信息安全文化对信息安全治理能力的影响(案例研究:PT XYZ)

K. Suwandi, Johan Setiawan
{"title":"信息安全文化对信息安全治理能力的影响(案例研究:PT XYZ)","authors":"K. Suwandi, Johan Setiawan","doi":"10.53748/jmis.v1i2.19","DOIUrl":null,"url":null,"abstract":"Objective – To analyze the relationship between a company’s information security approach/culture with its information security governance capabilities based on COBIT 5 framework and provide recommendations that can be used to improve the company's information security capabilities per COBIT 5 standard. \nMethodology – The research uses qualitative and quantitative methods by conducting interviews and distributing questionnaires to 3 members of the IT Department at PT XYZ. \nFindings – The research found that the measured COBIT 5 processes (APO13 and DSS05) failed to reach the expected target (level 4), with each DSS05 and APO13 can only reach level 1 and 2 respectively. In addition, several flaws were also found in the company’s information security culturethat may have contributed directly or indirectly to the current state of the company’s information security capabilities. \nNovelty – In this study, the researchers expand the previous study on information security culture conducted in 2010 by performing a security audit on a company's IT department to analyze the connection between corporate culture, especially information security culture and the capability level of information security governance. The company thus can make improvements or corrections to its information security approach/culture based on the recommendations provided with COBIT 5 framework. \nKeywords: Capability Level; COBIT; Governance; Information Security Culture. ","PeriodicalId":331767,"journal":{"name":"Journal of Multidisciplinary Issues","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2021-08-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Influence of Information Security Culture on the Information Security Governance Capabilities (Case Study: PT XYZ)\",\"authors\":\"K. Suwandi, Johan Setiawan\",\"doi\":\"10.53748/jmis.v1i2.19\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Objective – To analyze the relationship between a company’s information security approach/culture with its information security governance capabilities based on COBIT 5 framework and provide recommendations that can be used to improve the company's information security capabilities per COBIT 5 standard. \\nMethodology – The research uses qualitative and quantitative methods by conducting interviews and distributing questionnaires to 3 members of the IT Department at PT XYZ. \\nFindings – The research found that the measured COBIT 5 processes (APO13 and DSS05) failed to reach the expected target (level 4), with each DSS05 and APO13 can only reach level 1 and 2 respectively. In addition, several flaws were also found in the company’s information security culturethat may have contributed directly or indirectly to the current state of the company’s information security capabilities. \\nNovelty – In this study, the researchers expand the previous study on information security culture conducted in 2010 by performing a security audit on a company's IT department to analyze the connection between corporate culture, especially information security culture and the capability level of information security governance. The company thus can make improvements or corrections to its information security approach/culture based on the recommendations provided with COBIT 5 framework. \\nKeywords: Capability Level; COBIT; Governance; Information Security Culture. \",\"PeriodicalId\":331767,\"journal\":{\"name\":\"Journal of Multidisciplinary Issues\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-08-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Multidisciplinary Issues\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.53748/jmis.v1i2.19\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Multidisciplinary Issues","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.53748/jmis.v1i2.19","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

目标-分析公司的信息安全方法/文化与其基于COBIT 5框架的信息安全治理能力之间的关系,并根据COBIT 5标准提供可用于改进公司信息安全能力的建议。研究方法:本研究采用定性和定量方法,通过对PT XYZ IT部门的3名成员进行访谈和分发调查问卷。研究发现,测量的COBIT 5过程(APO13和DSS05)未能达到预期目标(4级),每个DSS05和APO13只能分别达到1级和2级。此外,在公司的信息安全文化中也发现了一些缺陷,这些缺陷可能直接或间接地导致了公司信息安全能力的现状。新颖性——在本研究中,研究者扩展了2010年对信息安全文化的研究,对某公司的IT部门进行了安全审计,分析了企业文化,尤其是信息安全文化与信息安全治理能力水平之间的联系。因此,公司可以根据COBIT 5框架提供的建议对其信息安全方法/文化进行改进或更正。关键词:能力水平;COBIT;治理;资讯保安文化。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Influence of Information Security Culture on the Information Security Governance Capabilities (Case Study: PT XYZ)
Objective – To analyze the relationship between a company’s information security approach/culture with its information security governance capabilities based on COBIT 5 framework and provide recommendations that can be used to improve the company's information security capabilities per COBIT 5 standard. Methodology – The research uses qualitative and quantitative methods by conducting interviews and distributing questionnaires to 3 members of the IT Department at PT XYZ. Findings – The research found that the measured COBIT 5 processes (APO13 and DSS05) failed to reach the expected target (level 4), with each DSS05 and APO13 can only reach level 1 and 2 respectively. In addition, several flaws were also found in the company’s information security culturethat may have contributed directly or indirectly to the current state of the company’s information security capabilities. Novelty – In this study, the researchers expand the previous study on information security culture conducted in 2010 by performing a security audit on a company's IT department to analyze the connection between corporate culture, especially information security culture and the capability level of information security governance. The company thus can make improvements or corrections to its information security approach/culture based on the recommendations provided with COBIT 5 framework. Keywords: Capability Level; COBIT; Governance; Information Security Culture. 
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信