当前位置: X-MOL 学术Aslib Journal of Information Management › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Holistic framework for evaluating and improving information security culture
Aslib Journal of Information Management ( IF 2.6 ) Pub Date : 2021-08-17 , DOI: 10.1108/ajim-02-2021-0037
Krunoslav Arbanas 1 , Mario Spremic 2 , Nikolina Zajdela Hrustek 3
Affiliation  

Purpose

The objective of this research was to propose and validate a holistic framework for information security culture evaluation, built around a novel approach, which includes technological, organizational and social issues. The framework's validity and reliability were determined with the help of experts in the information security field and by using multivariate statistical methods.

Design/methodology/approach

The conceptual framework was constructed upon a detailed literature review and validated using a range of methods: first, measuring instrument was developed, and then content and construct validity of measuring instrument was confirmed via experts' opinion and by closed map sorting method. Convergent validity was confirmed by factor analysis, while the reliability of the measuring instrument was tested using Cronbach's alpha coefficient to measure internal consistency.

Findings

The proposed framework was validated based upon the results of empirical research and the usage of multivariate analysis. The resulting framework ultimately consists of 46 items (manifest variables), describing eight factors (first level latent variables), grouped into three categories (second level latent variables). These three categories were built around technological, organizational and social issues.

Originality/value

This paper contributes to the body of knowledge in information security culture by developing and validating holistic framework for information security culture evaluation, which does not observe information security culture in only one aspect but takes into account its organizational, sociological and technical component.



中文翻译:

评估和改进信息安全文化的整体框架

目的

这项研究的目的是提出并验证信息安全文化评估的整体框架,该框架围绕一种新方法构建,其中包括技术、组织和社会问题。该框架的有效性和可靠性是在信息安全领域专家的帮助下通过使用多元统计方法确定的。

设计/方法/方法

该概念框架是在详细文献查阅的基础上构建的,并使用一系列方法进行验证:首先,开发测量工具,然后通过专家意见和封闭地图排序方法确认测量工具的内容和结构有效性。收敛效度通过因子分析得到确认,测量工具的信度通过Cronbach's alpha系数来衡量内部一致性。

发现

根据实证研究的结果和多变量分析的使用,对所提出的框架进行了验证。由此产生的框架最终由 46 个项目(清单变量)组成,描述了八个因素(第一级潜在变量),分为三类(第二级潜在变量)。这三个类别是围绕技术、组织和社会问题建立的。

原创性/价值

本文通过开发和验证信息安全文化评估的整体框架,为信息安全文化的知识体系做出贡献,该框架不仅仅从一个方面观察信息安全文化,而是考虑到其组织、社会和技术组成部分。

更新日期:2021-09-03
down
wechat
bug