Problems of evaluating the organization’s information security culture

Rasmiyya S. Mahmudova
{"title":"Problems of evaluating the organization’s information security culture","authors":"Rasmiyya S. Mahmudova","doi":"10.25045/jpis.v14.i1.07","DOIUrl":null,"url":null,"abstract":"Nowadays, digitization of all areas of human activity leads to an increase in the number of information security incidents in organizations. From this point of view, the problem of information security culture in organizations becomes very relevant in modern times. Obviously, the majority of incidents related to information security violations in organizations are associated to the human factor. To overcome this problem, the research in the field of the evaluation of information security culture is urgent. Measuring and evaluating information security culture can enable an organization to identify its weaknesses in this area and take measures to eliminate them. This article examines various approaches to the concept of information security culture, and analyzes the affecting factors within the organization (management’s attitude towards information security, information security policy, information security awareness and employee’s behaviors). It also studies the documents adopted in the field of development and evaluation of information security culture in the European Union countries and the United States, and implemented projects. It analyzes proposed methods for measuring the information security culture in the organization using various methods. Moreover, the article reveals existing problems in this field and provides certain recommendations for their elimination. The methods of analysis and synthesis, comparison, generalization and systematic approach are used in this research.","PeriodicalId":306024,"journal":{"name":"Problems of Information Society","volume":"49 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Problems of Information Society","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.25045/jpis.v14.i1.07","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Nowadays, digitization of all areas of human activity leads to an increase in the number of information security incidents in organizations. From this point of view, the problem of information security culture in organizations becomes very relevant in modern times. Obviously, the majority of incidents related to information security violations in organizations are associated to the human factor. To overcome this problem, the research in the field of the evaluation of information security culture is urgent. Measuring and evaluating information security culture can enable an organization to identify its weaknesses in this area and take measures to eliminate them. This article examines various approaches to the concept of information security culture, and analyzes the affecting factors within the organization (management’s attitude towards information security, information security policy, information security awareness and employee’s behaviors). It also studies the documents adopted in the field of development and evaluation of information security culture in the European Union countries and the United States, and implemented projects. It analyzes proposed methods for measuring the information security culture in the organization using various methods. Moreover, the article reveals existing problems in this field and provides certain recommendations for their elimination. The methods of analysis and synthesis, comparison, generalization and systematic approach are used in this research.
评估组织信息安全文化的问题
如今,人类活动各个领域的数字化导致组织中信息安全事件的数量增加。从这个角度来看,组织中的信息安全文化问题在现代变得非常相关。显然,组织中与信息安全违规相关的大多数事件都与人为因素有关。为了克服这一问题,信息安全文化评价领域的研究迫在眉睫。度量和评估信息安全文化可以使组织识别其在这方面的弱点,并采取措施消除它们。本文考察了信息安全文化概念的各种方法,并分析了组织内部的影响因素(管理层对信息安全的态度、信息安全政策、信息安全意识和员工行为)。研究欧盟国家和美国在信息安全文化发展和评估领域采用的文件,并实施项目。它分析了使用各种方法测量组织中信息安全文化的建议方法。此外,文章还揭示了该领域存在的问题,并提出了一些消除这些问题的建议。本研究采用了分析综合、比较、概括和系统的方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信