Data Collection Instruments  - Write an analysis on the variables of a survey designed to collect data. 

profilelazygeezer
MCIS2017-StudentsandInformationSecurityCultureinOrganizations-MCIS2017.pdf

See discussions, stats, and author profiles for this publication at: https://www.researchgate.net/publication/320456625

Students and Information Security Culture in Organizations

Conference Paper · July 2017

CITATIONS

0 READS

247

2 authors:

Some of the authors of this publication are also working on these related projects:

Cybersecurity Camps and Trainings for students and Public Sector View project

Nur Sena Tanrıverdi

Bogazici University

3 PUBLICATIONS   3 CITATIONS   

SEE PROFILE

Bilgin Metin

Bogazici University

98 PUBLICATIONS   1,016 CITATIONS   

SEE PROFILE

All content following this page was uploaded by Bilgin Metin on 31 May 2020.

The user has requested enhancement of the downloaded file.

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017

STUDENTS AND INFORMATION SECURITY CULTURE IN

ORGANIZATIONS

Research-in-Progress

Track 10

Tanrıverdi, Nur Sena, Bogazici University, Istanbul, Turkey, [email protected]

Metin, Bilgin, Bogazici University, Istanbul, Turkey, [email protected]

Abstract

Employees’ Information security policy (ISP) complied actions ensures security in organizations. Dai-

ly interaction with information system and behaviour of employees against security issues are affected

by information security culture of organization. ISP of an organization can be evaluated as a part of

an information security culture of organization. Obviously, adoption of the culture takes time especial-

ly for new hires. When threats are evolving and systems are becoming more complex, information se-

curity culture is important to be adopted by new hires in a short time. Therefore, this study targets

potential employees of organizations; students. Although security behaviour and awareness of stu-

dents are examined in previous studies, they aren’t evaluated within information security culture as

future employees of organizations. In this study, security behaviour and policy knowledge of students,

and effective factors for policy knowledge are examined. According to the results, knowing ISP chang-

es security behaviour of students. If students know what ISP is, they will probably not threat systems

with their daily activities and comply with ISP of their future organizations. 73.1% of students who

know ISP are senior and higher degree of students, so it can be concluded that future employees of

organizations are knowledgeable in terms of information security.

Keywords: Security Awareness of Student, Information Security Culture, Information Security Policy,

Security Behaviour.

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 2

1 Introduction

Most organizations’ operations are largely based on IT. Thus, managing risk related to information

security attacks is getting increasingly significant because infractions of information security often

have critical financial and reputational outcomes for organizations and their users (Cavusoglu, Mishra

and Raghunathan, 2004). That’s why protecting information security has become priority for compa-

nies.

IT systems are used in a variety of fields including transmission, storage and data processing in all

organizations regardless size. That’s why companies take a big care of security of their vital assets; IT

systems. Security of these systems is provided by using technical solutions like authentication, cryp-

tography, advanced firewalls against to attacks. However, technical solutions cannot succeed in pro-

tecting systems completely when human factor is ignored (Johnson, 2006). Employees have the most

critical role in the protection of information systems of their companies. According to participants of

ISACA’s 2016 Cybersecurity Snapshot Survey (ISACA, 2016) social engineering, insider threats and

advanced persistent threat are respectively the most important consideration for their organization in

2016. Intentional or unintentional actions of people are the biggest threat for organizations.

The Global State of Information Security Survey 2016 of PwC (PwC, 2016) shows that current em-

ployees have threated companies at most. 34% of security incidents in 2015 have been caused by cur-

rent employees according to results of the survey.

End-user is “the weakest link in the information security chain” (Mitnick, 2002). From the organiza-

tional perspective, the weakest chain is the new joiners because they are unfamiliar to the organiza-

tional culture. Information security culture is considered as an aspect of organizational culture (Okere,

van Niekerk and Carrol, 2012), (Schlienger and Teufel, 2003). It is embedded in a company so as to

ensure secure environment.

Al Hogail and Mirza defined information security culture as “The collection of perceptions, attitudes,

values, assumptions and knowledge that guides how thing are done in an organization in order to be

consistent with the information security requirements with the aim of protecting the information assets

and influencing employees’ security behaviour in a way that preserving the information security be-

comes a second nature” (Al Hogail and Mirza, 2014). Thus, it can be said that if an organization has

an information security culture, it has a defined information security policy (ISP). ISP of a company

bases on standards and it should be open for access of all employees (International Organization for

Standardization, 2013). It is expected that every employee complies with this policy. Because adaption

of rules and environment takes time for new employees, they probably have higher potential than oth-

ers in terms of threatening of information security.

