Kő, Andrea ORCID: https://orcid.org/0000-0003-0023-1143, Tarján, Gábor and Mitev Ariel, Zoltán ORCID: https://orcid.org/0000-0002-9986-3513 (2023) Information security awareness maturity : conceptual and practical aspects in Hungarian organizations. Information Technology and People, 36 (8). pp. 174-195. DOI https://doi.org/10.1108/ITP-11-2021-0849
PDF
- Requires a PDF viewer such as GSview, Xpdf or Adobe Acrobat Reader
1MB |
Official URL: https://doi.org/10.1108/ITP-11-2021-0849
Abstract
Purpose: This paper aims to provide a maturity model for information security awareness (MMISA), based on the literature, expert interviews and feedback. In addition to developing the MMISA, the authors investigate the role of the three decisive factors that affect ISA maturity level: risk management mechanism, organizational structure and ISA. Design/methodology/approach: The research methodology is a combined one; qualitative and quantitative methods were applied, including surveying the literature, interviews and developing a survey to collect quantitative data about decisive factors that affect ISA maturity level. The authors perform a variance-based partial least squares-structural equation modeling (PLS-SEM) investigation of the relationships between these factors. Findings: The investigation of decisive factors of ISA maturity levels revealed that if the authors identify a strong risk assessment mechanism (through a documented methodology and reliable results), the authors can expect a high level of ISA. If there is a well-defined organizational structure with clear responsibilities, this supports the linking of a risk management mechanism with the level of ISA. The connection between organizational structure and ISA maturity level is supported by ISA activities: an increased level of awareness actions strengthens an organizational structure via the best practices learned by the staff. Originality/value: The main contribution of the proposed MMISA model is that the model offers controls and audit evidence for maturity levels. Beyond that, the authors distinguish in the MMISA model controls supporting knowledge and controls supporting attitude, emphasizing that this is not enough to know what to do, but the proper attitude is required too. The authors didn't find any other ISA maturity model which has a similar feature. The contribution of the authors' work is that the authors provide a method for solving this complex measurement problem via the MMISA, which also offers direct guidance for the daily practices of organizations.
Item Type: | Article |
---|---|
Uncontrolled Keywords: | security, risk, audit, information management, capability maturity model (CMM) |
Divisions: | Institute of Data Analytics and Information Systems Institute of Marketing and Communication Sciences |
Subjects: | Information economy |
DOI: | https://doi.org/10.1108/ITP-11-2021-0849 |
ID Code: | 10462 |
Deposited By: | MTMT SWORD |
Deposited On: | 29 Oct 2024 15:01 |
Last Modified: | 29 Oct 2024 15:01 |
Repository Staff Only: item control page