Information security culture in health informatics environment: A qualitative approach

Noor Hafizah Hassan, Norazean Maarop, Zuraini Ismail, Wardah Zainal Abidin · 2017

Information security culture is recognised as having an influence towards end-user compliance towards information security controls and policies in the organisation. Literature agrees that cultural beliefs can be found to influence behaviours among members of a profession that distinguish them in the organisational system and profession that they belong to. Therefore, these phenomena led towards the investigation and understanding of factors influencing information security culture in healthcare organisations. A qualitative approach has been conducted to evaluate the proposed conceptual model that hinges on Systematic Literature Review (SLR), organisational culture characteristics and Health Belief Model (HBM). A semi-structured interview has been conducted with 19 healthcare professionals. Twelve themes found to be the factors that may influence information security culture in health informatics environment. The study outcomes may contribute towards the design of an appropriate Information Security Management System (ISMS) for establishing information security culture in healthcare organisations.

Read the paper · More papers on PaperTik