Assessing Information Security Culture.
Adéle Martins · Information Security for South Africa · 2002
The behaviour of employees and their interaction with computer systems have a significant impact on the security of information. Human interaction with information resources is often the weakest link in protecting Information assets. One way of addressing it is by focusing on positively changing the culture of the organisation. In order to do this a model is proposed which can be implemented by an organisation. An assessment approach consisting of an audit process and incorporating an information security culture questionnaire is discussed as the main focus of this paper.