Data Collection Instruments - Write an analysis on the variables of a survey designed to collect data.
See discussions, stats, and author profiles for this publication at: https://www.researchgate.net/publication/320456625
Students and Information Security Culture in Organizations
Conference Paper · July 2017
CITATIONS
0 READS
247
2 authors:
Some of the authors of this publication are also working on these related projects:
Cybersecurity Camps and Trainings for students and Public Sector View project
Nur Sena Tanrıverdi
Bogazici University
3 PUBLICATIONS 3 CITATIONS
SEE PROFILE
Bilgin Metin
Bogazici University
98 PUBLICATIONS 1,016 CITATIONS
SEE PROFILE
All content following this page was uploaded by Bilgin Metin on 31 May 2020.
The user has requested enhancement of the downloaded file.
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017
STUDENTS AND INFORMATION SECURITY CULTURE IN
ORGANIZATIONS
Research-in-Progress
Track 10
Tanrıverdi, Nur Sena, Bogazici University, Istanbul, Turkey, [email protected]
Metin, Bilgin, Bogazici University, Istanbul, Turkey, [email protected]
Abstract
Employees’ Information security policy (ISP) complied actions ensures security in organizations. Dai-
ly interaction with information system and behaviour of employees against security issues are affected
by information security culture of organization. ISP of an organization can be evaluated as a part of
an information security culture of organization. Obviously, adoption of the culture takes time especial-
ly for new hires. When threats are evolving and systems are becoming more complex, information se-
curity culture is important to be adopted by new hires in a short time. Therefore, this study targets
potential employees of organizations; students. Although security behaviour and awareness of stu-
dents are examined in previous studies, they aren’t evaluated within information security culture as
future employees of organizations. In this study, security behaviour and policy knowledge of students,
and effective factors for policy knowledge are examined. According to the results, knowing ISP chang-
es security behaviour of students. If students know what ISP is, they will probably not threat systems
with their daily activities and comply with ISP of their future organizations. 73.1% of students who
know ISP are senior and higher degree of students, so it can be concluded that future employees of
organizations are knowledgeable in terms of information security.
Keywords: Security Awareness of Student, Information Security Culture, Information Security Policy,
Security Behaviour.
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 2
1 Introduction
Most organizations’ operations are largely based on IT. Thus, managing risk related to information
security attacks is getting increasingly significant because infractions of information security often
have critical financial and reputational outcomes for organizations and their users (Cavusoglu, Mishra
and Raghunathan, 2004). That’s why protecting information security has become priority for compa-
nies.
IT systems are used in a variety of fields including transmission, storage and data processing in all
organizations regardless size. That’s why companies take a big care of security of their vital assets; IT
systems. Security of these systems is provided by using technical solutions like authentication, cryp-
tography, advanced firewalls against to attacks. However, technical solutions cannot succeed in pro-
tecting systems completely when human factor is ignored (Johnson, 2006). Employees have the most
critical role in the protection of information systems of their companies. According to participants of
ISACA’s 2016 Cybersecurity Snapshot Survey (ISACA, 2016) social engineering, insider threats and
advanced persistent threat are respectively the most important consideration for their organization in
2016. Intentional or unintentional actions of people are the biggest threat for organizations.
The Global State of Information Security Survey 2016 of PwC (PwC, 2016) shows that current em-
ployees have threated companies at most. 34% of security incidents in 2015 have been caused by cur-
rent employees according to results of the survey.
End-user is “the weakest link in the information security chain” (Mitnick, 2002). From the organiza-
tional perspective, the weakest chain is the new joiners because they are unfamiliar to the organiza-
tional culture. Information security culture is considered as an aspect of organizational culture (Okere,
van Niekerk and Carrol, 2012), (Schlienger and Teufel, 2003). It is embedded in a company so as to
ensure secure environment.
Al Hogail and Mirza defined information security culture as “The collection of perceptions, attitudes,
values, assumptions and knowledge that guides how thing are done in an organization in order to be
consistent with the information security requirements with the aim of protecting the information assets
and influencing employees’ security behaviour in a way that preserving the information security be-
comes a second nature” (Al Hogail and Mirza, 2014). Thus, it can be said that if an organization has
an information security culture, it has a defined information security policy (ISP). ISP of a company
bases on standards and it should be open for access of all employees (International Organization for
Standardization, 2013). It is expected that every employee complies with this policy. Because adaption
of rules and environment takes time for new employees, they probably have higher potential than oth-
ers in terms of threatening of information security.