New employees of the IT departments are expected to be aware about information security because of

their IT related backgrounds. But companies employ non-IT related employees in such departments as

finance, marketing and human resources to conduct main business and those employees are mostly

unfamiliar to the IT related concepts like information security.

However regardless their departments and backgrounds they all are responsible for corporate general

security. So, companies continuously support employees with different kind of education and training

programs. Not only information security related training programs but also various informative activi-

ties are generally applied in organizations. For example, security department informs all organization

against new threats in Internet environment via e-mails, posters, pop-up screens and newsletters, web

based sections, desk-to-desk alerts and email messages in informative context (Wilson and Hash,

2003). These continuous educative activities begin with orientation programs for new employees.

General security awareness is given to new joiners in orientation programs.

In previous studies, although security behaviour and awareness of students are examined, they are not

evaluated within information security culture as future employees of organizations. Security behaviour

and policy knowledge of students, and effective factors for policy knowledge are examined within this

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 3

study. According to the results, knowing ISP changes security behaviour of students. If students know

what ISP is, they will probably not threat systems with their daily activities and comply with ISP of

their future organizations. 73.1% of students who know ISP are senior and higher degree of students,

so it can be concluded that future employees of organizations are knowledgeable in terms of infor-

mation security.

2 Literature Review

In this section, previous studies on information security culture, information security policy compli-

ance, and student awareness are summarized so as to reveal what kind of outcomes have been present-

ed related to the concepts fundamental for the perspective of this study; students and information secu-

rity culture. Information security culture, information security policy compliance and student aware-

ness studies are reviewed to understand what kind of studies have been conducted, which factors have

been investigated in the literature.

2.1 Information Security Culture and Policy Compliance

Information security culture is a key term to understand, estimate and evaluate security behaviour of

human and the term is approached differently in the literature. Basically, it can be considered as the

subculture of organizational culture which constitutes company-wide shared values (Okere, van

Niekerk and Carrol, 2012), (Schlienger and Teufel, 2003).

The most common approach for information security culture has been derived from Schein’s organiza-

tional culture model by van Niekerk & von Solms (Renaud and Goucher, 2014). They present layers

of IS culture; artefacts, espoused values, shared tacit assumptions and information security knowledge

(Renaud and Goucher, 2014), (D'Arcy, Hovav and Galletta, 2009), (van Niekerk and von Solms,

2010).

The literature has different aspects of information security culture. One of them is an analysis of dif-

ferent information security culture definitions (Al Hogail and Mirza, 2014). Moreover Okere, van

Niekerk and Carroll (Okere, van Niekerk and Carrol, 2012) have analysed different approaches of in-

formation security culture in the literature. According to them, usual approach to assess information

security culture is auditing.

Karlsson, Åström and Karlsson’s literature review study shows that content of information security

culture, roots and consequences of information security culture and cultivating information security

culture have been commonly investigated in literature (Karlsson, Åström and Karlsson, 2015). They

summarize theories which have tried to explain contributive factors of information security culture.

Those theories are Schein’s (1985) culture model, competing values framework (Quinn and Cameron,

1983), theory of planned behaviour (Ajzen, 1991), Hofstede’s (1997) national culture framework, in-

formation security behaviour modes (Alfawaz, Nelson and Mohannak, 2010), Nonaka’s modes of

knowledge creation (Thomson, von Solms and Louw, 2010), and Lazarus’ (1993) stress model.

Information security behaviour is usually considered as behaviour that comply with information secu-

rity policy of a company in the literature. Effective factors on information security policy compliance

are also searched in information security literature. In addition to this, those factors are evaluated

based on the theories (Bulgurcu, Cavusoglu and Benbasat, 2010), (Pahnila et al., 2007), (Hu et al.,

2012), (Safa, von Solms and Furnell, 2016). There are also some studies that combine theories to ful-

fill the research gap in the literature (Bulgurcu, Cavusoglu and Benbasat, 2010), (Herath and Rao,

2009), (Ifinedo, 2012), (Hu and Dinev, 2007).

