Information security management and the human aspect in organizations. (13th November 2017)
- Record Type:
- Journal Article
- Title:
- Information security management and the human aspect in organizations. (13th November 2017)
- Main Title:
- Information security management and the human aspect in organizations
- Authors:
- Stewart, Harrison
Jürjens, Jan - Abstract:
- Abstract : Purpose: The aim of this study is to encourage management boards to recognize that employees play a major role in the management of information security. Thus, these issues need to be addressed efficiently, especially in organizations in which data are a valuable asset. Design/methodology/approach: Before developing the instrument for the survey, first, effective measurement built upon existing literature review was identified and developed and the survey questionnaires were set according to past studies and the findings based on qualitative analyses. Data were collected by using cross-sectional questionnaire and a Likert scale, whereby each question was related to an item as in the work ofWitherspoon et al. (2013 ). Data analysis was done using the SPSS.3B. Findings: Based on the results from three surveys and findings, a principle of information security compliance practices was proposed based on the authors' proposed nine-five-circle (NFC) principle that enhances information security management by identifying human conduct and IT security-related issues regarding the aspect of information security management. Furthermore, the authors' principle has enabled closing the gap between technology and humans in this study by proving that the factors in the present study's finding are interrelated and work together, rather than on their own. Research limitations/implications: The main objective of this study was to address the lack of research evidence on whatAbstract : Purpose: The aim of this study is to encourage management boards to recognize that employees play a major role in the management of information security. Thus, these issues need to be addressed efficiently, especially in organizations in which data are a valuable asset. Design/methodology/approach: Before developing the instrument for the survey, first, effective measurement built upon existing literature review was identified and developed and the survey questionnaires were set according to past studies and the findings based on qualitative analyses. Data were collected by using cross-sectional questionnaire and a Likert scale, whereby each question was related to an item as in the work ofWitherspoon et al. (2013 ). Data analysis was done using the SPSS.3B. Findings: Based on the results from three surveys and findings, a principle of information security compliance practices was proposed based on the authors' proposed nine-five-circle (NFC) principle that enhances information security management by identifying human conduct and IT security-related issues regarding the aspect of information security management. Furthermore, the authors' principle has enabled closing the gap between technology and humans in this study by proving that the factors in the present study's finding are interrelated and work together, rather than on their own. Research limitations/implications: The main objective of this study was to address the lack of research evidence on what mobilizes and influences information security management development and implementation. This objective has been fulfilled by surveying, collecting and analyzing data and by giving an account of the attributes that hinder information security management. Accordingly, a major practical contribution of the present research is the empirical data it provides that enable obtaining a bigger picture and precise information about the real issues that cause information security management shortcomings. Practical implications: In this sense, despite the fact that this study has limitations concerning the development of a diagnostic tool, it is obviously the main procedure for the measurements of a framework to assess information security compliance policies in the organizations surveyed. Social implications: The present study's discoveries recommend in actuality that using flexible tools that can be scoped to meet individual organizational needs have positive effects on the implementation of information security management policies within an organization. Accordingly, the research proposes that organizations should forsake the oversimplified generalized guidelines that neglect the verification of the difference in information security requirements in various organizations. Instead, they should focus on the issue of how to sustain and enhance their organization's compliance through a dynamic compliance process that involves awareness of the compliance regulation, controlling integration and closing gaps. Originality/value: The rapid growth of information technology (IT) has created numerous business opportunities. At the same time, this growth has increased information security risk. IT security risk is an important issue in industrial sectors, and in organizations that are innovating owing to globalization or changes in organizational culture. Previously, technology-associated risk assessments focused on various technology factors, but as of the early twenty-first century, the most important issue identified in technology risk studies is the human factor. … (more)
- Is Part Of:
- Information and computer security. Volume 25:Number 5(2017)
- Journal:
- Information and computer security
- Issue:
- Volume 25:Number 5(2017)
- Issue Display:
- Volume 25, Issue 5 (2017)
- Year:
- 2017
- Volume:
- 25
- Issue:
- 5
- Issue Sort Value:
- 2017-0025-0005-0000
- Page Start:
- 494
- Page End:
- 534
- Publication Date:
- 2017-11-13
- Subjects:
- Information security -- Culture and technology -- Employee behaviour in technology -- IT human aspects -- Security and leadership
Computer security -- Management -- Periodicals
Computer networks -- Security measures -- Periodicals
Data protection -- Management -- Periodicals
658.47 - Journal URLs:
- http://www.emeraldinsight.com/loi/ics ↗
http://www.emeraldinsight.com/ ↗ - DOI:
- 10.1108/ICS-07-2016-0054 ↗
- Languages:
- English
- ISSNs:
- 2056-4961
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4481.796000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 8600.xml