New employees of the IT departments are expected to be aware about information security because of
their IT related backgrounds. But companies employ non-IT related employees in such departments as
finance, marketing and human resources to conduct main business and those employees are mostly
unfamiliar to the IT related concepts like information security.
However regardless their departments and backgrounds they all are responsible for corporate general
security. So, companies continuously support employees with different kind of education and training
programs. Not only information security related training programs but also various informative activi-
ties are generally applied in organizations. For example, security department informs all organization
against new threats in Internet environment via e-mails, posters, pop-up screens and newsletters, web
based sections, desk-to-desk alerts and email messages in informative context (Wilson and Hash,
2003). These continuous educative activities begin with orientation programs for new employees.
General security awareness is given to new joiners in orientation programs.
In previous studies, although security behaviour and awareness of students are examined, they are not
evaluated within information security culture as future employees of organizations. Security behaviour
and policy knowledge of students, and effective factors for policy knowledge are examined within this
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 3
study. According to the results, knowing ISP changes security behaviour of students. If students know
what ISP is, they will probably not threat systems with their daily activities and comply with ISP of
their future organizations. 73.1% of students who know ISP are senior and higher degree of students,
so it can be concluded that future employees of organizations are knowledgeable in terms of infor-
mation security.
2 Literature Review
In this section, previous studies on information security culture, information security policy compli-
ance, and student awareness are summarized so as to reveal what kind of outcomes have been present-
ed related to the concepts fundamental for the perspective of this study; students and information secu-
rity culture. Information security culture, information security policy compliance and student aware-
ness studies are reviewed to understand what kind of studies have been conducted, which factors have
been investigated in the literature.
2.1 Information Security Culture and Policy Compliance
Information security culture is a key term to understand, estimate and evaluate security behaviour of
human and the term is approached differently in the literature. Basically, it can be considered as the
subculture of organizational culture which constitutes company-wide shared values (Okere, van
Niekerk and Carrol, 2012), (Schlienger and Teufel, 2003).
The most common approach for information security culture has been derived from Schein’s organiza-
tional culture model by van Niekerk & von Solms (Renaud and Goucher, 2014). They present layers
of IS culture; artefacts, espoused values, shared tacit assumptions and information security knowledge
(Renaud and Goucher, 2014), (D'Arcy, Hovav and Galletta, 2009), (van Niekerk and von Solms,
2010).
The literature has different aspects of information security culture. One of them is an analysis of dif-
ferent information security culture definitions (Al Hogail and Mirza, 2014). Moreover Okere, van
Niekerk and Carroll (Okere, van Niekerk and Carrol, 2012) have analysed different approaches of in-
formation security culture in the literature. According to them, usual approach to assess information
security culture is auditing.
Karlsson, Åström and Karlsson’s literature review study shows that content of information security
culture, roots and consequences of information security culture and cultivating information security
culture have been commonly investigated in literature (Karlsson, Åström and Karlsson, 2015). They
summarize theories which have tried to explain contributive factors of information security culture.
Those theories are Schein’s (1985) culture model, competing values framework (Quinn and Cameron,
1983), theory of planned behaviour (Ajzen, 1991), Hofstede’s (1997) national culture framework, in-
formation security behaviour modes (Alfawaz, Nelson and Mohannak, 2010), Nonaka’s modes of
knowledge creation (Thomson, von Solms and Louw, 2010), and Lazarus’ (1993) stress model.
Information security behaviour is usually considered as behaviour that comply with information secu-
rity policy of a company in the literature. Effective factors on information security policy compliance
are also searched in information security literature. In addition to this, those factors are evaluated
based on the theories (Bulgurcu, Cavusoglu and Benbasat, 2010), (Pahnila et al., 2007), (Hu et al.,
2012), (Safa, von Solms and Furnell, 2016). There are also some studies that combine theories to ful-
fill the research gap in the literature (Bulgurcu, Cavusoglu and Benbasat, 2010), (Herath and Rao,
2009), (Ifinedo, 2012), (Hu and Dinev, 2007).
2.2 Security Awareness of Students
In the literature students’ information security awareness has been investigated. Students’ security
awareness is not the only concern in the studies which investigates information security awareness
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 4
level of students. They investigate information security awareness in higher education environment, so
both staff and students are sample group of studies. Marks and Regui have studied factors affecting
information security awareness in higher education environments (Marks and Regui, 2009). In the re-
search, they have investigated and revealed university’s ISP, information security awareness training
applications, auditing procedures. Katz has examined both physical and technical information security
behaviour of employees in higher education institution (Katz, 2005). One of the finding of the study is
that physical information security is ensured in higher education environment whereas technical secu-
rity requires more awareness. Instructive programs within an information security course or a module
of a course oriented to students are recommended in the research.
