Corvinus
Corvinus

Information security awareness maturity : conceptual and practical aspects in Hungarian organizations

Kő, Andrea ORCID: https://orcid.org/0000-0003-0023-1143, Tarján, Gábor and Mitev Ariel, Zoltán ORCID: https://orcid.org/0000-0002-9986-3513 (2023) Information security awareness maturity : conceptual and practical aspects in Hungarian organizations. Information Technology and People, 36 (8). pp. 174-195. DOI https://doi.org/10.1108/ITP-11-2021-0849

[img] PDF - Requires a PDF viewer such as GSview, Xpdf or Adobe Acrobat Reader
1MB

Official URL: https://doi.org/10.1108/ITP-11-2021-0849


Abstract

Purpose: This paper aims to provide a maturity model for information security awareness (MMISA), based on the literature, expert interviews and feedback. In addition to developing the MMISA, the authors investigate the role of the three decisive factors that affect ISA maturity level: risk management mechanism, organizational structure and ISA. Design/methodology/approach: The research methodology is a combined one; qualitative and quantitative methods were applied, including surveying the literature, interviews and developing a survey to collect quantitative data about decisive factors that affect ISA maturity level. The authors perform a variance-based partial least squares-structural equation modeling (PLS-SEM) investigation of the relationships between these factors. Findings: The investigation of decisive factors of ISA maturity levels revealed that if the authors identify a strong risk assessment mechanism (through a documented methodology and reliable results), the authors can expect a high level of ISA. If there is a well-defined organizational structure with clear responsibilities, this supports the linking of a risk management mechanism with the level of ISA. The connection between organizational structure and ISA maturity level is supported by ISA activities: an increased level of awareness actions strengthens an organizational structure via the best practices learned by the staff. Originality/value: The main contribution of the proposed MMISA model is that the model offers controls and audit evidence for maturity levels. Beyond that, the authors distinguish in the MMISA model controls supporting knowledge and controls supporting attitude, emphasizing that this is not enough to know what to do, but the proper attitude is required too. The authors didn't find any other ISA maturity model which has a similar feature. The contribution of the authors' work is that the authors provide a method for solving this complex measurement problem via the MMISA, which also offers direct guidance for the daily practices of organizations.

Item Type:Article
Uncontrolled Keywords:security, risk, audit, information management, capability maturity model (CMM)
Divisions:Institute of Data Analytics and Information Systems
Institute of Marketing and Communication Sciences
Subjects:Information economy
DOI:https://doi.org/10.1108/ITP-11-2021-0849
ID Code:10462
Deposited By: MTMT SWORD
Deposited On:29 Oct 2024 15:01
Last Modified:29 Oct 2024 15:01

Repository Staff Only: item control page

Downloads

Downloads per month over past year

View more statistics