Defining organisational information security culture—perspectives from academia and industry

dc.contributor.authorDa Veiga, Adele
dc.contributor.authorAstakhova, Liudmila V.
dc.contributor.authorBotha, Adele
dc.contributor.authorHerselman, Marlien E.
dc.date.accessioned2020-09-28T13:17:39Z
dc.date.issued2020-05
dc.description.abstractThe ideal or strong information security culture can aid in minimising the threat of humans to information protection and thereby aid in reducing data breaches or incidents in organisations. This research sets out to understand how information security culture is defined from an academic and industry perspective using a mixed-method approach. The definition, factors necessary to instil the ideal information security culture and the potential impact of the ideal information security culture were investigated from both perspectives. A survey approach was implemented to obtain the views from industry and 512 respondents from organisations, many of which operate at an international level, participated in the survey. The research presents a description of information security culture, integrating the existing literature and expanding on it with the views of industry, thereby giving clarity to the concept. The ideal information security culture was identified with the top traits relating to aspects such as an aware and knowledgeable workforce implementing conscientious, caring behaviour to comply with policies as guided by management. The factors that could positively influence an information security culture were identified, consolidated and expanded to five external factors and twenty internal factors. Organisations that have a strong information security culture were identified as achieving mutual trust and integrity through the protection of their information. The description of an information security culture can be used as a baseline to define and understand the concept, identify a single, comprehensive set of factors to be implemented, comprehend the traits of such a culture, as well as what an organisation can achieve by having a strong information security culture. The analysis showed that scientific interpretations of the definitions and factors of information security culture are much wider than their understanding of the industry. Both the results from the scoping review of papers and the feedback from the industry experts are synthesised visually to provide an organisational information security culture model (OISCM). The definition, factors, and model that influence the organisational culture of information security, have prognostic value for industry. For scientists, this is an important topic of research on methods and forms of increasing the level of this knowledge.en_ZA
dc.description.departmentScience, Mathematics and Technology Educationen_ZA
dc.description.embargo2021-05-01
dc.description.librarianhj2020en_ZA
dc.description.sponsorshipThe National Research Foundation of South Africaen_ZA
dc.description.urihttp://www.elsevier.com/locate/coseen_ZA
dc.identifier.citationDa Veiga A., Astakhova L.V., Botha A. et al. 2020, 'Defining organisational information security culture—perspectives from academia and industry', Computers and Security, vol. 92, art. 101713.en_ZA
dc.identifier.issn0167-4048 (print)
dc.identifier.issn1872-6208 (online)
dc.identifier.other10.1016/j.cose.2020.101713
dc.identifier.urihttp://hdl.handle.net/2263/76240
dc.language.isoenen_ZA
dc.publisherElsevieren_ZA
dc.rights© 2020 Elsevier Ltd. All rights reserved. Notice : this is the author’s version of a work that was accepted for publication in Computers and Security. Changes resulting from the publishing process, such as peer review, editing, corrections, structural formatting, and other quality control mechanisms may not be reflected in this document. A definitive version was subsequently published in Computers and Security, vol. 92, art. 101713, 2020.doi : 10.1016/j.cose.2020.101713.en_ZA
dc.subjectInformation security cultureen_ZA
dc.subjectDefinitionen_ZA
dc.subjectFactorsen_ZA
dc.subjectImpacten_ZA
dc.subjectHumanen_ZA
dc.subjectKey traitsen_ZA
dc.subjectModelen_ZA
dc.subjectOrganisational information security culture model (OISCM)en_ZA
dc.titleDefining organisational information security culture—perspectives from academia and industryen_ZA
dc.typePostprint Articleen_ZA

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
DaVeiga_Defining_2020.pdf
Size:
1.38 MB
Format:
Adobe Portable Document Format
Description:
Postprint Article

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.75 KB
Format:
Item-specific license agreed upon to submission
Description: