Information security culture: a behaviour compliance conceptual framework
Salahuddin Alfawaz, Karen J. Nelson, Kavoos Mohannak · University of Southern Queensland ePrints (University of Southern Queensland) · 2010
Understanding the complex dynamic and uncertain characteristics of organisational employees who per-form authorised or unauthorised information security activities is deemed to be a very important and chal-lenging task. This paper presents a conceptual frame-work for classifying and organising the characteristics of organisational subjects involved in these informa-tion security practices. Our framework expands the traditional Human Behaviour and the Social Environ-ment perspectives used in social work by identifying how knowledge, skills and individual preferences work to influence individual and group practices with re-spect to information security management. The clas-sification of concepts and characteristics in the frame-work arises from a review of recent literature and is underpinned by theoretical models that explain these concepts and characteristics. Further, based upon an exploratory study of three case organisations in Saudi Arabia involving extensive interviews with se-nior managers, department managers, IT managers, information security officers, and IT staff; this arti-cle describes observed information security practices and identifies several factors which appear to be par-ticularly important in influencing information secu-rity behaviour. These factors include values asso-ciated with national and organisational culture and how they manifest in practice, and activities related to information security management.