IMPACTS OF COMPREHENSIVE INFORMATION SECURITY PROGRAMS ON INFORMATION SECURITY CULTURE

被引:78
|
作者
Chen, Yan [1 ]
Ramamurthy, K. [2 ]
Wen, Kuang-Wei [3 ]
机构
[1] Auburn Univ, Montgomery, AL 36117 USA
[2] Univ Wisconsin, Milwaukee, WI 53201 USA
[3] Univ Wisconsin, La Crosse, WI 54601 USA
关键词
information security culture; security policy; security monitoring; SETA programs; POLICY COMPLIANCE; DETERRENCE; MANAGEMENT; MODELS; FRAMEWORK; FIT;
D O I
10.1080/08874417.2015.11645767
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A large number of security breaches involve internal employee negligence and insider breach. This situation, coupled with the need to comply with regulatory mandates has led to the establishment of comprehensive information security programs in many organizations. However, the relationships between comprehensive information security programs and security culture are unclear This research thus proposes a research model to evaluate the influences of key components of comprehensive information security programs on security culture and empirically tests it. The results indicate that SETA programs awareness has significant influences on security culture and on employees' awareness of organizational security policy, and that the awareness of security monitoring also impacts security culture. The proposed research model can be used as a benchmark to evaluate the effectiveness of comprehensive information security pm grams, to improve the design of such programs should gaps exist, and eventually assist in building a security culture.
引用
收藏
页码:11 / 19
页数:9
相关论文
共 50 条
  • [1] The Formulation of Comprehensive Information Security Culture Dimensions for Information Security Policy Compliance Study
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    [J]. ADVANCED SCIENCE LETTERS, 2018, 24 (10) : 7690 - 7695
  • [2] The impacts of organizational culture on information security culture: a case study
    Tang, Mincong
    Li, Meng'gang
    Zhang, Tao
    [J]. INFORMATION TECHNOLOGY & MANAGEMENT, 2016, 17 (02): : 179 - 186
  • [3] The impacts of organizational culture on information security culture: a case study
    Mincong Tang
    Meng’gang Li
    Tao Zhang
    [J]. Information Technology and Management, 2016, 17 : 179 - 186
  • [4] Information security culture
    Martins, A
    Eloff, J
    [J]. SECURITY IN THE INFORMATION SOCIETY: VISIONS AND PERSPECTIVES, 2002, 86 : 203 - 214
  • [5] Analyzing information security culture: Increased trust by an appropriate information security culture
    Schlienger, T
    Teufel, S
    [J]. 14TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2003, : 405 - 409
  • [6] The Influence of Organizational Information Security Culture on Information Security Decision Making
    Parsons, Kathryn Marie
    Young, Elise
    Butavicius, Marcus Antanas
    McCormac, Agata
    Pattinson, Malcolm Robert
    Jerram, Cate
    [J]. JOURNAL OF COGNITIVE ENGINEERING AND DECISION MAKING, 2015, 9 (02) : 117 - 129
  • [7] Information Security Service Culture - Information Security for End-users
    Rastogi, Rahul
    von Solms, Rossouw
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2012, 18 (12) : 1628 - 1642
  • [8] A framework and tool for the assessment of information security risk, the reduction of information security cost and the sustainability of information security culture
    Govender S.G.
    Kritzinger E.
    Loock M.
    [J]. Personal and Ubiquitous Computing, 2021, 25 (05) : 927 - 940
  • [9] Information security breaches and IT security investments: Impacts on competitors
    Jeong, Christina Y.
    Lee, Sang-Yong Tom
    Lim, Jee-Hae
    [J]. INFORMATION & MANAGEMENT, 2019, 56 (05) : 681 - 695
  • [10] Information Security Culture: A Survey
    Mazhelis, Oleksiy
    Isomaki, Hannakaisa
    [J]. PROCEEDINGS OF THE 8TH INTERNATIONAL NETWORK CONFERENCE (INC 2010), 2010, : 153 - 157