Design science research is typically used to conduct research in the information systems space. Design science research has also existed for many years, and might be seen as a daunting task when first undertaken by inexperienced researchers. This is most likely due to the various approaches and terminologies that exist for conducting design science research. Therefore, this paper proposes a tailor-made approach for inexperienced researchers to conduct design science research. Accordingly, this approach aims to specifically assist researchers to develop an artefact as a research contribution in an environment where the artefact is developed and evaluated concurrently in close collaboration with stakeholders.
Relevance of the research. Ensuring the effectiveness of the information security systems requires creation of an appropriate information security culture for the employees of the organization in order to reduce human-related risks. Target setting. The techniques currently available for assessing information security risk are excluded as a source of the potential vulnerability. Considering the role of the personnel in the organization's information security systems, there is a need to create automated systems of human-machine interaction assessment through the level of the personnel information security culture, and to determine the integral indicator of the organization's information security culture. Actual scientific researches and issues analysis. Open access publications on the problems of integrating the information security culture into the corporate culture of the organization as a tool for ensuring the proper information security level of business processes are considered. Uninvestigated parts of general matters defining. The absence of formalized models for assessing the organization's information security culture level, as well as an automated process for its assessing were revealed by source analysis. The research objective. The purpose of the article to build a model that describes the process of obtaining an organization's information security culture level assessment in IDEF0 notation. Then, to create an architecture and database for system of information security culture assessment to support the general organization's information security system. The statement of basic materials. According to functional requirements, a conceptual model of «The organization`s ISC level determination» development process was created. Input information, governing elements, execution elements and mechanism, and output information were defined. To accomplish these tasks, an architecture and database of information system for assessing the information security culture level of the organization were proposed. Conclusions. The functional model of top-level development process was proposed. Formed functional requirements became the basis for development of information system architecture with description of its modules and database structure.
Information technology has brought with it many advantages for organisations, but information security is still a major concern for organisations which rely on such technology. Users, whether with intent or through negligence, are a great source of potential of risk to information assets. A lack of awareness, negligence, resistance, disobedience, apathy and mischievousness are root causes of information security incidents in organisations. As such, insider threats have attracted the attention of a number of experts in this domain. Two particularly important considerations when exploring insider threats are motivation and opportunity. Two fundamental theories relating to these phenomena, and on which the research presented in this paper relies, are Social Bond Theory (SBT), which can be used to help undermine motivation to engage in misbehaviour, and Situational Crime Prevention Theory (SCPT), which can be used to reduce opportunities for misbehaviour. The results of our data analysis show that situational prevention factors such as increasing the effort and risk involved in a crime, reducing the rewards and removing excuses can significantly promotes the adoption of negative attitudes towards misbehaviour, though reducing provocations does not have any effect on attitudes. Further, social bond factors such as a commitment to organisational policies and procedures, involvement in information security activities and personal norms also significantly promotes the adoption of negative attitudes towards misbehaviour. However, attachment does not significantly promote an attitude of misbehaviour avoidance on the part of employees. Finally, our findings also show that a negative attitude towards misbehaviour influences the employees’ intentions towards engaging in misbehaviour positively, and this in turn reduces insider threat behaviour. The outputs of this study shed some light on factors which play a role in reducing misbehaviour in the domain of information security for academics and practitioners.
The Internet and information technology have influenced human life significantly. However, information security is still an important concern for both users and organizations. Technology cannot solely guarantee a secure environment for information; the human aspects of information security should be taken into consideration, besides the technological aspects. The lack of information security awareness, ignorance, negligence, apathy, mischief, and resistance are the root of users' mistakes. In this research, a novel model shows how complying with organizational information security policies shapes and mitigates the risk of employees' behaviour. The significant aspect of this research is derived from the conceptualization of different aspects of involvement, such as information security knowledge sharing, collaboration, intervention and experience, as well as attachment, commitment, and personal norms that are important elements in the Social Bond Theory. The results of the data analysis revealed that information security knowledge sharing, collaboration, intervention and experience all have a significant effect on employees' attitude towards compliance with organizational information security policies. However, attachment does not have a significant effect on employees' attitude towards information security policy compliance. In addition, the findings have shown that commitment and personal norms affect employees' attitude. Attitude towards compliance with information security organizational policies also has a significant effect on the behavioural intention regarding information security compliance.