There is a study that targets only students in higher education. Ahmed and Zeki have investigated rela-
tionship between student’s knowledge and behaviour (Ahmed and Zeki, 2013). According to the re-
sults of the study, students know topics included in security courses if they took those courses. Other
study has been conducted by Kim that information security awareness level of undergraduate and
graduate students in a business college has been searched (Kim, 2014). It has suggested in the research
that information security awareness program should be given to their students for securing systems
and information.
There are also some studies that students are just chosen as sample group. However, what is important
especially for students in terms of information security is not a main focus of those studies (Herath et
al., 2012), (Limanyem and Hirt, 2003).
3 Theoretical Framework and Hypotheses
This section explains theoretical framework of this study and reveals hypotheses which have been
tested. In this research, applied ISP in the company is considered as a part of information security cul-
ture. So, factors which affect information security policy knowledge of students are aimed to be inves-
tigated.
This research contains two parts. Firstly, whether knowing ISP changes security behaviour of students
is intended to be investigated. Then factors which affect ISP knowledge are aimed to be extracted. Es-
pecially second part of this study can be applicable in real life. However, first part of the study has a
critical role to show whether second part is suitable to consider.
First part of the research is explained in Security Behaviour of Students in Personal Computer section
and the second part in Factors Related to Information Security Policy Knowledge section.
3.1 Security Behaviour of Students
In this section hypothesis and related concept are given for the first part of this study.
According to the result of the survey conducted in Lim, Chang, Maynard, and Ahmad’s (Lim et al.,
2010) research, organization’s security culture positively influences ISP compliant behaviour. Infor-
mation security policy is one of the components of information security culture or according to Van
Niekerk & Von Solms (Okere, van Niekerk and Carrol, 2012) it is a level of information security cul-
ture. Lim, Chang, Maynard, and Ahmad (Lim et al., 2010) cited from Thomson, von Solms, and Louw
(Thomson, von Solms and Louw, 2010) that ISP determines acceptable behaviour which constitutes
information security is ensured within daily activities of employees.
Behaviour of employee is one of the most important concerns so as to ensure information security.
Primarily, whether having knowledge about ISP changes security behaviour is aimed to be investigat-
ed. It is assumed that if students have secure behaviour when they are using their PC, they will have
secure behaviour in working environment.
Therefore, following hypothesis is analysed as the first part of this study. Results of conducted test for
the hypothesis is given in Table 1 and Table 2.
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 5
H1: There is a difference between students who have knowledge about ISP or not with respect to secu-
rity behaviour in their personal computer.
3.2 Factors Related to Information Security Policy Knowledge
Research model and hypotheses of the second part of this study is mentioned in this part.
Safa, von Solms and Furnell have shown the positive effect of IS experience on ISP compliant behav-
iour (Safa, von Solms and Furnell, 2016). They define information security experience as being famil-
iar to threats and preventive methods in information security and having the knowledge about how to
act against to risk in information security events.
In the Van Niekerk & Von Solms’s (Okere, van Niekerk and Carrol, 2012), (D’Arcy, Hovav and Gal-
letta, 2009) model, information security knowledge is considered as the least tangible, but the most
supportive layer of the model. When these features of information security knowledge make itself es-
sential component of IS culture, knowledge alone is insufficient to positively contribute information
security culture in terms of behaviour (Alfawaz, Nelson and Mohannak, 2010). Therefore, the role of
information security knowledge is critical in information security culture. However, Okere, van
Niekerk & Carroll (Okere, van Niekerk and Carrol, 2012) emphasize in their work that information
security knowledge is insufficiently evaluated in the literature in terms of information security culture.
That is why knowledge is determined as dependent variable of the conceptual model of this study
shown in Figure 1. Knowledge towards ISP is questioned. Independent variables of the framework are
seen as “taking information security course”, “grade of student”, “current working situation” in Figure
1. In reality only accumulations of student are education and limited working experience, “taking in-
formation security course”, so “current working situation” factors are considered to be investigated.
Moreover, grade of student is considered as a factor of having knowledge about ISP so as to under-
stand whether senior year student closer to be employed than others is readier to adopt information
security culture.
