A Composite Framework to Promote Information Security Policy Compliance in Organizations

0Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Information security policy (ISP) noncompliance continue to impede information security in organizations. This paper consolidates the strength of previous studies into an effective single solution. The paper, first, synthesizes the existing literature and groups relevant ISP compliance factors into user involvement, personality types, security awareness and training, behavioral factors, and information security culture. Secondly, a generic framework that guides the development of frameworks for ISP compliance in organizations was developed based on the literature review. The generic framework categorized elements required for developing an ISP compliance framework into structure, content and outcome elements. Thirdly, the generic framework was applied to develop a composite ISP compliance framework that proposes the establishment of ISP compliance as a culture in organizations. Finally, the results of the expert review assessment showed that the proposed composite ISP framework was suitable, structurally sound and fit for purpose.

Cite

CITATION STYLE

APA

Amankwa, E., Loock, M., & Kritzinger, E. (2020). A Composite Framework to Promote Information Security Policy Compliance in Organizations. In Learning and Analytics in Intelligent Systems (Vol. 7, pp. 458–468). Springer Nature. https://doi.org/10.1007/978-3-030-36778-7_51

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free