A systematic literature review: Information security culture

Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from insid...

Full description

Bibliographic Details
Main Authors: Mahfuth, A., Yussof, S., Baker, A.A., Ali, N.
Published: 2018
Online Access:http://dspace.uniten.edu.my/jspui/handle/123456789/9028
id uniten-123456789-9028
recordtype eprints
spelling uniten-123456789-90282018-02-21T04:53:05Z A systematic literature review: Information security culture Mahfuth, A. Yussof, S. Baker, A.A. Ali, N. Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations. © 2017 IEEE. 2018-02-21T04:53:05Z 2018-02-21T04:53:05Z 2017 http://dspace.uniten.edu.my/jspui/handle/123456789/9028
repository_type Digital Repository
institution_category Local University
institution Universiti Tenaga Nasional
building UNITEN Institutional Repository
collection Online Access
description Human behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations. © 2017 IEEE.
author Mahfuth, A.
Yussof, S.
Baker, A.A.
Ali, N.
spellingShingle Mahfuth, A.
Yussof, S.
Baker, A.A.
Ali, N.
A systematic literature review: Information security culture
author_facet Mahfuth, A.
Yussof, S.
Baker, A.A.
Ali, N.
author_sort Mahfuth, A.
title A systematic literature review: Information security culture
title_short A systematic literature review: Information security culture
title_full A systematic literature review: Information security culture
title_fullStr A systematic literature review: Information security culture
title_full_unstemmed A systematic literature review: Information security culture
title_sort systematic literature review: information security culture
publishDate 2018
url http://dspace.uniten.edu.my/jspui/handle/123456789/9028
first_indexed 2018-09-05T08:08:51Z
last_indexed 2018-09-05T08:08:51Z
_version_ 1610754221764771840