To read this content please select one of the options below:

Holistic framework for evaluating and improving information security culture

Krunoslav Arbanas (Croatian Energy Regulatory Agency, Zagreb, Croatia)
Mario Spremic (Faculty of Economics and Business, University of Zagreb, Zagreb, Croatia)
Nikolina Zajdela Hrustek (Faculty of Organisation and Informatics, University of Zagreb, Varazdin, Croatia)

Aslib Journal of Information Management

ISSN: 2050-3806

Article publication date: 17 August 2021

Issue publication date: 6 September 2021

610

Abstract

Purpose

The objective of this research was to propose and validate a holistic framework for information security culture evaluation, built around a novel approach, which includes technological, organizational and social issues. The framework's validity and reliability were determined with the help of experts in the information security field and by using multivariate statistical methods.

Design/methodology/approach

The conceptual framework was constructed upon a detailed literature review and validated using a range of methods: first, measuring instrument was developed, and then content and construct validity of measuring instrument was confirmed via experts' opinion and by closed map sorting method. Convergent validity was confirmed by factor analysis, while the reliability of the measuring instrument was tested using Cronbach's alpha coefficient to measure internal consistency.

Findings

The proposed framework was validated based upon the results of empirical research and the usage of multivariate analysis. The resulting framework ultimately consists of 46 items (manifest variables), describing eight factors (first level latent variables), grouped into three categories (second level latent variables). These three categories were built around technological, organizational and social issues.

Originality/value

This paper contributes to the body of knowledge in information security culture by developing and validating holistic framework for information security culture evaluation, which does not observe information security culture in only one aspect but takes into account its organizational, sociological and technical component.

Keywords

Citation

Arbanas, K., Spremic, M. and Zajdela Hrustek, N. (2021), "Holistic framework for evaluating and improving information security culture", Aslib Journal of Information Management, Vol. 73 No. 5, pp. 699-719. https://doi.org/10.1108/AJIM-02-2021-0037

Publisher

:

Emerald Publishing Limited

Copyright © 2021, Emerald Publishing Limited

Related articles