Today, the Internet can be considered to be a basic commodity, similar to electricity, without which many businesses simply cannot operate. However, information security for both private and business aspects is important. Experts believe that technology cannot solely guarantee a secure environment for information. Users' behaviour should be considered as an important factor in this domain. The Internet is a huge network with great potential for information security breaches. Hackers use different methods to change confidentiality, integrity, and the availability of information in line with their benefits, while users intentionally or through negligence are a great threat for information security. Sharing their account information, downloading any software from the Internet, writing passwords on sticky paper, and using social security numbers as a username or password are examples of their mistakes. Users' negligence, ignorance, lack of awareness, mischievous, apathy and resistance are usually the reasons for security breaches. Users' poor information security behaviour is the main problem in this domain and the presented model endeavours to reduce the risk of users' behaviour in this realm. The results of structural equation modelling (SEM) showed that Information Security Awareness, Information Security Organization Policy, Information Security Experience and Involvement, Attitude towards information security, Subjective Norms, Threat Appraisal, and Information Security Self-efficacy have a positive effect on users' behaviour. However, Perceived Behavioural Control does not affect their behaviour significantly. The Protection Motivation Theory and Theory of Planned Behaviour were applied as the backbone of the research model.
This paper has critically assessed a Higher Education Institution's (HEI) Examination Paper Preparation Process (EPPP) to identify threats and vulnerabilities that could place the security of the process at a risk; thus, compromising the security of the examination papers. Surveys were utilized to identify examiners' behaviour which could pose a risk to the security of the examination papers. The paper further highlights the vital role the human factor plays in ensuring that the EPPP is secure. The paper proposes an Information Security Assurance Model (ISAM) that is based on information security principles and best practices to manage and improve the security of the EPPP. The model provides a step-by-step guide which could be followed to ensure that relevant information security aspects are covered to ensure that examination papers are handled more securely. The aim of the model is to ensure that examination papers are not accessible to unauthorized individuals; which, may lead to some students being conferred with qualifications that they do not deserve.
Public higher education in South Africa is governed by the Higher Education Act (Act No. 101 of 1997). Governance of public higher education in South Africa is just one element of governance practised across the entire domain of government to ensure accountability to the citizens of the country. This paper refers to four different, but related, levels of governance that span the landscape of public higher education: firstly, within the global context, secondly, in the context of the country with all of its government ministries; thirdly, the "system" of education in the context of legislative governance within the public higher education sector in South Africa; and finally, the institutional governance arrangements required in terms of legislation or regulation, which will be reviewed with particular attention being given to IT governance. Further, the notion of "managerialism" will be discussed to provide some structure to the context in which governance is practised. IT governance, as a subset of institutional governance, within and across the public higher education system is subsequently addressed. Finally, the current absence of IT governance oversight or reporting to the public higher education authority and mechanisms to improve governance in the sector are discussed, which provide an indication of the value that can be created by the implementation of a best practice IT governance framework at institutional level. Accordingly, an IT governance framework can be used to measure the maturity of a wide range of IT processes that The layered approach to governance investigated in this paper provides insight into the factors that influence the ability to govern subsystems, particularly the IT subsystem, in the public higher education sector in South Africa.
Phishing continues to remain a lucrative market for cyber criminals, mostly because of the vulnerable human element. Through emails and spoofed-websites, phishers exploit almost any opportunity using major events, considerable financial awards, fake warnings and the trusted reputation of established organizations, as a basis to gain their victims' trust. For many years, humans have often been referred to as the `weakest link' towards protecting information. To gain their victims' trust, phishers continue to use sophisticated looking emails and spoofed websites to trick them, and rely on their victims' lack of knowledge, lax security behavior and organizations' inadequate security measures towards protecting itself and their clients. As such, phishing security controls and vulnerabilities can arguably be classified into three main elements namely human factors (H), organizational aspects (O) and technological controls (T). All three of these elements have the common feature of human involvement and as such, security gaps are inevitable. Each element also functions as both security control and security vulnerability. A holistic framework towards combatting phishing is required whereby the human feature in all three of these elements is enhanced by means of a security education, training and awareness programme. This paper discusses the educational factors required to form part of a holistic framework, addressing the HOT elements as well as the relationships between these elements towards combatting phishing. The development of this framework uses the principles of design science to ensure that it is developed with rigor. Furthermore, this paper reports on the verification of the framework.
This paper conceptually explores the existing IT governance literature and reveals that the concept remains an evolving and `murky' phenomenon. Specifically, it highlights that as IT governance continues to evolve, it emerges in ever-new forms with increasing complexity and confusion. This is especially true, when studying the various differing definitions and terms applied within current literature and the nature and breadth of discussion. Even more so, when taking into account the whirlpool of standards and best practices currently operating within this domain. All of this leads to a lack of clarity, having the potential to confuse and possibly impede useful development and research in the field. Using content analysis, argumentation and modelling, this paper sets out to review and model a possible reform to the IT governance landscape. Hereby, it aims to offer much-needed clarity, provide a frame of reference and guide future research in the field.
