Information Security Culture Model. A Case Study

被引:0
|
作者
Marchand-Nino, William-Rogelio [1 ]
Huaman Samaniego, Hector [2 ]
机构
[1] Univ Nacl Agr Selva, Tingo Maria, Peru
[2] Univ Nacl Ctr Peru, Huancayo, Peru
关键词
information security; culture; human factors; information assets protection; DESIGN;
D O I
10.1109/CLEI53233.2021.9639939
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This research covers the problem related to user behavior and its relationship with the protection of computer assets in terms of confidentiality, integrity, and availability. The main objective was to evaluate the relationship between the dimensions of awareness, compliance and appropriation of the information security culture and the asset protection variable, the ISCA diagnostic instrument was applied, and social engineering techniques were incorporated for this process. The results show the levels of awareness, compliance and appropriation of the university that was considered as a case study, these oscillate between the second and third level of four levels. Similarly, the performance regarding asset protection ranges from low to medium. It was concluded that there is a significant relationship between the variables of the investigation, verifying that of the total types of incidents registered in the study case, approximately 69% are associated with human behavior. As a contribution, an information security culture model was formulated whose main characteristic is a complementary diagnostic process between surveys and social engineering techniques, the model also includes the information security management system, risk management and security incident handling as part of the information security culture ecosystem in an enterprise.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Information Security Culture Assessment: Case Study
    Al-Mayahi, Ibrahim
    Mansoor, Sa'ad P.
    [J]. 2013 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND TECHNOLOGY (ICIST), 2013, : 789 - 792
  • [2] The impacts of organizational culture on information security culture: a case study
    Tang, Mincong
    Li, Meng'gang
    Zhang, Tao
    [J]. INFORMATION TECHNOLOGY & MANAGEMENT, 2016, 17 (02): : 179 - 186
  • [3] The impacts of organizational culture on information security culture: a case study
    Mincong Tang
    Meng’gang Li
    Tao Zhang
    [J]. Information Technology and Management, 2016, 17 : 179 - 186
  • [4] Democracy, culture and information security: A case study in Zanzibar
    Shaaban, Hussein
    Conrad, Marc
    [J]. Information Management and Computer Security, 2013, 21 (03): : 191 - 201
  • [5] Organizational Transformation and Information Security Culture: A Telecom Case Study
    Dhillon, Gurpreet
    Chowdhuri, Romilla
    Pedron, Cristiane
    [J]. ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, IFIP TC 11 INTERNATIONAL CONFERENCE, SEC 2014, 2014, 428 : 431 - 437
  • [6] Interpreting information security culture: An organizational transformation case study
    Dhillon, Gurpreet
    Syed, Romilla
    Pedron, Cristiane
    [J]. COMPUTERS & SECURITY, 2016, 56 : 63 - 69
  • [7] Information Security Culture Dimensions in Information Security Policy Compliance Study: A Review
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    [J]. ADVANCED SCIENCE LETTERS, 2018, 24 (02) : 943 - 946
  • [8] A dimension-based information security culture model and its relationship with employees' security behavior: A case study in Malaysian higher educational institutions
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    [J]. INFORMATION SECURITY JOURNAL, 2019, 28 (03): : 55 - 80
  • [9] The Formulation of Comprehensive Information Security Culture Dimensions for Information Security Policy Compliance Study
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    [J]. ADVANCED SCIENCE LETTERS, 2018, 24 (10) : 7690 - 7695
  • [10] A Model for Information Security Culture with Innovation and Creativity as Enablers
    Da Veiga, Adele
    [J]. HUMAN ASPECTS OF INFORMATION SECURITY AND ASSURANCE, HAISA 2022, 2022, 658 : 186 - 196