As a summary, hypotheses given in the following paragraphs are aimed to be researched based on pre-
viously explained considerations:
H2: There is a relationship between taking information security course and having knowledge about
ISP.
H3: There is a relationship between the grade of student and having knowledge about ISP.
H4: There is a relationship between current working situation of student and having knowledge about
ISP.
Figure 1. Research Model for The Factors Related to Information Security Policy Knowledge
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 6
4 Data Collection and Analysis
Survey of this study has been published online in May 2015. Participants, higher education students in
Turkey, have been chosen randomly. None of respondents have been excluded from analyses because
of missing or inconsistent answers. Survey questions have been mandatory to answer.
The survey has 8 questions. Questions measure such variables as, “Taking information security
course”, “Current working situation”, “Grade of student”, “Having knowledge about ISP”. They are
self-created questions asked in nominal/ordinal scale.
Moreover, question which measures security behaviour of students in usage of their personal computer
is cited from Talib, Clarke and Furnell’s study (Talib, Clarke and Furnell, 2010). It is asked in 5-point
Likert scale includes 13 items. Because it is multi-item question, reliability test is conducted. Accord-
ing to the reliability analysis, Cronbach’s Alpha equals to 0.794. So, the question is reliable and all
items are used to evaluate behaviour on personal computer variable in the analyses.
Other questions ask ages, departments and previous working experience of students in nominal/ordinal
scale.
SPSS is used for the analyses of questions in this research. Frequency tests are conducted for questions
in nominal/ordinal scale. Hypotheses H2, H3, H4 are analysed with crosstab analysis and another hy-
pothesis H1 is analysed with ANOVA test.
Total of 138 students have responded. Demographic information of survey participants is in following
paragraphs.
The participants of the survey almost equally distribute in gender perspective. 56.52% of all partici-
pants are male while 43.47 % of them are female.
Because the survey is directly related to the students, age range is limited. Based on the conducted re-
search, range shows that the number of people, at the age of 17 and below, is equal to the zero. The
highest rate equal to 65.94% represents the people in the age between 18 and 24. 31.88% of them con-
sist of people from age between 25 and 30. At the age of 31 and over has the lowest rate equal to
2.17%.
Grades of students are given in Figure 2. Based on results, most of participants are senior year students
with 42% of total. Grade is evaluated as two categories in this research; senior grade and higher levels
and lower levels than senior.
Figure 2. Grade of Students
What is more, previous working experiences of students are shown in Figure 3. They were allowed to
response to multiple answers. Students have internship experience mostly. They respond 111 times for
internship.
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 7
Figure 3. Previous Working Experience of Students
In addition to past working experience current working situation has been asked to students. 58% of
them are currently working while rests are not.
Departments of students have been asked in the survey. Most of participants are coming from Depart-
ment of Management Information Systems as it is seen in Figure 4.
Figure 4. Departments of Students
5 Hypotheses Testing Results
In this section tests results of hypotheses are given.
5.1 ANOVA Test Results of H1
As it is mentioned in Research Methodology and Analyses section ANOVA analysis is conducted to
test H1. Based on test results significance value is 0.042. So, there is a significant difference between
students who have knowledge about ISP or not with respect to security behaviour in their personal
computer (Table 1).
Sum of Squares df Mean Square F Sig.
Between Group 2.209 2 1.105 3.254 0.042
Within Groups 45.827 135 0.339 - -
Total 48.036 137 - - -
Table 1. ANOVA Test Results for H1.
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 8
How students’ security behaviour changes based on having knowledge about ISP is given in Table 2.
As it is seen in Table 2 the highest rate in mean value of security behaviour in PC belongs to those
who have knowledge about ISP.
Knowledge about ISP Frequency Mean Value of Security
Behaviour in PC
Yes 52 3.78
Not sure 44 3.71
No 42 3.48
Total 138 3.66
Table 2. Descriptives of ANOVA Test for H1.
5.2 Cross-tab Analyses Results of H2, H3 and H4
At the second part of the research effective factors of ISP knowledge are investigated. Cross-tab anal-
yses are conducted for tests of H2, H3, H4. Results of analyses (Table 3) show that there is a relation-
ship between ISP knowledge and factors; “taking information security course” and “grade of student”,
whereas there is not a relationship between ISP knowledge and “current working situation”.
