The Enemy Within: A Behavioural Intention Model and an Information Security Awareness Process

被引:0
|
作者
Gundu, Tapiwa [1 ]
Flowerday, Stephen V. [1 ]
机构
[1] Univ Ft Hare, Dept Informat Syst, E London, South Africa
关键词
Information Security Awareness; Security Behaviour; POLICY COMPLIANCE; CULTURE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Most employees in small and medium enterprise (SME) engineering firms now have access to their own personal workstations which have become part of their daily functions. This has led to an increased need for information security management to safeguard against loss/alteration or theft of the firm's important information. SMEs tend to be concerned with vulnerabilities from external threats, although industry research suggests that a substantial proportion of security incidents originate from insiders within the firm. Hence, physical preventative measures such as antivirus software and firewalls are proving to solve only part of the problem as the employees controlling them do not have adequate information security knowledge. This tends to expose the firm to costly mistakes that can be made by naive/uninformed employees. This paper presents an information security awareness process that seeks to cultivate positive security behaviours using the behavioural intentions models i.e. the Theory of Reasoned Action and the Protection Motivation Theory. The process presented has been tested at an SME engineering firm, and findings are also presented and discussed in this paper.
引用
收藏
页数:8
相关论文
共 50 条
  • [41] Gamification of Information Security Awareness and Training
    Gjertsen, Eyvind Garder B.
    Gjaere, Erlend Andreas
    Bartnes, Maria
    Flores, Waldo Rocha
    ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2017, : 59 - 70
  • [42] A prototype for assessing information security awareness
    Kruger, H. A.
    Kearney, W. D.
    COMPUTERS & SECURITY, 2006, 25 (04) : 289 - 296
  • [43] Mediating effects of information security awareness
    van der Schyff, Karl
    Flowerday, Stephen
    COMPUTERS & SECURITY, 2021, 106
  • [44] Building an information security awareness program
    Marshall, P
    JOURNAL OF GOVERNMENT INFORMATION, 2002, 29 (06): : 431 - 433
  • [45] Information Security Awareness of School Administrators
    Karabatak, SongUl
    Karabatak, Murat
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [46] Analyzing trajectories of information security awareness
    Tsohou, Aggeliki
    Karyda, Maria
    Kokolakis, Spyros
    Kiountouzis, Evangelos
    INFORMATION TECHNOLOGY & PEOPLE, 2012, 25 (03) : 327 - 352
  • [47] A Research on Students' Information Security Awareness
    Tekerek, Mehmet
    Tekerek, Adem
    TURKISH JOURNAL OF EDUCATION, 2013, 2 (03): : 61 - 70
  • [48] Intention Awareness Theory; Risk Engineering Architecture Integrating Situation Awareness and Intention Awareness in Network-Centric Information Policy
    Howard, Newton
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2013, 8 (01): : 1 - 8
  • [49] THE ENEMY WITHIN - THE PROCESS OF INTERNMENT OF ENEMY ALIENS IN QUEENSLAND 1939-45
    SAUNDERS, K
    TAYLOR, H
    AUSTRALIAN JOURNAL OF POLITICS AND HISTORY, 1988, 34 (01): : 16 - 27
  • [50] The Role of Information Deserts in Information Security Awareness and Behaviour
    Snyman, D. P.
    Kruger, H. A.
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2021, : 613 - 620