Full Text Available

Note: Clicking the button above will open the full text document at the original institutional repository in a new window.

Cultivating and assessing information security culture

Thesis (PhD)--University of Pretoria, 2009.

Saved in:
Bibliographic Details
Other Authors: Eloff, Jan H.P.
Format: Thesis
Published: University of Pretoria 2013
Subjects:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1867613683701514240
access_status_str Open Access
author2 Eloff, Jan H.P.
author_browse Eloff, Jan H.P.
author_facet Eloff, Jan H.P.
collection Thesis
dc_rights_str_mv © 2008 University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria.
description Thesis (PhD)--University of Pretoria, 2009.
format Thesis
id oai:repository.up.ac.za:2263/24117
institution University of Pretoria (South Africa)
last_indexed 2026-06-10T12:40:02.981Z
license_str Other — see source repository
provenance_str_mv Harvested via OAI-PMH from UPSpace — University of Pretoria Institutional Repository
publishDate 2013
publishDateRange 2013
publishDateSort 2013
publisher University of Pretoria
publisherStr University of Pretoria
record_format dspace
source_str UPSpace — University of Pretoria Institutional Repository
spelling oai:repository.up.ac.za:2263/24117 Cultivating and assessing information security culture Eloff, Jan H.P. adele.daveiga@kpmg.co.za Da Veiga, Adele Information security culture UCTD Thesis (PhD)--University of Pretoria, 2009. The manner in which employees perceive and interact (behave) with controls implemented to protect information assets is one of the main threats to the protection of such assets and the effective use of information security controls. Should the interaction not be conducive to the protection of the information assets, it could have a profound impact on the profit of an organisation, productive working hours could be lost, confidential information might be disclosed to unauthorised people and compliance with legal and regulatory regulations could be affected - all this, despite the fact that adequate technical and procedural controls might be in place. Current research highlights the importance of a strong information security culture to address the threat that employee behaviour poses to the protection of information assets. Various research perspectives propose how an acceptable level of information security culture should be cultivated, and how to assess this culture to determine whether it is on an acceptable level. These approaches are however not adequate to cultivate information security culture, as all the relevant information security components and the influences on the information security culture have to be considered. This leads to the question as to whether the assessment instruments proposed to assess the information security culture are indeed adequate and valid. The main contribution of this research relates to the development of an information security culture framework and process consisting of an assessment instrument to assess information security culture. In order to develop the information security culture framework, the researcher developed a Comprehensive Information Security Framework (CISF) that equips organisations with a holistic approach to the implementation of information security. The framework provides a single point of reference for the governance of information security. The Information Security Culture Framework (ISCF) is developed using the CISF as foundation. The ISCF can be used by organisations to cultivate an information security culture conducive to the protection of information assets. It considers all the components required for information security culture, namely information security, organisational culture and organisational behaviour. It integrates the aforementioned concepts and illustrates the influence between the components. The ISCF further serves as a basis for designing an information security culture assessment instrument. This instrument is incorporated as part of an Information Security Culture Assessment process (lSCULA) defined by the researcher. ISCULA provides management with the steps to conduct an information security culture assessment, as well as the steps to validate the assessment instrument. The application of ISCULA is tested in an empirical study conducted in an organisation. It illustrates how to validate an information security culture assessment instrument by ensuring that it is designed based on the ISCF and meets the statistical requirements for a valid and reliable assessment instrument. Both the ISCF and the ISCULA process can ultimately be deployed by organisations to minimise the threat that employee behaviour poses to the protection of information assets. Computer Science unrestricted 2013-09-06T16:42:35Z 2009-04-24 2013-09-06T16:42:35Z 2009-04-20 2009-04-24 2009-04-24 Thesis Da Veiga, A 2008, Cultivating and assessing information security culture, PhD thesis, University of Pretoria, Pretoria, viewed yymmdd < http://hdl.handle.net/2263/24117 > D585/ag http://hdl.handle.net/2263/24117 http://upetd.up.ac.za/thesis/available/etd-04242009-165716/ © 2008 University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria. application/pdf application/pdf application/pdf application/pdf University of Pretoria
spellingShingle Information security culture
UCTD
Cultivating and assessing information security culture
title Cultivating and assessing information security culture
title_full Cultivating and assessing information security culture
title_fullStr Cultivating and assessing information security culture
title_full_unstemmed Cultivating and assessing information security culture
title_short Cultivating and assessing information security culture
title_sort cultivating and assessing information security culture
topic Information security culture
UCTD
url http://hdl.handle.net/2263/24117
http://upetd.up.ac.za/thesis/available/etd-04242009-165716/