2.2 Security Awareness of Students

In the literature students’ information security awareness has been investigated. Students’ security

awareness is not the only concern in the studies which investigates information security awareness

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 4

level of students. They investigate information security awareness in higher education environment, so

both staff and students are sample group of studies. Marks and Regui have studied factors affecting

information security awareness in higher education environments (Marks and Regui, 2009). In the re-

search, they have investigated and revealed university’s ISP, information security awareness training

applications, auditing procedures. Katz has examined both physical and technical information security

behaviour of employees in higher education institution (Katz, 2005). One of the finding of the study is

that physical information security is ensured in higher education environment whereas technical secu-

rity requires more awareness. Instructive programs within an information security course or a module

of a course oriented to students are recommended in the research.

There is a study that targets only students in higher education. Ahmed and Zeki have investigated rela-

tionship between student’s knowledge and behaviour (Ahmed and Zeki, 2013). According to the re-

sults of the study, students know topics included in security courses if they took those courses. Other

study has been conducted by Kim that information security awareness level of undergraduate and

graduate students in a business college has been searched (Kim, 2014). It has suggested in the research

that information security awareness program should be given to their students for securing systems

and information.

There are also some studies that students are just chosen as sample group. However, what is important

especially for students in terms of information security is not a main focus of those studies (Herath et

al., 2012), (Limanyem and Hirt, 2003).

3 Theoretical Framework and Hypotheses

This section explains theoretical framework of this study and reveals hypotheses which have been

tested. In this research, applied ISP in the company is considered as a part of information security cul-

ture. So, factors which affect information security policy knowledge of students are aimed to be inves-

tigated.

This research contains two parts. Firstly, whether knowing ISP changes security behaviour of students

is intended to be investigated. Then factors which affect ISP knowledge are aimed to be extracted. Es-

pecially second part of this study can be applicable in real life. However, first part of the study has a

critical role to show whether second part is suitable to consider.

First part of the research is explained in Security Behaviour of Students in Personal Computer section

and the second part in Factors Related to Information Security Policy Knowledge section.

3.1 Security Behaviour of Students

In this section hypothesis and related concept are given for the first part of this study.

According to the result of the survey conducted in Lim, Chang, Maynard, and Ahmad’s (Lim et al.,

2010) research, organization’s security culture positively influences ISP compliant behaviour. Infor-

mation security policy is one of the components of information security culture or according to Van

Niekerk & Von Solms (Okere, van Niekerk and Carrol, 2012) it is a level of information security cul-

ture. Lim, Chang, Maynard, and Ahmad (Lim et al., 2010) cited from Thomson, von Solms, and Louw

(Thomson, von Solms and Louw, 2010) that ISP determines acceptable behaviour which constitutes

information security is ensured within daily activities of employees.

Behaviour of employee is one of the most important concerns so as to ensure information security.

Primarily, whether having knowledge about ISP changes security behaviour is aimed to be investigat-

ed. It is assumed that if students have secure behaviour when they are using their PC, they will have

secure behaviour in working environment.

Therefore, following hypothesis is analysed as the first part of this study. Results of conducted test for

the hypothesis is given in Table 1 and Table 2.

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 5

H1: There is a difference between students who have knowledge about ISP or not with respect to secu-

rity behaviour in their personal computer.

3.2 Factors Related to Information Security Policy Knowledge

Research model and hypotheses of the second part of this study is mentioned in this part.

Safa, von Solms and Furnell have shown the positive effect of IS experience on ISP compliant behav-

iour (Safa, von Solms and Furnell, 2016). They define information security experience as being famil-

iar to threats and preventive methods in information security and having the knowledge about how to

act against to risk in information security events.

In the Van Niekerk & Von Solms’s (Okere, van Niekerk and Carrol, 2012), (D’Arcy, Hovav and Gal-

letta, 2009) model, information security knowledge is considered as the least tangible, but the most

supportive layer of the model. When these features of information security knowledge make itself es-

sential component of IS culture, knowledge alone is insufficient to positively contribute information

security culture in terms of behaviour (Alfawaz, Nelson and Mohannak, 2010). Therefore, the role of

information security knowledge is critical in information security culture. However, Okere, van

Niekerk & Carroll (Okere, van Niekerk and Carrol, 2012) emphasize in their work that information

security knowledge is insufficiently evaluated in the literature in terms of information security culture.

That is why knowledge is determined as dependent variable of the conceptual model of this study

shown in Figure 1. Knowledge towards ISP is questioned. Independent variables of the framework are

seen as “taking information security course”, “grade of student”, “current working situation” in Figure

1. In reality only accumulations of student are education and limited working experience, “taking in-

formation security course”, so “current working situation” factors are considered to be investigated.

