Fostering information security policies compliance with ISA-95-based framework: an empirical study of oil and gas employees

被引:0
|
作者
Rao Faizan Ali
P. D. D. Dominic
Sadaf Hina
Sheraz Naseer
机构
[1] University of Management and Technology,School of Systems and Technology
[2] Universiti Teknologi PETRONAS,Department of Computer and Information Sciences
[3] University of Salford,School of Science, Engineering and Environment
[4] Xeven Solutions,undefined
关键词
Oil and gas organizations; ISA-95; Organizational governance; Social bonding;
D O I
暂无
中图分类号
学科分类号
摘要
Oil and gas (O&G) organizations are progressively being digitalized in order to facilitate substantial information flow to remain competitive in the information age. This critical sector is spearheading the establishment of technical security measures to mitigate information security risks, yet employee behavioral influence remains an ongoing challenge in assuring information security. Existing studies of this domain primarily focus on employee behavior reshaping through multiple psychological theories. However, these studies ignore how these critical infrastructures implement information security. Most such infrastructures follow the International Society of Automation (ISA)-95 levels of automation and implement information security controls in line with these levels. This research paper proposed a theoretical framework to enhance information security policy compliance (ISPC) at level 4 to level 2 automation level in O&G organizations. To support the hypotheses, data were collected from 13 Malaysian O&G organizations. A total of 254 O&G employees participated in the survey and the structural equation modeling technique was used for data analysis. The study confirmed that ISA-95-based organizational governance factors and social bonding could enhance ISPC in O&G organizations. However, risk assessment and involvement factors have shown less support to the notion. For information systems practitioners, this study has shown how to enhance ISPC in O&G organizations through ISA-95-based organizational governance and social bonding.
引用
收藏
页码:1197 / 1213
页数:16
相关论文
共 7 条
  • [1] Fostering information security policies compliance with ISA-95-based framework: an empirical study of oil and gas employees
    Ali, Rao Faizan
    Dominic, P. D. D.
    Hina, Sadaf
    Naseer, Sheraz
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (02) : 1197 - 1213
  • [2] Employees' adherence to information security policies: An empirical study
    Siponen, Mikko
    Pahnila, Seppo
    Mahmood, Adam
    [J]. NEW APPROACHES FOR SECURITY, PRIVACY AND TRUST IN COMPLEX ENVIRONMENTS, 2007, 232 : 133 - +
  • [3] Factors Impacting Users' Compliance with Information Security Policies: An Empirical Study
    Alzahrani, Latifa
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (10) : 437 - 447
  • [4] Which Factors Explain Employees' Adherence to Information Security Policies? An Empirical Study
    Pahnila, Seppo
    Siponen, Mikko
    Mahmood, Adam
    [J]. PACIFIC ASIA CONFERENCE ON INFORMATION SYSTEMS 2007, SECTIONS 1-6, 2007,
  • [5] Organizational Governance, Social Bonds and Information Security Policy Compliance: A Perspective towards Oil and Gas Employees
    Ali, Rao Faizan
    Dominic, P. D. D.
    Ali, Kashif
    [J]. SUSTAINABILITY, 2020, 12 (20) : 1 - 27
  • [6] Cognitive-affective drivers of employees' daily compliance with information security policies: A multilevel, longitudinal study
    D'Arcy, John
    Lowry, Paul Benjamin
    [J]. INFORMATION SYSTEMS JOURNAL, 2019, 29 (01) : 43 - 69
  • [7] INFORMATION SECURITY POLICY COMPLIANCE: AN EMPIRICAL STUDY OF RATIONALITY-BASED BELIEFS AND INFORMATION SECURITY AWARENESS
    Bulgurcu, Burcu
    Cavusoglu, Hasan
    Benbasat, Izak
    [J]. MIS QUARTERLY, 2010, 34 (03) : 523 - 548