An approach to information security culture change combining ADKAR and the ISCA questionnaire to aid transition to the desired culture. (12th November 2018)
- Record Type:
- Journal Article
- Title:
- An approach to information security culture change combining ADKAR and the ISCA questionnaire to aid transition to the desired culture. (12th November 2018)
- Main Title:
- An approach to information security culture change combining ADKAR and the ISCA questionnaire to aid transition to the desired culture
- Authors:
- Da Veiga, Adéle
- Abstract:
- Abstract : Purpose: Employee behaviour is a continuous concern owing to the number of information security incidents resulting from employee behaviour. The purpose of this paper is to propose an approach to information security culture change management (ISCCM) that integrates existing change management approaches, such as the ADKAR model of Prosci, and the Information Security Culture Assessment (ISCA) diagnostic instrument (questionnaire), to aid in addressing the risk of employee behaviour that could compromise information security. Design/methodology/approach: The ISCCM approach is constructed based on literature and the inclusion of the ISCA diagnostic instrument. The ISCA diagnostic instrument statements are also presented in this paper. The ISCCM approach using ISCA is illustrated using data from an empirical study. Findings: The ISCCM approach was found to be useful in defining change management interventions for organisations using the data of the ISCA survey. Employees' perception and acceptance of change to ensure information security and the effectiveness of the information security training initiatives improved significantly from the as-is survey to the follow-up survey. Research limitations/implications: The research illustrates the ISCCM approach and shows how it should be combined with the ISCA diagnostic instrument. Future research will focus on including a qualitative assessment of information security culture to complement the empirical data. PracticalAbstract : Purpose: Employee behaviour is a continuous concern owing to the number of information security incidents resulting from employee behaviour. The purpose of this paper is to propose an approach to information security culture change management (ISCCM) that integrates existing change management approaches, such as the ADKAR model of Prosci, and the Information Security Culture Assessment (ISCA) diagnostic instrument (questionnaire), to aid in addressing the risk of employee behaviour that could compromise information security. Design/methodology/approach: The ISCCM approach is constructed based on literature and the inclusion of the ISCA diagnostic instrument. The ISCA diagnostic instrument statements are also presented in this paper. The ISCCM approach using ISCA is illustrated using data from an empirical study. Findings: The ISCCM approach was found to be useful in defining change management interventions for organisations using the data of the ISCA survey. Employees' perception and acceptance of change to ensure information security and the effectiveness of the information security training initiatives improved significantly from the as-is survey to the follow-up survey. Research limitations/implications: The research illustrates the ISCCM approach and shows how it should be combined with the ISCA diagnostic instrument. Future research will focus on including a qualitative assessment of information security culture to complement the empirical data. Practical implications: Organisations do not have to rely on or adapt organisational development approaches to change their information security culture – they can use the proposed ISCCM approach, which has been customised from information security and change management approaches, together with the presented ISCA questionnaire, to address information security culture change purposefully. Originality/value: The proposed ISCCM approach can be applied to complement existing information security management approaches through a holistic and structured approach that combines the ADKAR model, Prosci's approach of change management and the ISCA diagnostic instrument. It will enable organisations to focus on transitioning to a positive or desired information security culture that mitigates the risk of the human element in the protection of information. … (more)
- Is Part Of:
- Information and computer security. Volume 26:Number 5(2018)
- Journal:
- Information and computer security
- Issue:
- Volume 26:Number 5(2018)
- Issue Display:
- Volume 26, Issue 5 (2018)
- Year:
- 2018
- Volume:
- 26
- Issue:
- 5
- Issue Sort Value:
- 2018-0026-0005-0000
- Page Start:
- 584
- Page End:
- 612
- Publication Date:
- 2018-11-12
- Subjects:
- Change management -- Questionnaire -- Human -- Information security culture -- ADKAR -- ISCA
Computer security -- Management -- Periodicals
Computer networks -- Security measures -- Periodicals
Data protection -- Management -- Periodicals
658.47 - Journal URLs:
- http://www.emeraldinsight.com/loi/ics ↗
http://www.emeraldinsight.com/ ↗ - DOI:
- 10.1108/ICS-08-2017-0056 ↗
- Languages:
- English
- ISSNs:
- 2056-4961
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4481.796000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 8776.xml