Moreover, grade of student is considered as a factor of having knowledge about ISP so as to under-

stand whether senior year student closer to be employed than others is readier to adopt information

security culture.

As a summary, hypotheses given in the following paragraphs are aimed to be researched based on pre-

viously explained considerations:

H2: There is a relationship between taking information security course and having knowledge about

ISP.

H3: There is a relationship between the grade of student and having knowledge about ISP.

H4: There is a relationship between current working situation of student and having knowledge about

ISP.

Figure 1. Research Model for The Factors Related to Information Security Policy Knowledge

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 6

4 Data Collection and Analysis

Survey of this study has been published online in May 2015. Participants, higher education students in

Turkey, have been chosen randomly. None of respondents have been excluded from analyses because

of missing or inconsistent answers. Survey questions have been mandatory to answer.

The survey has 8 questions. Questions measure such variables as, “Taking information security

course”, “Current working situation”, “Grade of student”, “Having knowledge about ISP”. They are

self-created questions asked in nominal/ordinal scale.

Moreover, question which measures security behaviour of students in usage of their personal computer

is cited from Talib, Clarke and Furnell’s study (Talib, Clarke and Furnell, 2010). It is asked in 5-point

Likert scale includes 13 items. Because it is multi-item question, reliability test is conducted. Accord-

ing to the reliability analysis, Cronbach’s Alpha equals to 0.794. So, the question is reliable and all

items are used to evaluate behaviour on personal computer variable in the analyses.

Other questions ask ages, departments and previous working experience of students in nominal/ordinal

scale.

SPSS is used for the analyses of questions in this research. Frequency tests are conducted for questions

in nominal/ordinal scale. Hypotheses H2, H3, H4 are analysed with crosstab analysis and another hy-

pothesis H1 is analysed with ANOVA test.

Total of 138 students have responded. Demographic information of survey participants is in following

paragraphs.

The participants of the survey almost equally distribute in gender perspective. 56.52% of all partici-

pants are male while 43.47 % of them are female.

Because the survey is directly related to the students, age range is limited. Based on the conducted re-

search, range shows that the number of people, at the age of 17 and below, is equal to the zero. The

highest rate equal to 65.94% represents the people in the age between 18 and 24. 31.88% of them con-

sist of people from age between 25 and 30. At the age of 31 and over has the lowest rate equal to

2.17%.

Grades of students are given in Figure 2. Based on results, most of participants are senior year students

with 42% of total. Grade is evaluated as two categories in this research; senior grade and higher levels

and lower levels than senior.

Figure 2. Grade of Students

What is more, previous working experiences of students are shown in Figure 3. They were allowed to

response to multiple answers. Students have internship experience mostly. They respond 111 times for

internship.

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 7

Figure 3. Previous Working Experience of Students

In addition to past working experience current working situation has been asked to students. 58% of

them are currently working while rests are not.

Departments of students have been asked in the survey. Most of participants are coming from Depart-

ment of Management Information Systems as it is seen in Figure 4.

Figure 4. Departments of Students

5 Hypotheses Testing Results

In this section tests results of hypotheses are given.

5.1 ANOVA Test Results of H1

As it is mentioned in Research Methodology and Analyses section ANOVA analysis is conducted to

test H1. Based on test results significance value is 0.042. So, there is a significant difference between

students who have knowledge about ISP or not with respect to security behaviour in their personal

computer (Table 1).

Sum of Squares df Mean Square F Sig.

Between Group 2.209 2 1.105 3.254 0.042

Within Groups 45.827 135 0.339 - -

Total 48.036 137 - - -

Table 1. ANOVA Test Results for H1.

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 8

How students’ security behaviour changes based on having knowledge about ISP is given in Table 2.

As it is seen in Table 2 the highest rate in mean value of security behaviour in PC belongs to those

who have knowledge about ISP.

Knowledge about ISP Frequency Mean Value of Security

Behaviour in PC

Yes 52 3.78

Not sure 44 3.71

No 42 3.48

Total 138 3.66

Table 2. Descriptives of ANOVA Test for H1.

5.2 Cross-tab Analyses Results of H2, H3 and H4

At the second part of the research effective factors of ISP knowledge are investigated. Cross-tab anal-

yses are conducted for tests of H2, H3, H4. Results of analyses (Table 3) show that there is a relation-

ship between ISP knowledge and factors; “taking information security course” and “grade of student”,

whereas there is not a relationship between ISP knowledge and “current working situation”.

