Search results

1 – 10 of 294
Open Access
Article
Publication date: 26 April 2024

Marcus Gerdin, Ella Kolkowska and Åke Grönlund

Research on employee non-/compliance to information security policies suffers from inconsistent results and there is an ongoing discussion about the dominating survey research…

Abstract

Purpose

Research on employee non-/compliance to information security policies suffers from inconsistent results and there is an ongoing discussion about the dominating survey research methodology and its potential effect on these results. This study aims to add to this discussion by investigating discrepancies between what the authors claim to measure (theoretical properties of variables) and what they actually measure (respondents’ interpretations of the operationalized variables). This study asks: How well do respondents’ interpretations of variables correspond to their theoretical definitions? What are the characteristics of any discrepancies between variable definitions and respondent interpretations?

Design/methodology/approach

This study is based on in-depth interviews with 17 respondents from the Swedish public sector to understand how they interpret questionnaire measurement items operationalizing the variables Perceived Severity from Protection Motivation Theory and Attitude from Theory of Planned Behavior.

Findings

The authors found that respondents’ interpretations in many cases differ substantially from the theoretical definitions. Overall, the authors found four principal ways in which respondents interpreted measurement items – referred to as property contextualization, extension, alteration and oscillation – each implying more or less (dis)alignment with the intended theoretical properties of the two variables examined.

Originality/value

The qualitative method used proved vital to better understand respondents’ interpretations which, in turn, is key for improving self-reporting measurement instruments. To the best of the authors’ knowledge, this study is a first step toward understanding how precise and uniform definitions of variables’ theoretical properties can be operationalized into effective measurement items.

Details

Information & Computer Security, vol. ahead-of-print no. ahead-of-print
Type: Research Article
ISSN: 2056-4961

Keywords

Open Access
Article
Publication date: 30 March 2023

Areej Alyami, David Sammon, Karen Neville and Carolanne Mahony

This study explores the critical success factors (CSFs) for Security Education, Training and Awareness (SETA) program effectiveness. The questionable effectiveness of SETA…

3421

Abstract

Purpose

This study explores the critical success factors (CSFs) for Security Education, Training and Awareness (SETA) program effectiveness. The questionable effectiveness of SETA programs at changing employee behavior and an absence of empirical studies on the CSFs for SETA program effectiveness is the key motivation for this study.

Design/methodology/approach

This exploratory study follows a systematic inductive approach to concept development. The methodology adopts the “key informant” approach to give voice to practitioners with SETA program expertise. Data are gathered using semi-structured interviews with 20 key informants from various geographic locations including the Gulf nations, Middle East, USA, UK and Ireland.

Findings

In this study, the analysis of these key informant interviews, following an inductive open, axial and selective coding approach, produces 11 CSFs for SETA program effectiveness. These CSFs are mapped along the phases of a SETA program lifecycle (design, development, implementation and evaluation) and nine relationships identified between the CSFs (within and across the lifecycle phases) are highlighted. The CSFs and CSFs' relationships are visualized in a Lifecycle Model of CSFs for SETA program effectiveness.

Originality/value

This research advances the first comprehensive conceptualization of the CSFs for SETA program effectiveness. The Lifecycle Model of CSFs for SETA program effectiveness provides valuable insights into the process of introducing and sustaining an effective SETA program in practice. The Lifecycle Model contributes to both theory and practice and lays the foundation for future studies.

Details

Information Technology & People, vol. 36 no. 8
Type: Research Article
ISSN: 0959-3845

Keywords

Open Access
Article
Publication date: 27 July 2023

Andrea Kő, Gábor Tarján and Ariel Mitev

This paper aims to provide a maturity model for information security awareness (MMISA), based on the literature, expert interviews and feedback. In addition to developing the…

814

Abstract

Purpose

This paper aims to provide a maturity model for information security awareness (MMISA), based on the literature, expert interviews and feedback. In addition to developing the MMISA, the authors investigate the role of the three decisive factors that affect ISA maturity level: risk management mechanism, organizational structure and ISA.

Design/methodology/approach

The research methodology is a combined one; qualitative and quantitative methods were applied, including surveying the literature, interviews and developing a survey to collect quantitative data about decisive factors that affect ISA maturity level. The authors perform a variance-based partial least squares-structural equation modeling (PLS-SEM) investigation of the relationships between these factors.

Findings

The investigation of decisive factors of ISA maturity levels revealed that if the authors identify a strong risk assessment mechanism (through a documented methodology and reliable results), the authors can expect a high level of ISA. If there is a well-defined organizational structure with clear responsibilities, this supports the linking of a risk management mechanism with the level of ISA. The connection between organizational structure and ISA maturity level is supported by ISA activities: an increased level of awareness actions strengthens an organizational structure via the best practices learned by the staff.

