Information Systems Security and End-User Consciousness – A Strategic Matter
Maurizio Cavallari · 2010
“Information security consciousness” (also cited in literature as awareness) is referred to the condition in which information systems users (end-users principally) in an organisation are well informed, prepared to – and committed – the security issues concerning the use of those systems. There is no doubt in doctrine that security of IS represents a central strategic matter. In adherence to Mathieson’s thought about the use of Information Systems (IS) information security consciousness is, within that view, of fundamental importance. It is foreseen by a number of studies that a higher level of consciousness should significantly reduce “user related faults” and maximize the overall information system. Understanding of the context and of the original reasons of users-level errors, are crucial to achieve, at a strategic level, the above mentioned goals. The motivation of different organisational levels, e.g., to comply with information security policies and procedures is an activity that falls into the “content category”. Technology Acceptance Model (TAM) of Davis and the Theory of Planned Behaviour of Ajzen are taken into account. Communication and moreover, the “persuasive communication” turned out to be one of the main key points. It is suggested that the persuasion strategy should start from communication of reasons and explanations, providing answers about rules and security procedures. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.