Pearson Chi-Square Item Value df Asymp. Sig. (2-sided)
Taking IS course 21.896 2 0.0
Grade of student 7.886 2 0.019
Current working situation 4.806 2 0.09
Table 3. Chi-Square Test Results of Cross Tabulation Analyses.
According to the test results of H2, chi-square value is significant by 0 (Table 3). So, there is a signifi-
cant relationship between taking information security course and having knowledge about ISP. Nature
of the relationship is shown in Figure 5 that 56.9% of students who took information security course in
university have ISP knowledge whereas 20.50% of students who didn’t take any information security
course know what ISP is.
Figure 5. Cross Tabulation Results for H2
According to the results there is a relationship between grade of student and their knowledge about
ISP because chi-square value of cross-tab test is significant by 0.019 (Table 3). When 46.90% of sen-
ior and higher-grade students know ISP, only 24.60% of students whose grades are less than senior
know ISP (Figure 6).
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 9
Figure 6. Cross Tabulation Results for H3
Based on the results given in Figure 7 48.30% of students who currently work in a company have
knowledge about ISP but there is not a relationship between current working situation of students and
their knowledge about ISP. Because chi-square value is not a significant by 0.09 (Table 3).
Figure 7. Cross Tabulation Results for H4
6 Conclusion
In this section, more insights about results are given. Related issues are mentioned for further research
projects.
First of all, the most important result of the study is that having a knowledge about ISP makes a differ-
ence on students’ personal computer security behaviour. We can expect that students who behave se-
curely on their personal computer will not threat their prospective companies’ systems with their daily
activities. It is expected that they will comply with their companies’ ISP. Additionally, factors affect
ISP knowledge is found. According to the results, taking information security course and grade of stu-
dents are positively affect students’ knowledge about ISP.
On the other hand, knowledge of students is not affected from their current working situation. This
result can be caused by their past working experiences. Those experiences can be an effective factor
on their insights about working environment. In other words, working experience should be evaluated
by not only current working situation but also past working experiences of respondents. To explain
whether choosing candidates who have an internship/part-time/full-time experience are beneficial for
companies, working experience can be questioned in detail in future research.
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 10
Moreover, another important consideration of working experience can be scale of the company in
which student worked. How candidates have experienced organizational structure in their past work-
ing experience can be significant consideration for an employer in terms of adaptability of organiza-
tional policies.
It can be concluded that whether candidates have taken an information security related course during
university education can be useful criteria for companies in terms of information security culture.
According to the results 73.1% of students who know ISP are senior and higher degree of students, so
it can be concluded that future employees of organizations are knowledgeable in terms of information
security. It can be expected that companies’ future employees have an enough potential to comply
with ISP of their companies and adopt information security culture of the company in a short time.
In future research the most effective factors for creating ISP knowledge of students can be investigated
to develop effective education programs to give new joined employees. Threats and protection meth-
ods can be taught via simulation. Companies can benefit from the prospective results of the future re-
search in terms of choosing the most effective education program.
References
Ahmed, A.A. and A.M. Zeki, (2013). “The influence of students’ knowledge on security towards their
behaviour with security risks within the context of Saudi Arabia,” 2013 International Conference
on Advanced Computer Science Applications and Technologies, pp. 1-4.
Alfawaz, S., K. Nelson, and K. Mohannak, (2010). “Information security culture: A Behaviour Com-
pliance Conceptual Framework,” Proc. 8th Australasian Information Security Conference (AISC
2010), Brisbane, Australia.
Al Hogail, A., and A. Mirza, (2014). “Information Security Culture: A Definition and A Literature
Review,” 2014 World Congress on Computer Applications and Information Systems (WCCAIS),
pp. 1-7.
Bulgurcu, B., H. Cavusoglu, and I. Benbasat, (2010). “Information Security Policy Compliance: An
Empirical Study of Rationality-Based Beliefs and Information Security Awareness,” MIS Quarter-
ly, 34(3), pp. 523–548.
Cavusoglu, H., B. Mishra, and S. Raghunathan, (2004). “A Model for Evaluating IT Security Invest-
ments,” Communications of the ACM, 47(7), pp. 87-92.
D'Arcy, J., A. Hovav, and D. Galletta, (2009) “User awareness of security countermeasures and its
impact on information systems misuse: a deterrence approach,” Information Systems Research,
20(1), pp. 79-98.
Herath, T., R. Chen, J. Wang, K. Banjara, J. Wilbur, and H. R. Rao, (2012). “Security Services as
Coping Mechanisms: An Investigation into User Intention to Adopt an Email Authentication Ser-
vice,” Info Systems J.
