To read this content please select one of the options below:

Information security practice in Saudi Arabia: case study on Saudi organizations

Zakarya A. Alzamil (Software Engineering Department, King Saud University, Riyadh, Saudi Arabia)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 12 November 2018

498

Abstract

Purpose

Information security of an organization is influenced by the deployed policy and procedures. Information security policy reflects the organization’s attitude to the protection of its information assets. The purpose of this paper is to investigate the status of the information security policy at a subset of Saudi’s organizations by understanding the perceptions of their information technology’s employees.

Design/methodology/approach

A descriptive and statistical approach has been used to describe the collected data and characteristics of the IT employees and managers to understand the information security policy at the surveyed organizations. The author believes that understanding the IT employees’ views gives a better understanding of the organization’s status of information security policy.

Findings

It has been found that most of the surveyed organizations have established information security policy and deployed fair technology; however, many of such policies are not enforced and publicized effectively and efficiently which degraded the deployed technology for such protection. In addition, the clarity and the comprehensibility of such policies are questionable as indicated by most of the IT employees’ responses. A comparison with similar studies at Middle Eastern and European countries has shown similar findings and shares the same concerns.

Originality/value

The findings of this research suggest that the Saudi Communications and Information Technology Commission should develop a national framework for information security to guide the governmental and non-governmental organizations as well as the information security practitioners on the good information security practices in terms of policy and procedures to help the organizations to avoid any vulnerability that may lead to violations on the security of their information.

Keywords

Citation

Alzamil, Z.A. (2018), "Information security practice in Saudi Arabia: case study on Saudi organizations", Information and Computer Security, Vol. 26 No. 5, pp. 568-583. https://doi.org/10.1108/ICS-01-2018-0006

Publisher

:

Emerald Publishing Limited

Copyright © 2018, Emerald Publishing Limited

Related articles