A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions

Despite strong recommendations by scholars to establish Information Security Culture (ISC), the lack of ISC guidelines persists, particularly in aspects that could effectively improve employees’ security behavior in an organization. This study proposes an ISC model based on seven new formulated dime...

Full description

Bibliographic Details
Main Authors: Akhyari, Nasir, Ruzaini, Abdullah Arshah, Ab Hamid, Mohd Rashid
Format: Article
Language:English
Published: Taylor and Francis Inc. 2019
Subjects:
Online Access:http://umpir.ump.edu.my/id/eprint/30435/1/A%20dimension-based%20information%20security%20culture%20model%20.pdf
_version_ 1825813683728547840
author Akhyari, Nasir
Ruzaini, Abdullah Arshah
Ab Hamid, Mohd Rashid
author_facet Akhyari, Nasir
Ruzaini, Abdullah Arshah
Ab Hamid, Mohd Rashid
author_sort Akhyari, Nasir
collection UMP
description Despite strong recommendations by scholars to establish Information Security Culture (ISC), the lack of ISC guidelines persists, particularly in aspects that could effectively improve employees’ security behavior in an organization. This study proposes an ISC model based on seven new formulated dimensions to examine its influence on employees’ Information Security Policy (ISP) compliance behavior. The dimensions represent specific aspects of ISC and were formulated based on widely accepted concepts of Organizational Culture and ISC. The model was tested at 19 out of 21 public universities in Malaysia and validated using Partial Least Square Structural Equation Modelling (PLS-SEM). Findings revealed all seven dimensions are significant in contributing to the underlying concept of ISC, with Information Security Knowledge being the most important dimension. This ISC concept was also found to be significant in influencing ISP compliance behavior. This study contributes to ISC literature in terms of conceptualization and operationalization of an ISC concept based on the new comprehensive dimensions in relation to ISP compliance behavior. The model could be employed by practitioners in assessing, improving and cultivating a positive ISC that would effectively influence employees’ security behavior in higher educational institutions.
first_indexed 2024-03-06T12:47:40Z
format Article
id UMPir30435
institution Universiti Malaysia Pahang
language English
last_indexed 2024-03-06T12:47:40Z
publishDate 2019
publisher Taylor and Francis Inc.
record_format dspace
spelling UMPir304352021-01-11T06:23:08Z http://umpir.ump.edu.my/id/eprint/30435/ A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions Akhyari, Nasir Ruzaini, Abdullah Arshah Ab Hamid, Mohd Rashid LB2300 Higher Education QA Mathematics QA76 Computer software Despite strong recommendations by scholars to establish Information Security Culture (ISC), the lack of ISC guidelines persists, particularly in aspects that could effectively improve employees’ security behavior in an organization. This study proposes an ISC model based on seven new formulated dimensions to examine its influence on employees’ Information Security Policy (ISP) compliance behavior. The dimensions represent specific aspects of ISC and were formulated based on widely accepted concepts of Organizational Culture and ISC. The model was tested at 19 out of 21 public universities in Malaysia and validated using Partial Least Square Structural Equation Modelling (PLS-SEM). Findings revealed all seven dimensions are significant in contributing to the underlying concept of ISC, with Information Security Knowledge being the most important dimension. This ISC concept was also found to be significant in influencing ISP compliance behavior. This study contributes to ISC literature in terms of conceptualization and operationalization of an ISC concept based on the new comprehensive dimensions in relation to ISP compliance behavior. The model could be employed by practitioners in assessing, improving and cultivating a positive ISC that would effectively influence employees’ security behavior in higher educational institutions. Taylor and Francis Inc. 2019-05-04 Article PeerReviewed pdf en http://umpir.ump.edu.my/id/eprint/30435/1/A%20dimension-based%20information%20security%20culture%20model%20.pdf Akhyari, Nasir and Ruzaini, Abdullah Arshah and Ab Hamid, Mohd Rashid (2019) A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions. Information Security Journal, 28 (3). pp. 55-80. ISSN 1939-3555. (Published) https://doi.org/10.1080/19393555.2019.1643956 https://doi.org/10.1080/19393555.2019.1643956
spellingShingle LB2300 Higher Education
QA Mathematics
QA76 Computer software
Akhyari, Nasir
Ruzaini, Abdullah Arshah
Ab Hamid, Mohd Rashid
A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions
title A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions
title_full A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions
title_fullStr A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions
title_full_unstemmed A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions
title_short A dimension-based information security culture model and its relationship with employees’ security behavior: A case study in Malaysian higher educational institutions
title_sort dimension based information security culture model and its relationship with employees security behavior a case study in malaysian higher educational institutions
topic LB2300 Higher Education
QA Mathematics
QA76 Computer software
url http://umpir.ump.edu.my/id/eprint/30435/1/A%20dimension-based%20information%20security%20culture%20model%20.pdf
work_keys_str_mv AT akhyarinasir adimensionbasedinformationsecurityculturemodelanditsrelationshipwithemployeessecuritybehavioracasestudyinmalaysianhighereducationalinstitutions
AT ruzainiabdullaharshah adimensionbasedinformationsecurityculturemodelanditsrelationshipwithemployeessecuritybehavioracasestudyinmalaysianhighereducationalinstitutions
AT abhamidmohdrashid adimensionbasedinformationsecurityculturemodelanditsrelationshipwithemployeessecuritybehavioracasestudyinmalaysianhighereducationalinstitutions
AT akhyarinasir dimensionbasedinformationsecurityculturemodelanditsrelationshipwithemployeessecuritybehavioracasestudyinmalaysianhighereducationalinstitutions
AT ruzainiabdullaharshah dimensionbasedinformationsecurityculturemodelanditsrelationshipwithemployeessecuritybehavioracasestudyinmalaysianhighereducationalinstitutions
AT abhamidmohdrashid dimensionbasedinformationsecurityculturemodelanditsrelationshipwithemployeessecuritybehavioracasestudyinmalaysianhighereducationalinstitutions