Pearson Chi-Square Item Value df Asymp. Sig. (2-sided)

Taking IS course 21.896 2 0.0

Grade of student 7.886 2 0.019

Current working situation 4.806 2 0.09

Table 3. Chi-Square Test Results of Cross Tabulation Analyses.

According to the test results of H2, chi-square value is significant by 0 (Table 3). So, there is a signifi-

cant relationship between taking information security course and having knowledge about ISP. Nature

of the relationship is shown in Figure 5 that 56.9% of students who took information security course in

university have ISP knowledge whereas 20.50% of students who didn’t take any information security

course know what ISP is.

Figure 5. Cross Tabulation Results for H2

According to the results there is a relationship between grade of student and their knowledge about

ISP because chi-square value of cross-tab test is significant by 0.019 (Table 3). When 46.90% of sen-

ior and higher-grade students know ISP, only 24.60% of students whose grades are less than senior

know ISP (Figure 6).

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 9

Figure 6. Cross Tabulation Results for H3

Based on the results given in Figure 7 48.30% of students who currently work in a company have

knowledge about ISP but there is not a relationship between current working situation of students and

their knowledge about ISP. Because chi-square value is not a significant by 0.09 (Table 3).

Figure 7. Cross Tabulation Results for H4

6 Conclusion

In this section, more insights about results are given. Related issues are mentioned for further research

projects.

First of all, the most important result of the study is that having a knowledge about ISP makes a differ-

ence on students’ personal computer security behaviour. We can expect that students who behave se-

curely on their personal computer will not threat their prospective companies’ systems with their daily

activities. It is expected that they will comply with their companies’ ISP. Additionally, factors affect

ISP knowledge is found. According to the results, taking information security course and grade of stu-

dents are positively affect students’ knowledge about ISP.

On the other hand, knowledge of students is not affected from their current working situation. This

result can be caused by their past working experiences. Those experiences can be an effective factor

on their insights about working environment. In other words, working experience should be evaluated

by not only current working situation but also past working experiences of respondents. To explain

whether choosing candidates who have an internship/part-time/full-time experience are beneficial for

companies, working experience can be questioned in detail in future research.

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 10

Moreover, another important consideration of working experience can be scale of the company in

which student worked. How candidates have experienced organizational structure in their past work-

ing experience can be significant consideration for an employer in terms of adaptability of organiza-

tional policies.

It can be concluded that whether candidates have taken an information security related course during

university education can be useful criteria for companies in terms of information security culture.

According to the results 73.1% of students who know ISP are senior and higher degree of students, so

it can be concluded that future employees of organizations are knowledgeable in terms of information

security. It can be expected that companies’ future employees have an enough potential to comply

with ISP of their companies and adopt information security culture of the company in a short time.

In future research the most effective factors for creating ISP knowledge of students can be investigated

to develop effective education programs to give new joined employees. Threats and protection meth-

ods can be taught via simulation. Companies can benefit from the prospective results of the future re-

search in terms of choosing the most effective education program.

References

Ahmed, A.A. and A.M. Zeki, (2013). “The influence of students’ knowledge on security towards their

behaviour with security risks within the context of Saudi Arabia,” 2013 International Conference

on Advanced Computer Science Applications and Technologies, pp. 1-4.

Alfawaz, S., K. Nelson, and K. Mohannak, (2010). “Information security culture: A Behaviour Com-

pliance Conceptual Framework,” Proc. 8th Australasian Information Security Conference (AISC

2010), Brisbane, Australia.

Al Hogail, A., and A. Mirza, (2014). “Information Security Culture: A Definition and A Literature

Review,” 2014 World Congress on Computer Applications and Information Systems (WCCAIS),

pp. 1-7.

Bulgurcu, B., H. Cavusoglu, and I. Benbasat, (2010). “Information Security Policy Compliance: An

Empirical Study of Rationality-Based Beliefs and Information Security Awareness,” MIS Quarter-

ly, 34(3), pp. 523–548.

Cavusoglu, H., B. Mishra, and S. Raghunathan, (2004). “A Model for Evaluating IT Security Invest-

ments,” Communications of the ACM, 47(7), pp. 87-92.

D'Arcy, J., A. Hovav, and D. Galletta, (2009) “User awareness of security countermeasures and its

impact on information systems misuse: a deterrence approach,” Information Systems Research,

20(1), pp. 79-98.

