Establishing A Personalized Information Security Culture

被引:3
|
作者
Talib, Shuhaili [1 ,2 ]
Clarke, Nathan L. [1 ,3 ]
Furnell, Steven M. [1 ,3 ]
机构
[1] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth, Devon, England
[2] Int Islam Univ, Kulliyyah Informat & Commun Technol, Dept Informat Syst, Kuala Lumpur, Malaysia
[3] Edith Cowan Univ, Churchlands, WA, Australia
关键词
Home; Information Security; Information Security Awareness; Security Culture; Security Management; Workplace;
D O I
10.4018/jmcmc.2011010105
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Good security cannot be achieved through technical means alone and a solid understanding of the issues and how to protect one's self is required from users. Whilst many initiatives, programs and strategies have been proposed to improve the level of information security awareness, most have been directed at organizations. Given people's use of technology is primarily focused between the workplace and home; this paper seeks to understand the knowledge and practice relationship between these environments. Through a developed survey, it was identified that the majority of the learning about information security occurred in the workplace, where clear motivations, such as legislation and regulation, existed. Results found that users were more than willing to engage with such awareness raising initiatives. From a comparison of practice between work and home environments, it was found that this knowledge and practice obtained at the workplace was transferred to the home environment. Given this positive transferability of knowledge and the willingness to learn about how to remain secure, an opportunity exists to move away from specific organizational awareness programs and to move towards awareness raising strategies that will develop an all-round individual security culture for users independent of the environment they are operating in.
引用
收藏
页码:63 / 79
页数:17
相关论文
共 50 条
  • [1] Establishing information security policy compliance culture in organizations
    Amankwa, Eric
    Loock, Marianne
    Kritzinger, Elmarie
    [J]. INFORMATION AND COMPUTER SECURITY, 2018, 26 (04) : 420 - 436
  • [2] PERSONALIZED INFORMATION SECURITY IN HEALTH INFORMATION SYSTEMS
    Kablukov, A. A.
    Ivankova, I. A.
    [J]. ZAPOROZHYE MEDICAL JOURNAL, 2012, (06) : 91 - 93
  • [3] A Psychological Approach to Information Security Some Ideas for Establishing Information Security Psychology
    Uchida, Katsuya
    [J]. HUMAN-COMPUTER INTERACTION: DESIGN AND EVALUATION, PT I, 2015, 9169 : 96 - 104
  • [4] Information security culture
    Martins, A
    Eloff, J
    [J]. SECURITY IN THE INFORMATION SOCIETY: VISIONS AND PERSPECTIVES, 2002, 86 : 203 - 214
  • [5] ESTABLISHING A SECURITY CULTURE: POINTERS FOR SENIOR MANAGEMENT
    Jones, Nigel A.
    Trim, Peter R. J.
    [J]. STRATEGIZING RESILIENCE AND REDUCING VULNERABILITY, 2009, : 165 - 179
  • [6] Analyzing information security culture: Increased trust by an appropriate information security culture
    Schlienger, T
    Teufel, S
    [J]. 14TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2003, : 405 - 409
  • [7] Establishing an Information Systems Security Organization (ISSO)
    Kovacich, G
    [J]. COMPUTERS & SECURITY, 1998, 17 (07) : 600 - 612
  • [8] IMPACTS OF COMPREHENSIVE INFORMATION SECURITY PROGRAMS ON INFORMATION SECURITY CULTURE
    Chen, Yan
    Ramamurthy, K.
    Wen, Kuang-Wei
    [J]. JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2015, 55 (03) : 11 - 19
  • [9] Information Security Culture: A Survey
    Mazhelis, Oleksiy
    Isomaki, Hannakaisa
    [J]. PROCEEDINGS OF THE 8TH INTERNATIONAL NETWORK CONFERENCE (INC 2010), 2010, : 153 - 157
  • [10] Enablers of information security culture
    Munteanu, Adrian-Bogdanel
    Fotache, Doina
    [J]. GLOBALIZATION AND HIGHER EDUCATION IN ECONOMICS AND BUSINESS ADMINISTRATION - GEBA 2013, 2015, 20 : 414 - 422