首页> 外文期刊>Information management & computer security >Comparing the information security culture of employees who had read the information security policy and those who had not: Illustrated through an empirical study
【24h】

Comparing the information security culture of employees who had read the information security policy and those who had not: Illustrated through an empirical study

机译:比较已阅读信息安全政策的员工和未阅读信息安全政策的员工的信息安全文化:通过实证研究进行说明

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - This study aims, firstly, to determine what influence the information security policy has on the information security culture by comparing the culture of employees who read the policy to those who do not, and, secondly, whether a stronger information security culture is embedded over time if more employees have read the information security policy. Design/methodology/approach - An empirical study is conducted at four intervals over eight years across 12 countries using a validated information security culture assessment (ISCA) questionnaire. Findings - The overall information security culture average scores as well as individual statements for all four survey assessments were significantly more positive for employees who had read the information security policy compared with employees who had not. The overall information security culture also improved from one assessment to the next. Research limitations/implications - The information security culture should be measured and benchmarked over time to monitor change and identify and prioritise actions to improve the information security culture. If employees read the information security policy, it has a positive influence on the information security culture of an organisation. Practical implications - Organisations should ensure that employees have read the information security policy to aid in minimising the human risk, related errors and incidents and, ultimately, to instil a stronger information security culture with a higher level of compliant behaviour. Originality/value - This research confirms theoretical research indicating that the information security policy could influence the information security culture positively. It provides novel and statistical evidence illustrating that if employees read the information security policy, they have a stronger information security culture and that the culture can be improved through targeted interventions using an ISCA.
机译:目的-这项研究的目的是,首先通过比较阅读该政策的员工的文化与不阅读该政策的员工的文化,来确定信息安全策略对信息安全文化的影响,其次,是否嵌入了更强大的信息安全文化随着时间的流逝,如果更多的员工已阅读信息安全政策。设计/方法/方法-使用经过验证的信息安全文化评估(ISCA)问卷调查表,在12个国家/地区,每隔八年的时间里,每隔四个间隔进行一次实证研究。调查结果-与未阅读信息安全政策的员工相比,阅读了信息安全政策的员工的总体信息安全文化平均评分以及所有四项调查评估的个人陈述要积极得多。整体的信息安全文化也从一项评估改进到另一项评估。研究的局限性/含意-信息安全文化应随时间进行衡量和基准测试,以监控变化并确定和优先考虑改善信息安全文化的措施。如果员工阅读了信息安全政策,它将对组织的信息安全文化产生积极影响。实际意义-组织应确保员工已阅读信息安全政策,以帮助最大程度地减少人为风险,相关的错误和事件,并最终灌输更强的信息安全文化和更高的合规行为。原创性/价值-该研究证实了理论研究,表明信息安全策略可以对信息安全文化产生积极影响。它提供了新颖的统​​计证据,说明如果员工阅读了信息安全政策,他们将拥有更强大的信息安全文化,并且可以使用ISCA通过有针对性的干预措施来改善这种文化。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号