in information security and ISP compliance to refine and validate the framework. The outcome of the interviews with government officials and experts resulted in the inclusion of additional components and factors to the conceptual ECISP framework. The outcome of this process is a validated framework intended to enhance end-user compliance with ISPs within government institutions. The main aim of the research study is to integrate literature findings with practical insights from government officials and experts to develop, refine, and validate a framework for end-user compliance with ISPs in Government departments (the ECISP Framework). The ECISP Framework provides guidance that enables organisations to address specific challenges related to end-user compliance with ISPs, thereby improving the likelihood of achieving end-user compliance with ISPs. |
en |
| dc.language.iso |
en |
en |
| dc.subject |
Information security policy |
en |
| dc.subject |
End-user compliance with information security policy |
en |
| dc.subject |
Government departments |
en |
| dc.subject |
ECISP framework |
en |
| dc.subject.lcsh |
Computer security -- South Africa -- Mpumalanga |
en |
| dc.subject.lcsh |
Data protection -- South Africa -- Mpumalanga |
en |
| dc.subject.lcsh |
Information technology -- Security measures |
en |
| dc.subject.lcsh |
Information technology -- Employees -- Attitudes |
en |
| dc.subject.other |
UCTD |
en |
| dc.title |
A framework for end-user compliance with the information security policy in government institutions |
en |
| dc.type |
Dissertation |
en |
| dc.description.department |
Computing |
en |