This research focused on what constitutes information integrity as this is a problem facing companies today. Moreover, information integrity is a pillar of information security and is required in order to have a sound security management programme. However, it is acknowledged that 100% information integrity is not currently achievable due to various limitations and therefore the auditing concept of reasonable assurance is adopted. This is in line with the concept that 100% information security is not achievable and the notion that adequate security is the goal, using appropriate countermeasures. The main contribution of this article is to illustrate the importance of and provide a macro view of what constitutes information integrity. The findings are in harmony with Samuel Johnson's words (1751): 'Integrity without knowledge is weak and useless, and knowledge without integrity is dangerous and dreadful.'
A study has compared the methodologies behind financial integrity and network information integrity. Researchers from South African Universities showed shortcomings in information integrity and made recommendations to address them. The authors believe that some of the “extreme measures” used to ensure the integrity of financial matters should be applied to information security. According to the research, only 1/9 of processes to achieve integrity assurance are fully implemented. Three quarters are implemented in an ad-hoc manner or normally implemented, while 1/9 are never put in place. It was found that security reports are “never” distributed to business units and CEOs don't sign-off reports. The study also discovered that transactions were recorded and stored in an ad-hoc manner. In response to the identified shortcomings, authors recommend all network activities should be captured and stored, while CEOs should sign-off high-level IT security reports. This paper draws an analogy between the models that provide financial integrity and network information integrity. A comparative study between the financial integrity assurance model and the information integrity assurance model was conducted to identify possible information integrity assurance shortcomings or ‘missing links’. Recommendations are made towards improving the generic information integrity assurance scenario to address the identified shortcomings.
This paper addresses the concept of integrated risk management by making use of an analogy of the mortal human body. Firstly, this paper argues that, for a human to enjoy a quality life, a body that is functioning effectively is required. To accomplish this, the risks that a human body faces must be managed properly. Next, the similarities between a human body and an enterprise are highlighted, whereafter it is reasoned that an enterprise needs to adopt similar risk management practices to be effective. Ultimately, this paper reinforces the importance of the adoption of integrated risk management practices throughout the enterprise.
It is generally accepted that Information Security Governance is an integral part of Corporate Governance. It is therefore essential for any company to have a proper Information Security Governance program which reflects this integration with Corporate Governance. One of the core principles of Governance, and specifically Corporate Governance, is the Direct–Control Cycle which, in its simplest form, ‘prescribes’ and ‘checks’. This paper presents an Information Security Governance model based on this cycle.
Information is a fundamental asset within any organisation and the protection of this asset, through a process of information security, is of equal importance. This paper examines the relationships that exist between the fields of corporate governance, information security and corporate culture. It highlights the role that senior management should play in cultivating an information security conscious culture in their organisation, for the benefit of the organisation, senior management and the users of information.
This paper identifies 10 essential aspects, which, if not taken into account in an information security governance plan, will surely cause the plan to fail, or at least, cause serious flaws in the plan. These 10 aspects can be used as a checklist by management to ensure that a comprehensive plan has been defined and introduced.
Today's global economy is increasingly dependent on the creation, management, and distribution of information resources. Information and its use permeate all aspects of modem society. Most modem organizations need information systems to survive and prosper. Information has become a valuable commodity and as such needs to be protected. This protection is typically implemented in the form of various security controls. In order for these controls to be effective, the users in the organization need to be educated regarding these controls. Recent studies have indicated that current user education programs fail to pay adequate attention to behavioral theories. This paper examines the educational principles an information security user education program should adhere to. It then introduces outcomes based education (OBE) and finally argues that OBE is ideally suited for the needs of information security.
In traditional IDS environments, little activity has been applied to using visual analysis as an aid to intrusion detection. With more information systems being attacked and attack techniques evolving, the task of detecting intrusions is becoming an increasingly difficult job. This paper proposes an approach whereby traditional visualization techniques using a glyph metaphor can be applied to intrusion detection system analysis. This provides for a real-time monitoring environment to allow for effective and timeous analysis.
Due to the overwhelming complexity in establishing and maintaining a secure organizational framework, it is essential that various Information Security Management elements be tightly integrated to form a well planned methodology. However, organizations often do not have the necessary expertise or resources to follow such a detailed methodology. This paper introduces a software tool that can automate the phases comprising the Information Security Management Methodology.
To protect the information systems of an organisation an appropriate set of security controls needs to be installed and managed properly. Through a risk analysis exercise, the most effective set of controls is recommended. This analysis or identification process can be subjective and many assumptions are made about the environment. A possible solution may be the definition of suitable protection profiles that will include the best suitable security controls for specific information technology environments. This paper will provide some guidelines in the formation of a fully defined security control. Sets of these controls can be used in the determination of an information security profile that will encompass all aspects of security such that no assumptions need to be made, thereby leading towards a totally secure organization.
Steven Furnell合作论文数Communications & Electronics;School of Computing2