A Systematic Literature Review: Information Security Culture

被引:0
|
作者
Mahfuth, Amjad [1 ]
Yussof, Salman [1 ]
Abu Baker, Asmidar [1 ]
Ali, Nor'ashikin [1 ]
机构
[1] Univ Tenaga Nas, Coll Comp Sci & Informat Technol, Putrajaya, Malaysia
关键词
Attitudes; Security knowledge; Information Security culture; Human Behavior; FRAMEWORK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] INFORMATION SECURITY CULTURE: A SYSTEMATIC LITERATURE REVIEW
    Hassan, Noor Hafizah
    Ismail, Zuraini
    Maarop, Nurazean
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS, 2015, : 456 - 463
  • [2] Information Security Culture: A Definition and A Literature Review
    AlHogail, Areej
    Mirza, Abdulrahman
    [J]. 2014 WORLD CONGRESS ON COMPUTER APPLICATIONS AND INFORMATION SYSTEMS (WCCAIS), 2014,
  • [3] A Systematic Literature Review of Information Security in Chatbots
    Yang, Jing
    Chen, Yen-Lin
    Por, Lip Yee
    Ku, Chin Soon
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (11):
  • [4] Human Factors in Information Security Culture: A Literature Review
    Glaspie, Henry W.
    Karwowski, Waldemar
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 269 - 280
  • [5] A systematic review of scales for measuring information security culture
    Orehek, Spela
    Petric, Gregor
    [J]. INFORMATION AND COMPUTER SECURITY, 2021, 29 (01) : 133 - 158
  • [6] Information Security Policy Compliance: Systematic Literature Review
    Angraini
    Alias, Rose Alinda
    Okfalisa
    [J]. FIFTH INFORMATION SYSTEMS INTERNATIONAL CONFERENCE, 2019, 161 : 1216 - 1224
  • [7] Systematic Literature Review: Information security behaviour on smartphone users
    Dawie, Ferdinand Jilan
    Masrek, Mohamad Noorman
    Rahman, Safawi Abdul
    [J]. ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2022, 7 : 275 - 281
  • [8] Information and cyber security maturity models: a systematic literature review
    Rabii, Anass
    Assoul, Saliha
    Ouazzani Touhami, Khadija
    Roudies, Ounsa
    [J]. INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 627 - 644
  • [9] Economic valuation for information security investment: a systematic literature review
    Schatz, Daniel
    Bashroush, Rabih
    [J]. INFORMATION SYSTEMS FRONTIERS, 2017, 19 (05) : 1205 - 1228
  • [10] Inter-organisational information security: a systematic literature review
    Karlsson, Fredrik
    Kolkowska, Ella
    Prenkert, Frans
    [J]. INFORMATION AND COMPUTER SECURITY, 2016, 24 (05) : 418 - 451