Improving information system security by evaluating human factors

Health Information System (HIS) has been implemented in Malaysia since late 1990s. HIS is an integration of several hospitals’ information system to manage administration works, patients and clinical records. Accessing HIS data through the internet make it more vulnerable to data lost, misuses and a...

Full description

Bibliographic Details
Main Author: Soltanmohammadi, Saeed
Format: Thesis
Language:English
Published: 2013
Subjects:
Online Access:http://eprints.utm.my/37074/5/SaeedSoltanmohammadiMFSKSM2013.pdf
_version_ 1796857614633533440
author Soltanmohammadi, Saeed
author_facet Soltanmohammadi, Saeed
author_sort Soltanmohammadi, Saeed
collection ePrints
description Health Information System (HIS) has been implemented in Malaysia since late 1990s. HIS is an integration of several hospitals’ information system to manage administration works, patients and clinical records. Accessing HIS data through the internet make it more vulnerable to data lost, misuses and attacks. Health data is extremely sensitive, therefore they require high protection and information security must be carefully watched as it plays an important role to protect the data from being stolen or harmed. Despite the vast research in information security, the human factor has been neglected from the research community, with most security research giving focus on the technological component of an information technology system. The human factor is still subject to attacks and thus, in need of auditing and addressing any existing vulnerabilities. This research evaluates the human factor by the creation of a survey which examines three distinct user properties. Each of these properties comprises a series of questions, which with their turn assist on confirmation or refutation of three hypotheses. The survey was conducted on five public and private hospitals in Malaysia and distributed to all members of staff who have access on electronic information. Results have shown that the human factor has a significant role in information security; among the surveyed factors (organizational factor, motivational factor and learning), it is confirmed that Learning has the most effect on information system security. This research has addressed two sub factors of learning that are organizational learning and individual learning. In order to improve the information system security in hospitals, it is recommended for future study to consider some other factors except these two sub factors in learning.
first_indexed 2024-03-05T19:00:25Z
format Thesis
id utm.eprints-37074
institution Universiti Teknologi Malaysia - ePrints
language English
last_indexed 2024-03-05T19:00:25Z
publishDate 2013
record_format dspace
spelling utm.eprints-370742017-07-04T00:39:49Z http://eprints.utm.my/37074/ Improving information system security by evaluating human factors Soltanmohammadi, Saeed QA75 Electronic computers. Computer science Health Information System (HIS) has been implemented in Malaysia since late 1990s. HIS is an integration of several hospitals’ information system to manage administration works, patients and clinical records. Accessing HIS data through the internet make it more vulnerable to data lost, misuses and attacks. Health data is extremely sensitive, therefore they require high protection and information security must be carefully watched as it plays an important role to protect the data from being stolen or harmed. Despite the vast research in information security, the human factor has been neglected from the research community, with most security research giving focus on the technological component of an information technology system. The human factor is still subject to attacks and thus, in need of auditing and addressing any existing vulnerabilities. This research evaluates the human factor by the creation of a survey which examines three distinct user properties. Each of these properties comprises a series of questions, which with their turn assist on confirmation or refutation of three hypotheses. The survey was conducted on five public and private hospitals in Malaysia and distributed to all members of staff who have access on electronic information. Results have shown that the human factor has a significant role in information security; among the surveyed factors (organizational factor, motivational factor and learning), it is confirmed that Learning has the most effect on information system security. This research has addressed two sub factors of learning that are organizational learning and individual learning. In order to improve the information system security in hospitals, it is recommended for future study to consider some other factors except these two sub factors in learning. 2013-08 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/37074/5/SaeedSoltanmohammadiMFSKSM2013.pdf Soltanmohammadi, Saeed (2013) Improving information system security by evaluating human factors. Masters thesis, Universiti Teknologi Malaysia, Faculty of Computing. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:70077?site_name=Restricted Repository
spellingShingle QA75 Electronic computers. Computer science
Soltanmohammadi, Saeed
Improving information system security by evaluating human factors
title Improving information system security by evaluating human factors
title_full Improving information system security by evaluating human factors
title_fullStr Improving information system security by evaluating human factors
title_full_unstemmed Improving information system security by evaluating human factors
title_short Improving information system security by evaluating human factors
title_sort improving information system security by evaluating human factors
topic QA75 Electronic computers. Computer science
url http://eprints.utm.my/37074/5/SaeedSoltanmohammadiMFSKSM2013.pdf
work_keys_str_mv AT soltanmohammadisaeed improvinginformationsystemsecuritybyevaluatinghumanfactors