Herath, T., and H. G. Rao (2009). “Protection Motivation and Deterrence: A Framework for Security
Policy Compliance in Organisations,” European Journal of Information Systems, 18(2), pp. 106-
125.
Hu, Q., and T. Dinev, (2007). “The centrality of awareness in the formation of user behavioural inten-
tion toward protective information technologies,” Journal of the Association for Information Sys-
tems, 8(7), pp. 386–408.
Hu, Q., T. Dinev, P. Hart, and D. Cooke, (2012). “Managing employee compliance with information
security policies: the role of top management and organizational culture,” Decision Sciences, 43(4).
Ifinedo, P. (2012). “Understanding information systems security policy compliance: an integration of
the theory of planned behaviour and the protection motivation theory,” Computers & Security,
31(1), pp. 83-95.
Students and Information Security Culture
The 11th Mediterranean Conference on Information Systems (MCIS), Genoa, Italy, 2017 11
International Organization for Standardization/ International Electrotechnical Commission, (2013).
ISO/IEC 27001:2013: Information Technology – Security Techniques – Information Security Man-
agement Systems – Requirements.
ISACA, (2016). “January 2016 Cybersecurity Snapshot Global Results,” [Online] Available:
http://www.isaca.org/cyber/ Documents/2016-Global-Cybersecurity-Snapshot-Data-Sheet_mkt
_Eng _0116.pdf
Johnson, E.C., (2006). “Security Awareness: Switch to a Better Programme,” Network Security,
2006(2), pp. 15-18.
Karlsson, F., J. Åström, and M. Karlsson, (2015). “Information security culture state-of-theart review
between 2000 and 2013", Information & Computer Security, Vol. 23 Iss 3, pp. 246 – 285.
Katz, F.H., (2005). “The Effect of a University Information Security Survey on Instruction Methods in
Information Security”.
Kim, E.B., (2014). "Recommendations for information security awareness training for college stu-
dents," Information Management & Computer Security, vol. 22, pp. 115-126.
Limayem, M. and S.G., Hirt, (2003). “Force of Habit and Information Systems Usage: Theory and
Initial Validation”, Journal of Association for Information Systems, 4, pp. 65- 97.
Lim, J., S. Chang, S. Maynard, and A. Ahmad, (2010). “Embedding information security culture
Emerging concerns and challenges,” in PACIS 2010 Proceedings, pp. 463-474.
Marks, A. and Y. Rezgui, (2009). “A Comparative Study of Information Security Awareness in High-
er Education Based on The Concept of Design Theorizing” International Conference on Manage-
ment and Service Science.
Mitnick, K., (2002). “The Art of Deception: Controlling the Human Element of Security,” Wiley.
Okere, I., J. van Niekerk, and M. Carrol, (2012). “Assessing information security culture: A critical
analysis of current approaches,” Information Security for South Africa (ISSA), pp. 1-8.
PwC, “Key Findings from The Global State of Information Security Survey 2016 [Online] Available:
http://www.pwc.com/gx/en/issues/cyber-security/information-security-survey/download.html
Renaud, K. and W. Goucher, (2014). “The Curious Incidence of Security Breaches by Knowledgeable
Employees and the Pivotal Role of Security Culture,” in Human Aspects of Information Security,
Privacy and Trust, Springer International Publishing, pp. 361-372.
Safa, N.S., R. von Solms, and S. Furnell, (2016). “Information Security Policy Compliance Model in
Organizations,” Computer & Security, 56(2016), pp. 70-82.
Schlienger, T. and S. Teufel, (2003). “Analyzing Information Security Culture: Increased Trust by an
Appropriate Information Security Culture,” 14th International Workshop on Database and Expert
Systems Applications Proceedings.
Talib, N.L. Clarke, and S.M. Furnell, (2010). “An analysis of information security awareness within
home and work environments,” InAvailability, Reliability, and Security, ARES'10 International
Conference, pp. 196-203.
Thomson, K., von Solms, R., and Louw, L., (2006). “Cultivating an Organizational Information Secu-
rity Culture,” Computer Fraud & Security, 2006(10), pp. 7-11.
Van Niekerk, J. and R. von Solms, (2010). “Information security culture: A management perspective,”
Computers & Security, vol. 29, pp. 476-486.
Wilson, M., Hash, J., (2003). Building an Information Technology Security Awareness and Training
Program. NIST SP 800-50.
View publication statsView publication stats