Establishing A Personalized Information Security Culture

被引:3
|
作者
Talib, Shuhaili [1 ,2 ]
Clarke, Nathan L. [1 ,3 ]
Furnell, Steven M. [1 ,3 ]
机构
[1] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth, Devon, England
[2] Int Islam Univ, Kulliyyah Informat & Commun Technol, Dept Informat Syst, Kuala Lumpur, Malaysia
[3] Edith Cowan Univ, Churchlands, WA, Australia
关键词
Home; Information Security; Information Security Awareness; Security Culture; Security Management; Workplace;
D O I
10.4018/jmcmc.2011010105
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Good security cannot be achieved through technical means alone and a solid understanding of the issues and how to protect one's self is required from users. Whilst many initiatives, programs and strategies have been proposed to improve the level of information security awareness, most have been directed at organizations. Given people's use of technology is primarily focused between the workplace and home; this paper seeks to understand the knowledge and practice relationship between these environments. Through a developed survey, it was identified that the majority of the learning about information security occurred in the workplace, where clear motivations, such as legislation and regulation, existed. Results found that users were more than willing to engage with such awareness raising initiatives. From a comparison of practice between work and home environments, it was found that this knowledge and practice obtained at the workplace was transferred to the home environment. Given this positive transferability of knowledge and the willingness to learn about how to remain secure, an opportunity exists to move away from specific organizational awareness programs and to move towards awareness raising strategies that will develop an all-round individual security culture for users independent of the environment they are operating in.
引用
收藏
页码:63 / 79
页数:17
相关论文
共 50 条
  • [31] Security issues arising in establishing a regional health information infrastructure
    Neame, R
    Olson, MJ
    [J]. INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2004, 73 (03) : 285 - 290
  • [32] Establishing an Integrated Push Notification System with Information Security Mechanism
    Wu, Hsin-Te
    [J]. BIO-INSPIRED INFORMATION AND COMMUNICATIONS TECHNOLOGIES, BICT 2021, 2021, 403 : 26 - 32
  • [33] A pattern-based method for establishing a cloud-specific information security management system: Establishing information security management systems for clouds considering security, privacy, and legal compliance
    Beckers K.
    Côté I.
    Faßbender S.
    Heisel M.
    Hofbauer S.
    [J]. Requirements Engineering, 2013, 18 (4) : 343 - 395
  • [34] Developing Personalized Security Information Service Using Open Data
    Kagawa, Takuhiro
    Saiki, Sachio
    Nakamura, Masahide
    [J]. 2017 18TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNDP 2017), 2017, : 465 - 470
  • [35] The Formulation of Comprehensive Information Security Culture Dimensions for Information Security Policy Compliance Study
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    [J]. ADVANCED SCIENCE LETTERS, 2018, 24 (10) : 7690 - 7695
  • [36] Deriving the Relationship between Organizational Culture and Information Security Culture
    Hassan, Noor Hafizah
    Ismail, Zuraini
    [J]. VISION 2020: INNOVATION, DEVELOPMENT SUSTAINABILITY, AND ECONOMIC GROWTH, VOLS 1-3, 2013, : 926 - 932
  • [37] The impacts of organizational culture on information security culture: a case study
    Tang, Mincong
    Li, Meng'gang
    Zhang, Tao
    [J]. INFORMATION TECHNOLOGY & MANAGEMENT, 2016, 17 (02): : 179 - 186
  • [38] The impacts of organizational culture on information security culture: a case study
    Mincong Tang
    Meng’gang Li
    Tao Zhang
    [J]. Information Technology and Management, 2016, 17 : 179 - 186
  • [39] Social Engineering for Diagnostic the Information Security Culture
    Marchand-Nino, William-Rogelio
    Guzman Fonseca, Bruno Paolo
    [J]. 2019 IEEE 39TH CENTRAL AMERICA AND PANAMA CONVENTION (CONCAPAN XXXIX), 2019, : 233 - 238
  • [40] Information security culture - validation of an assessment instrument
    da Veiga, A.
    Martins, N.
    Eloff, J. H. P.
    [J]. SOUTHERN AFRICAN BUSINESS REVIEW, 2007, 11 (01) : 147 - 166