Information security culture: A systematic literature review

Information security culture becomes an enabler towards minimising the protection of security risk and incidents. This research will systematically identify and analyse published research exploring factors influencing information security culture. A systematic literature review is conducted througho...

Full description

Bibliographic Details
Main Authors: Hassan, Noor Hafizah, Ismail, Zuraini, Maarop, Nurazean
Format: Conference or Workshop Item
Language:English
Published: 2015
Subjects:
Online Access:https://repo.uum.edu.my/id/eprint/15599/1/PID205.pdf
_version_ 1825803564245581824
author Hassan, Noor Hafizah
Ismail, Zuraini
Maarop, Nurazean
author_facet Hassan, Noor Hafizah
Ismail, Zuraini
Maarop, Nurazean
author_sort Hassan, Noor Hafizah
collection UUM
description Information security culture becomes an enabler towards minimising the protection of security risk and incidents. This research will systematically identify and analyse published research exploring factors influencing information security culture. A systematic literature review is conducted throughout this process.40 papers were used in our synthesis of evidence with nine compatibility factors has been found to influence information security culture in organisation setting. One thousand two hundred and four studies were identified as 40 fulfilled the inclusion criteria. Of these, most (13%) were assessed being high quality, and three were rated very poor.Nine common factors were identified which are cultural differences, security awareness, security behaviour, top management commitment, trust, information sharing, security knowledge, security policy, and belief.The most common factors found was security behaviour that highly influences information security culture from analysis conducted.The result of this study also shows the gap that there is lack of studies conducted in healthcare informatics environments setting. Findings are useful in developing theoretical model that shows factors influencing information security culture in healthcare informatics environment
first_indexed 2024-07-04T05:59:10Z
format Conference or Workshop Item
id uum-15599
institution Universiti Utara Malaysia
language English
last_indexed 2024-07-04T05:59:10Z
publishDate 2015
record_format eprints
spelling uum-155992016-04-27T03:46:05Z https://repo.uum.edu.my/id/eprint/15599/ Information security culture: A systematic literature review Hassan, Noor Hafizah Ismail, Zuraini Maarop, Nurazean QA75 Electronic computers. Computer science Information security culture becomes an enabler towards minimising the protection of security risk and incidents. This research will systematically identify and analyse published research exploring factors influencing information security culture. A systematic literature review is conducted throughout this process.40 papers were used in our synthesis of evidence with nine compatibility factors has been found to influence information security culture in organisation setting. One thousand two hundred and four studies were identified as 40 fulfilled the inclusion criteria. Of these, most (13%) were assessed being high quality, and three were rated very poor.Nine common factors were identified which are cultural differences, security awareness, security behaviour, top management commitment, trust, information sharing, security knowledge, security policy, and belief.The most common factors found was security behaviour that highly influences information security culture from analysis conducted.The result of this study also shows the gap that there is lack of studies conducted in healthcare informatics environments setting. Findings are useful in developing theoretical model that shows factors influencing information security culture in healthcare informatics environment 2015-08-11 Conference or Workshop Item PeerReviewed application/pdf en https://repo.uum.edu.my/id/eprint/15599/1/PID205.pdf Hassan, Noor Hafizah and Ismail, Zuraini and Maarop, Nurazean (2015) Information security culture: A systematic literature review. In: 5th International Conference on Computing and Informatics (ICOCI) 2015, 11-13 August 2015, Istanbul, Turkey. http://www.icoci.cms.net.my/proceedings/2015/TOC.html
spellingShingle QA75 Electronic computers. Computer science
Hassan, Noor Hafizah
Ismail, Zuraini
Maarop, Nurazean
Information security culture: A systematic literature review
title Information security culture: A systematic literature review
title_full Information security culture: A systematic literature review
title_fullStr Information security culture: A systematic literature review
title_full_unstemmed Information security culture: A systematic literature review
title_short Information security culture: A systematic literature review
title_sort information security culture a systematic literature review
topic QA75 Electronic computers. Computer science
url https://repo.uum.edu.my/id/eprint/15599/1/PID205.pdf
work_keys_str_mv AT hassannoorhafizah informationsecuritycultureasystematicliteraturereview
AT ismailzuraini informationsecuritycultureasystematicliteraturereview
AT maaropnurazean informationsecuritycultureasystematicliteraturereview