The Enemy Within: A Behavioural Intention Model and an Information Security Awareness Process

被引:0
|
作者
Gundu, Tapiwa [1 ]
Flowerday, Stephen V. [1 ]
机构
[1] Univ Ft Hare, Dept Informat Syst, E London, South Africa
关键词
Information Security Awareness; Security Behaviour; POLICY COMPLIANCE; CULTURE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Most employees in small and medium enterprise (SME) engineering firms now have access to their own personal workstations which have become part of their daily functions. This has led to an increased need for information security management to safeguard against loss/alteration or theft of the firm's important information. SMEs tend to be concerned with vulnerabilities from external threats, although industry research suggests that a substantial proportion of security incidents originate from insiders within the firm. Hence, physical preventative measures such as antivirus software and firewalls are proving to solve only part of the problem as the employees controlling them do not have adequate information security knowledge. This tends to expose the firm to costly mistakes that can be made by naive/uninformed employees. This paper presents an information security awareness process that seeks to cultivate positive security behaviours using the behavioural intentions models i.e. the Theory of Reasoned Action and the Protection Motivation Theory. The process presented has been tested at an SME engineering firm, and findings are also presented and discussed in this paper.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] IGNORANCE TO AWARENESS: TOWARDS AN INFORMATION SECURITY AWARENESS PROCESS
    Gundu, T.
    Flowerday, S. V.
    SAIEE AFRICA RESEARCH JOURNAL, 2013, 104 (02): : 69 - 79
  • [2] A model for information security vulnerability awareness
    Mejias, Roberto J.
    Greer, Joshua J.
    Greer, Gabrila C.
    Shepherd, Morgan M.
    Reyes, Raul Y.
    COMPUTERS & SECURITY, 2025, 151
  • [3] Exploring the role of gamified information security education systems on information security awareness and protection behavioral intention
    Hao Chen
    Yan Zhang
    Song Zhang
    Tu Lyu
    Education and Information Technologies, 2023, 28 : 15915 - 15948
  • [4] Exploring the role of gamified information security education systems on information security awareness and protection behavioral intention
    Chen, Hao
    Zhang, Yan
    Zhang, Song
    Lyu, Tu
    EDUCATION AND INFORMATION TECHNOLOGIES, 2023, 28 (12) : 15915 - 15948
  • [5] Information security management: An information security retrieval and awareness model for industry
    Kritzinger, E.
    Smith, E.
    COMPUTERS & SECURITY, 2008, 27 (5-6) : 224 - 231
  • [6] The Role of Employees' Information Security Awareness on the Intention to Resist Social Engineering
    Grassegger, Tanja
    Nedbal, Dietmar
    INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS / INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT / INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES 2020 (CENTERIS/PROJMAN/HCIST 2020), 2021, 181 : 59 - 66
  • [7] Towards an Information Security Awareness Maturity Model
    Fertig, Tobias
    Schuetz, Andreas E.
    Weber, Kristin
    Mueller, Nicholas H.
    LEARNING AND COLLABORATION TECHNOLOGIES. HUMAN AND TECHNOLOGY ECOSYSTEMS, LCT 2020, PT II, 2020, 12206 : 587 - 599
  • [8] Understanding the Information Security Awareness Process in Real Estate Organizations Using the SECI Model
    Mani, Deepa
    Mubarak, Sameera
    Choo, Kim-Kwang Raymond
    AMCIS 2014 PROCEEDINGS, 2014,
  • [9] An Analysis of Information Security Awareness within Home and Work Environments
    Talib, Shuhaili
    Clarke, Nathan L.
    Furnell, Steven M.
    FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS, 2010, : 196 - 203
  • [10] Exploring the relationship between student mobile information security awareness and behavioural intent
    Ngoqo, Bukelwa
    Flowerday, Stephen V.
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (04) : 406 - 420