Publication:
A systematic literature review: Information security culture

dc.citedby27
dc.contributor.authorMahfuth A.en_US
dc.contributor.authorYussof S.en_US
dc.contributor.authorBaker A.A.en_US
dc.contributor.authorAli N.en_US
dc.contributor.authorid57190976577en_US
dc.contributor.authorid16023225600en_US
dc.contributor.authorid35178991300en_US
dc.contributor.authorid54985243500en_US
dc.date.accessioned2023-05-29T06:37:57Z
dc.date.available2023-05-29T06:37:57Z
dc.date.issued2017
dc.descriptionBehavioral research; Information systems; Metadata; Social sciences; Societies and institutions; Attitudes; Best practices; Critical factors; Human behaviors; Information security cultures; Security knowledge; Systematic literature review; Weakest links; Security of dataen_US
dc.description.abstractHuman behavior inside organizations is considered the main threat to organizations. Moreover, in information security the human element consider the most of weakest link in general. Therefore it is crucial to create an information security culture to protect the organization's assets from inside and to influence employees' security behavior. This paper focuses on identifying the definitions and frameworks for establishing and maintaining information security culture inside organizations. It presents work have been done to conduct a systematic literature review of papers published on information security culture from 2003 to 2016. The review identified 68 papers that focus on this area, 18 of which propose an information security culture framework. An analysis of these papers indicate there is a positive relationship between levels of knowledge and how employees behave. The level of knowledge significantly affects information security behavior and should be considered as a critical factor in the effectiveness of information security culture and in any further work that is carried out on information security culture. Therefore, there is a need for more studies to identity the security knowledge that needs to be incorporated into organizations and to find instances of best practice for building an information security culture within organizations. � 2017 IEEE.en_US
dc.description.natureFinalen_US
dc.identifier.ArtNo8002442
dc.identifier.doi10.1109/ICRIIS.2017.8002442
dc.identifier.scopus2-s2.0-85029958831
dc.identifier.urihttps://www.scopus.com/inward/record.uri?eid=2-s2.0-85029958831&doi=10.1109%2fICRIIS.2017.8002442&partnerID=40&md5=1e7463eb271049eb774b9ea26bcd24b0
dc.identifier.urihttps://irepository.uniten.edu.my/handle/123456789/23140
dc.publisherIEEE Computer Societyen_US
dc.sourceScopus
dc.sourcetitleInternational Conference on Research and Innovation in Information Systems, ICRIIS
dc.titleA systematic literature review: Information security cultureen_US
dc.typeConference Paperen_US
dspace.entity.typePublication
Files
Collections