An Importance of Behavioral Aspects of Information System Security in Ethiopian Construction Industry
Dr Yohannes Tadesse · 2017
Recent literature has identified that research in behavioral aspects of information systems security suggests organization culture as an important aspect of creating good security practices in an organization and instilling security principles in minds of employees. However, there are three key areas that must be considered when creating a secure information system: technical, formal and informal systems. Therefore, with much of the literature focusing on the technical and formal systems but, this paper explores only the literature aimed at the informal system. Moreover, the goal of this paper is to explore theories and empirical studies about ICT administration and information systems security (ISS) to discover common denominators and best practices for organizations in regards to the softer side of security. The most commonly used theories in the behavioral aspects of ISS are theory of reasoned action, deterrence theory, social bond theory, social learning theory, and theory of planned behavior. The emerging themes need more attention from organizations in regards to the human element and ISS that are organization culture, training/awareness, and internal controls. Now a day, in construction industry an importance of behavioral information system is vital, as conventionally known that most of construction projects relies on labor intensive works as well as supported by ICT administration aliened with a management framework, which has to coordinate stakeholders in the sector such as many professional, construction and supplier organizations whose random involvement resolve change through the track of the project. However, the disintegration and enthusiasm of this process and the need to integrate a wide range of occupational cultures cause to be construction one of the most complex projects based industries in which to apply good information construction technology administration (ICTA) practices. Here, in this paper, it is challenged to address this shortfall by providing an informative exploration into how modern construction organizations manage computer misuse/abuse, the various aspects of ICTA that leads to pinpoint on the real practices exhibited construction industry; As well as holding up a mirror to current practice in the empirical site called the Addis Ababa City Road Authority (AACRA), it is also attempted to cast a critical views pinpointed on current approaches to administrating ICT in the construction industry. Moreover, this paper is focused on the current practice and policy of the above company, which is conducted and evaluated followed by gap identification. For this task, interview is conducted at ICT directorate responsible persons and employees of the company. Afterwards, the gaps are identified and company’s maturity level regards to ICT administration is identified. Finally, improvement recommendations are put forwarded to grow up the maturity level of the company and hopefully to fill the gaps regards to ICT policy. Therefore, the research in behavioral aspects of information systems security suggests organization culture as an important aspect of creating good security practices in an organization and instilling security principles in minds of employees.