Assessing Organisational Information Security Culture Among Workforce in Universities: A Case of Namibia
Pius Tangeni Shambabi, Stanford Musarurwa, Fungai Bhunu Shava · 2021 IST-Africa Conference (IST-Africa) · 2021
Information security culture is one of the crucial elements that need to be established to protect organisational assets. Many organisations usually employ technical approach to protect business information. However, complete information security needs to consider the human, processes and procedures. Technical controls, processes and procedures need humans to implement and manage them effectively if information security is to be achieved. Core to human security is behaviour and culture. Technical techniques need to be supported by adopting a proper information security culture among employees. Introducing a culture whereby information that must be protected and governed by the entire workforce at all times in agreement with organisational policy and regulatory requirements is of paramount importance. University communities are no exception to this subject matter. The main objective of this study was to evaluate organisational information security culture amongst a university community. A case study was carried out at a university in Namibia where data to establish the state of security culture was collected using surveys and interviews. Qualitative data analysis techniques were applied. Some of the findings highlighted lack of knowledge and understanding of the institution information security policies, lack of information security awareness and lack of executive involvement in information security policy formulation and implementation. It was also noted that there was no compliance to existing information security policies as only a few individuals were aware of the existence of organisational security policies. In conclusion, ways to improve organisational information security culture were proposed.