Institutional Repository

A framework for end-user compliance with the information security policy in government institutions

Show simple item record

dc.contributor.advisor Da Veiga, Adele en
dc.contributor.author Lekhuleni, Sakhile Charity Dories en
dc.date.accessioned 2026-08-14T13:06:08Z
dc.date.available 2026-08-14T13:06:08Z
dc.date.issued 2026
dc.identifier.uri https://ir.unisa.ac.za/handle/10500/32937
dc.description.abstract Employees’ non-adherence causes most security breaches in both private and public organisations to information security policies (ISPs). The purpose of this research is to develop a framework for end-user compliance with ISPs in government departments. A framework that integrates all factors that enhance end-user compliance will assist organisations and information security managers in understanding the elements that affect end-user compliance. A systematic literature review was conducted using the PRISMA method to identify the factors and components contributing to the development of the framework. Moreover, semi-structured interviews were conducted with government officials from two Mpumalanga departments and with experts in information security and ISP compliance to refine and validate the framework. The outcome of the interviews with government officials and experts resulted in the inclusion of additional components and factors to the conceptual ECISP framework. The outcome of this process is a validated framework intended to enhance end-user compliance with ISPs within government institutions. The main aim of the research study is to integrate literature findings with practical insights from government officials and experts to develop, refine, and validate a framework for end-user compliance with ISPs in Government departments (the ECISP Framework). The ECISP Framework provides guidance that enables organisations to address specific challenges related to end-user compliance with ISPs, thereby improving the likelihood of achieving end-user compliance with ISPs. en
dc.language.iso en en
dc.subject Information security policy en
dc.subject End-user compliance with information security policy en
dc.subject Government departments en
dc.subject ECISP framework en
dc.subject.lcsh Computer security -- South Africa -- Mpumalanga en
dc.subject.lcsh Data protection -- South Africa -- Mpumalanga en
dc.subject.lcsh Information technology -- Security measures en
dc.subject.lcsh Information technology -- Employees -- Attitudes en
dc.subject.other UCTD en
dc.title A framework for end-user compliance with the information security policy in government institutions en
dc.type Dissertation en
dc.description.department Computing en


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search UnisaIR


Browse

My Account

Statistics