Originality/value

The main contribution of the proposed MMISA model is that the model offers controls and audit evidence for maturity levels. Beyond that, the authors distinguish in the MMISA model controls supporting knowledge and controls supporting attitude, emphasizing that this is not enough to know what to do, but the proper attitude is required too. The authors didn't find any other ISA maturity model which has a similar feature. The contribution of the authors' work is that the authors provide a method for solving this complex measurement problem via the MMISA, which also offers direct guidance for the daily practices of organizations.

Details

Information Technology & People, vol. 36 no. 8
Type: Research Article
ISSN: 0959-3845

Keywords

Open Access
Article
Publication date: 1 August 2023

Areej Alyami, David Sammon, Karen Neville and Carolanne Mahony

Cyber security has never been more important than it is today in an ever more connected and pervasive digital world. However, frequently reported shortages of suitably skilled and…

1852

Abstract

Purpose

Cyber security has never been more important than it is today in an ever more connected and pervasive digital world. However, frequently reported shortages of suitably skilled and trained information system (IS)/cyber security professionals elevate the importance of delivering effective Security Education,Training and Awareness (SETA) programmes within organisations. Therefore, the purpose of this study is the questionable effectiveness of SETA programmes at changing employee behaviour and an absence of empirical studies on the critical success factors (CSFs) for SETA programme effectiveness.

Design/methodology/approach

This exploratory study follows a three-stage research design to give voice to practitioners with SETA programme expertise. Data is gathered in Stage 1 using semi-structured interviews with 20 key informants (the emergence of the CSFs), in Stage 2 from 65 respondents to a short online survey (the ranking of the CSFs) and in Stage 3 using semi-structured interviews with nine IS/cyber security practitioners (the emergence of the guiding principles). Using a multi-stage research design allows the authors to propose and evaluate the 11 CSFs for SETA programme effectiveness.

Findings

This study conducted a mean score analysis to evaluate the level of importance of each CSF within two independent groups of IS/cyber security professionals. This multi-stage analysis produces a ranked list of 11 CSFs for SETA programme effectiveness, while the difference in the rankings leads to the emergence of five CSF-specific guiding principles (to increase the likelihood of delivering an effective SETA programme within an organisational context). This analysis also reveals that most of the contradictions/differences in CSF rankings between IS/cyber security practitioners are linked to the design phase of the SETA programme life cycle. While two CSFs, “maintain quarterly evaluation of employee performance” (CSF-DS6) and “build security awareness campaigns” (CSF-EV1), represent the most significant contradiction in this study.

Originality/value

The 11 CSFs for SETA programme effectiveness, along with the five CSF-specific guiding principles, provide a greater depth of knowledge contributing to both theory and practice and lays the foundation for future studies. Therefore, the outputs of this study provide valuable insights on the areas that practice needs to get right to deliver effective SETA programmes.

Details

Information & Computer Security, vol. 32 no. 1
Type: Research Article
ISSN: 2056-4961

Keywords

Open Access
Article
Publication date: 5 October 2023

Peter Dornheim and Ruediger Zarnekow

The human factor is the most important defense asset against cyberattacks. To ensure that the human factor stays strong, a cybersecurity culture must be established and cultivated…

1049

Abstract

Purpose

The human factor is the most important defense asset against cyberattacks. To ensure that the human factor stays strong, a cybersecurity culture must be established and cultivated in a company to guide the attitudes and behaviors of employees. Many cybersecurity culture frameworks exist; however, their practical application is difficult. This paper aims to demonstrate how an established framework can be applied to determine and improve the cybersecurity culture of a company.

Design/methodology/approach

Two surveys were conducted within eight months in the internal IT department of a global software company to analyze the cybersecurity culture and the applied improvement measures. Both surveys comprised the same 23 questions to measure cybersecurity culture according to six dimensions: cybersecurity accountability, cybersecurity commitment, cybersecurity necessity and importance, cybersecurity policy effectiveness, information usage perception and management buy-in.

Findings

Results demonstrate that cybersecurity culture maturity can be determined and improved if accurate measures are derived from the results of the survey. The first survey showed potential for improving the dimensions of cybersecurity accountability, cybersecurity commitment and cybersecurity policy effectiveness, while the second survey proved that these dimensions have been improved.

Originality/value

This paper proves that practical application of cybersecurity culture frameworks is possible if they are appropriately tailored to a given organization. In this regard, scientific research and practical application combine to offer real value to researchers and cybersecurity executives.

Details

Information & Computer Security, vol. 32 no. 2
Type: Research Article
ISSN: 2056-4961

Keywords

Open Access
Article
Publication date: 4 April 2023

Matteo Podrecca and Marco Sartor

The aim of this paper is to present the first diffusion analysis of ISO/IEC 27001, the fourth most popular ISO certification at global level and the most important standard for…

1210

Abstract

Purpose

The aim of this paper is to present the first diffusion analysis of ISO/IEC 27001, the fourth most popular ISO certification at global level and the most important standard for information security.

