A Systematic Literature Review: Information Security Culture

被引:0
|
作者
Mahfuth, Amjad [1 ]
Yussof, Salman [1 ]
Abu Baker, Asmidar [1 ]
Ali, Nor'ashikin [1 ]
机构
[1] Univ Tenaga Nas, Coll Comp Sci & Informat Technol, Putrajaya, Malaysia
来源
2017 5TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS 2017): SOCIAL TRANSFORMATION THROUGH DATA SCIENCE | 2017年
关键词
Attitudes; Security knowledge; Information Security culture; Human Behavior; FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] INFORMATION SECURITY CULTURE: A SYSTEMATIC LITERATURE REVIEW
    Hassan, Noor Hafizah
    Ismail, Zuraini
    Maarop, Nurazean
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS, 2015, : 456 - 463
  • [2] Information Security Culture: A Definition and A Literature Review
    AlHogail, Areej
    Mirza, Abdulrahman
    2014 WORLD CONGRESS ON COMPUTER APPLICATIONS AND INFORMATION SYSTEMS (WCCAIS), 2014,
  • [3] A Systematic Literature Review of Information Security in Chatbots
    Yang, Jing
    Chen, Yen-Lin
    Por, Lip Yee
    Ku, Chin Soon
    APPLIED SCIENCES-BASEL, 2023, 13 (11):
  • [4] Human Factors in Information Security Culture: A Literature Review
    Glaspie, Henry W.
    Karwowski, Waldemar
    ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 269 - 280
  • [5] A systematic review of scales for measuring information security culture
    Orehek, Spela
    Petric, Gregor
    INFORMATION AND COMPUTER SECURITY, 2021, 29 (01) : 133 - 158
  • [6] Information Security Policy Compliance: Systematic Literature Review
    Angraini
    Alias, Rose Alinda
    Okfalisa
    FIFTH INFORMATION SYSTEMS INTERNATIONAL CONFERENCE, 2019, 161 : 1216 - 1224
  • [7] Information and cyber security maturity models: a systematic literature review
    Rabii, Anass
    Assoul, Saliha
    Ouazzani Touhami, Khadija
    Roudies, Ounsa
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 627 - 644
  • [8] Systematic Literature Review: Information security behaviour on smartphone users
    Dawie, Ferdinand Jilan
    Masrek, Mohamad Noorman
    Rahman, Safawi Abdul
    ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2022, 7 : 275 - 281
  • [9] Economic valuation for information security investment: a systematic literature review
    Schatz, Daniel
    Bashroush, Rabih
    INFORMATION SYSTEMS FRONTIERS, 2017, 19 (05) : 1205 - 1228
  • [10] Inter-organisational information security: a systematic literature review
    Karlsson, Fredrik
    Kolkowska, Ella
    Prenkert, Frans
    INFORMATION AND COMPUTER SECURITY, 2016, 24 (05) : 418 - 451