Herath, T., R. Chen, J. Wang, K. Banjara, J. Wilbur, and H. R. Rao, (2012). “Security Services as

Coping Mechanisms: An Investigation into User Intention to Adopt an Email Authentication Ser-

vice,” Info Systems J.

Herath, T., and H. G. Rao (2009). “Protection Motivation and Deterrence: A Framework for Security

Policy Compliance in Organisations,” European Journal of Information Systems, 18(2), pp. 106-

125.

Hu, Q., and T. Dinev, (2007). “The centrality of awareness in the formation of user behavioural inten-

tion toward protective information technologies,” Journal of the Association for Information Sys-

tems, 8(7), pp. 386–408.

Hu, Q., T. Dinev, P. Hart, and D. Cooke, (2012). “Managing employee compliance with information

security policies: the role of top management and organizational culture,” Decision Sciences, 43(4).

Ifinedo, P. (2012). “Understanding information systems security policy compliance: an integration of

the theory of planned behaviour and the protection motivation theory,” Computers & Security,

31(1), pp. 83-95.

Students and Information Security Culture

The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 11

International Organization for Standardization/ International Electrotechnical Commission, (2013).

ISO/IEC 27001:2013: Information Technology – Security Techniques – Information Security Man-

agement Systems – Requirements.

ISACA, (2016). “January 2016 Cybersecurity Snapshot Global Results,” [Online] Available:

http://www.isaca.org/cyber/ Documents/2016-Global-Cybersecurity-Snapshot-Data-Sheet_mkt

_Eng _0116.pdf

Johnson, E.C., (2006). “Security Awareness: Switch to a Better Programme,” Network Security,

2006(2), pp. 15-18.

Karlsson, F., J. Åström, and M. Karlsson, (2015). “Information security culture state-of-theart review

between 2000 and 2013", Information & Computer Security, Vol. 23 Iss 3, pp. 246 – 285.

Katz, F.H., (2005). “The Effect of a University Information Security Survey on Instruction Methods in

Information Security”.

Kim, E.B., (2014). "Recommendations for information security awareness training for college stu-

dents," Information Management & Computer Security, vol. 22, pp. 115-126.

Limayem, M. and S.G., Hirt, (2003). “Force of Habit and Information Systems Usage: Theory and

Initial Validation”, Journal of Association for Information Systems, 4, pp. 65- 97.

Lim, J., S. Chang, S. Maynard, and A. Ahmad, (2010). “Embedding information security culture

Emerging concerns and challenges,” in PACIS 2010 Proceedings, pp. 463-474.

Marks, A. and Y. Rezgui, (2009). “A Comparative Study of Information Security Awareness in High-

er Education Based on The Concept of Design Theorizing” International Conference on Manage-

ment and Service Science.

Mitnick, K., (2002). “The Art of Deception: Controlling the Human Element of Security,” Wiley.

Okere, I., J. van Niekerk, and M. Carrol, (2012). “Assessing information security culture: A critical

analysis of current approaches,” Information Security for South Africa (ISSA), pp. 1-8.

PwC, “Key Findings from The Global State of Information Security Survey 2016 [Online] Available:

http://www.pwc.com/gx/en/issues/cyber-security/information-security-survey/download.html

Renaud, K. and W. Goucher, (2014). “The Curious Incidence of Security Breaches by Knowledgeable

Employees and the Pivotal Role of Security Culture,” in Human Aspects of Information Security,

Privacy and Trust, Springer International Publishing, pp. 361-372.

Safa, N.S., R. von Solms, and S. Furnell, (2016). “Information Security Policy Compliance Model in

Organizations,” Computer & Security, 56(2016), pp. 70-82.

Schlienger, T. and S. Teufel, (2003). “Analyzing Information Security Culture: Increased Trust by an

Appropriate Information Security Culture,” 14th International Workshop on Database and Expert

Systems Applications Proceedings.

Talib, N.L. Clarke, and S.M. Furnell, (2010). “An analysis of information security awareness within

home and work environments,” InAvailability, Reliability, and Security, ARES'10 International

Conference, pp. 196-203.

Thomson, K., von Solms, R., and Louw, L., (2006). “Cultivating an Organizational Information Secu-

rity Culture,” Computer Fraud & Security, 2006(10), pp. 7-11.

Van Niekerk, J. and R. von Solms, (2010). “Information security culture: A management perspective,”

Computers & Security, vol. 29, pp. 476-486.

Wilson, M., Hash, J., (2003). Building an Information Technology Security Awareness and Training

Program. NIST SP 800-50.

View publication statsView publication stats