Design/methodology/approach

To achieve the purposes, the authors applied Grey Models (GM) – Even GM (1,1), Even GM (1,1,α,θ), Discrete GM (1,1), Discrete GM (1,1,α) – complemented by the relative growth rate and the doubling time indexes on the six most important countries in terms of issued certificates.

Findings

Results show that a growing trend is likely to be expected in the years to come and that China will lead at country level.

Originality/value

The study contributes to the scientific debate by presenting the first diffusive analysis of ISO/IEC 27001 and by proposing a forecasting approach that to date has found little application in the field of international standards.

Content available
Book part
Publication date: 14 December 2023

Abstract

Details

Digitisation, AI and Algorithms in African Journalism and Media Contexts
Type: Book
ISBN: 978-1-80455-135-6

Open Access
Article
Publication date: 14 March 2023

Paul Kojo Ametepe, Emetomo Uchefiho Otuaga, Chinwe Felicia Nnaji and Mustapha Sina Arilesere

This study aimed at investigating employee training, employee participation and organizational commitment (OC) and the moderating effect of workplace ostracism among bank…

2216

Abstract

Purpose

This study aimed at investigating employee training, employee participation and organizational commitment (OC) and the moderating effect of workplace ostracism among bank employees.

Design/methodology/approach

The study used a descriptive and cross-sectional design with the aid of a standard scale constructed into a questionnaire. Cluster, convenience and simple random sampling techniques were used to select 1,067 respondents, of which 870 were deemed fit for the study. The theories underpinning the study were the social exchange theory (SET) and social identity theory (SIT). Four hypotheses were developed and tested using hierarchical multiple regression analysis, and moderation using PROCESS macro.

Findings

The study found that employee training and employee participation had a significant positive relationship with organizational commitment, while organizational ostracism had a significant but negative relationship with organizational commitment among bank employees. The study also found that workplace ostracism moderated the relationship between organizational climate and organizational commitment The study recommended that organizational commitment requires management training their workforce, allowing employee participation in decisions, and minimizing or outrightly eradicating the practice of organizational ostracism. It is, therefore, concluded that workers place great value on training and participation in decision-making and frown at organizational ostracism.

Originality/value

This paper fills in the gaps left by the paucity of empirical investigation of the moderating role that workplace ostracism plays between employee training, employee participation and organizational commitment – a feat that is lacking in developing countries. It serves as a reminder to management to prevent or entirely eliminate workplace ostracism to allay an employee's impression of being a threat to an organization when commitment is low.

Details

Arab Gulf Journal of Scientific Research, vol. 42 no. 2
Type: Research Article
ISSN: 1985-9899

Keywords

Content available
Book part
Publication date: 25 March 2024

Sophia Beckett Velez

Abstract

Details

Compliance and Financial Crime Risk in Banks
Type: Book
ISBN: 978-1-83549-042-6

Open Access
Article
Publication date: 3 July 2023

Howard Chitimira

It is important to note that insider trading is currently outlawed under the Securities Act 17 of 2004 (Chapter 24: 25) as amended (Securities Act) in Zimbabwe. This Act…

Abstract

Purpose

It is important to note that insider trading is currently outlawed under the Securities Act 17 of 2004 (Chapter 24: 25) as amended (Securities Act) in Zimbabwe. This Act enumerates some practices that may give rise to insider trading liability in the Zimbabwean financial markets. Nonetheless, numerous challenges, such as the lack of adequate financial resources, the lack of sufficient persons with the relevant skills and expertise on the part of the enforcement authorities, lack of political will, inadequacy of insider trading provisions, poor cooperation and collaboration between the relevant authorities and the ongoing coronavirus (Covid-19) pandemic have negatively impeded the effective regulation and combating of insider trading in Zimbabwe. To this end, the author explores the stated challenges and recommend measures that could be used by regulatory bodies and other relevant enforcement authorities to enhance the regulation and combating of insider trading in the Zimbabwean financial markets. This study aims to enhance the detection and combating of insider trading in Zimbabwe.

Design/methodology/approach

A qualitative research methodology is used through the analysis of relevant legislation and case law.

Findings

It is hoped that the findings and recommendations made in this study will be considered by the Zimbabwean policymakers.

Research limitations/implications

The study does not use empirical research methodology.

Practical implications

The findings and recommendations made in this study could enhance the combating of insider trading activities in Zimbabwe.

Social implications

The study seeks to curb insider trading in the Zimbabwean financial markets and financial institutions in the wake of the covid-19 pandemic-related regulatory and enforcement challenges.

Originality/value

The study provides original research on the regulation and combating of insider trading activities in Zimbabwe.

Details

Journal of Financial Crime, vol. 30 no. 6
Type: Research Article
ISSN: 1359-0790

Keywords

Access

Only content I have access to

Year

Last 6 months (294)

Content type

1 – 10 of 294