Establishing a conceptual model for information security framework including human factor
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
The manner in which employees perceive and interact (behave) with controls implemented to protect information assets is one of the main threats to the protection of such assets and the effective use of information security controls and human role. Should the interaction not be conductive to the protection of the information assets, it can have a profound impact on the profit of an organisation, productive working hours could be lost, confidential information might be disclosed to unauthorised people and compliance with legal and regulatory regulations could be affected – all this, despite the fact that adequate technical and procedural controls might be in place. Current research highlights the importance of a strong information security awareness, culture, policy and management to address the threat that employee behaviour poses to the protection of information. Various research perspectives propose how an acceptable level of information security awareness, policy, management and culture should be promoted, and how to assess this human to determine whether it is on an acceptable level. These approaches are however not adequate to promote information security awareness, information security policy, information security management, information security culture, as all the relevant information security components and the influences on the information security framework have to be considered. This leads to the question as to whether the instruments proposed to assess the information security framework are indeed adequate and valid. The main contribution of this research relates to the development of an information security framework and process consisting of an instrument to assess information security awareness, culture, policy and management. In order to develop the information security framework based on human role, the researcher developed a Conceptual Information Security Framework (CISF) that equips organisations with a holistic approach to the implementation of information security. The framework provides a single point of reference for the governance of information security and human. The Information Security awareness Framework (ISAF), Information Security Culture Framework (ISCF), Information Security Policy Framework (ISPF) and Information Security Management Framework (ISMF) is developed using the CISF as foundation. It considers all the components required for information security namely information security, organisational culture and human, behaviour, culture, policy, trust, awareness, management, busines and privacy. It integrates the aforementioned concepts and illustrates the influence between the components. The ISAF, ISCF, ISPF, ISMF further serves as a basis for designing an information security awareness, culture, policy and management assessment instrument. This instrument is incorporated as part of an Information Security Assessment process (ISFHF) defined by the researcher. ISFHF provides management with the steps to conduct an human behaviour assessment, as well as the steps to validate the assessment instrument. The application of ISFHF is tested in an empirical study conducted in an organisation, group and individual environment. It illustrates how to validate an information security awarenees, culture, policy and management assessment instrument by ensuring that it is designed based on the CISF and meets the statistical requirements for a valid and reliable assessment instrument. Both the ISAF, ISCF, ISPF, ISMF and the ISFHF process can ultimately be deployed by organisations to minimise the threat that employee behaviour poses to the protection of information assets. Keywords:Information Security, Policy, Awareness, Management, Culture
Author
Oldouz Karimi
Institution
How to Cite
Oldouz Karimi (Doctorate thesis). Establishing a conceptual model for information security framework including human factor, 2018, İstanbul University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from İstanbul University
- Determination of total anthocyanin, caretenoid andantioxidant capacity of black goji berry (Lycium ruthenicummurr.) fruits(2021)
- Abulfaz Elchibey and his family life(2021)
- In the covid 19 pandemic of female employees at a university hospital attitudes and affecting factors in nutrition of 9 months-6 years old children(2022)
- New surveillance paradigms in the COVİD-19 era: Critical discourse analysis on a cross-secti̇onal sample of Health Minister Fahrettin Koca's twitter posts(2022)
- Buying and selling precious documents in terms of Islamic Law(2022)
- Analysis of clinical correlation of radiological imaging in idiopathic pulmonary fibrosis by quantitative computed tomography(2020)