Master'sOpen Access

Evaluation of information security management awareness within the scope of ISO/IEC 27001: The case of Ankara province health institutions information processing unit employees

Is this your thesis?

This record came from a bulk archive import. If it’s yours, link it to your profile.

2023
0 views
0 downloads

Abstract (EN)

Health institutions are a sector where medical and administrative data are used intensively as well as personal information of patients and information and communication technologies that enable the definition, evaluation, application, storage and data sharing of this information are used intensively and effectively. The health sector is faced with greater cyber risks due to the importance of the data obtained compared to other sectors, and the implementation of information security policies for the control of data breaches that may be encountered becomes a mandatory process. Information security emerges as a complex process that is not only related to the security of information systems of health facilities, but also affected by many factors related to the human factor, condition of devices, personnel diversity, access authorization, privacy, cost, ethics, education and duty level in the information security process.The purpose of this research is to analyze the applications of the IT personnel responsible for the processes of all kinds of operational activities in terms of the IT infrastructure of health facilities within the scope of the Information Security Policy Directive of the Ministry of Health; According to the survey prepared by ISO/IEC 27001 Information Technology - Security Techniques - Information Security Management Systems - Requirements document in parallel with Reference Control Objectives and Controls (Kılıç 2019) in Annex-A, conceptual awareness levels and gender, experience, education level, title The aim is to reveal the relationship between information security management awareness according to the unit, the type of institution and the capacity of the institution. Managers, engineers, technicians and other public personnel working in the IT unit of Ankara Provincial Health Directorate and all affiliated health facilities (Central Directorate, Hospitals, District Hospitals, District Health Directorates, Integrated Hospitals) and data processing personnel employed in health facilities by service procurement method. Data for the purpose of the study were obtained through the answers given to the data collection tool by 268 health workers who voluntarily participated in the study. In the study, Mann_Whitney U test and Kruskall-Wallis H test, which is one of the non-parametric methods, were used to compare the group averages, since the descriptive statistics and department scores were not normally distributed. When the Cronbach Alpha values of the sub-objective question groups for each research problem were examined, it was observed that the results were between .88 and .98, and it was observed that the scales used in the analyzes were reliable. 66.2% of the 260 health workers who participated in the survey work in the second and third level health facilities. 35% of the participants have undergraduate education, 37.7% are in the 34-41 age group, 72.7% are male and 80.00% are married. 25% of the participants have 6-10 years of service. Of the participants, 163 (62.7%) were technicians, technicians or IT personnel working with the service procurement method, who settled with public procurement, and 66.2% of the personnel worked directly in the information processing unit, 17.3% of them He works as a manager at the facility. In response to the yes, partially and no answers given to each question in the information security management awareness evaluation form of healthcare professionals, at least 95.77% of the answers given to the departments gave a yes answer; It has been determined that there is a significant and positive relationship between educational status, title, type of institution, capacity of the institution and the level of conceptual awareness of information security management policies. In response to the yes, partially and no answers given by the healthcare professionals to each question in the information security management awareness evaluation form, at least 95.77% of the answers given to the departments gave a yes answer; It has been determined that there is a significant and positive relationship between educational status, title, type of institution, the capacity of the institution, and the level of conceptual awareness of information security management policies.

Author

Hadis Soysal

How to Cite

Hadis Soysal (Master Thesis). Evaluation of information security management awareness within the scope of ISO/IEC 27001: The case of Ankara province health institutions information processing unit employees, 2023, Necmettin Erbakan University.

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Necmettin Erbakan University