Information security policy compliance model for public sector

Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the w...

पूर्ण विवरण

ग्रंथसूची विवरण
मुख्य लेखक: Abd. Rahim, Fuad Harriz
स्वरूप: थीसिस
भाषा:अंग्रेज़ी
प्रकाशित: 2017
विषय:
ऑनलाइन पहुंच:http://eprints.utm.my/91983/1/FuadHarrizAbdMRAZAK2017.pdf
_version_ 1846218445626015744
author Abd. Rahim, Fuad Harriz
author_facet Abd. Rahim, Fuad Harriz
author_sort Abd. Rahim, Fuad Harriz
description Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the weakest link in information security thus factor that affect their intention towards compliance behaviour should be identified. The purpose of this research is to identify factors from recent researches that uses the most common compliance model used in social psychology and technological domain. These factors would then be built up into a proposed model where it will be validated with the survey questionnaire result from an IT department that consists of administrative and IT professionals. This research uses quantitative approach as it is the most used research design used in this domain and statistics software will be used to determine the frequencies, reliability, and the correlation of the factors towards compliance intention. According to 214 respondents, eleven factors have been concluded to have significant impact towards compliance intention that is perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy, attitude, subjective norm, perceived usefulness, perceived ease of use, awareness and punishment while rewards have insignificant relation. The result from this research would support the proposed model that will act as a guidance in public sector to solve issues regarding employee behaviour that impacts information security policy compliance.
format Thesis
id uthm-91983
institution Universiti Teknologi Malaysia
language English
publishDate 2017
record_format eprints
spelling uthm-919832021-08-30T05:11:06Z http://eprints.utm.my/91983/ Information security policy compliance model for public sector Abd. Rahim, Fuad Harriz QA75 Electronic computers. Computer science T58.5-58.64 Information technology Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the weakest link in information security thus factor that affect their intention towards compliance behaviour should be identified. The purpose of this research is to identify factors from recent researches that uses the most common compliance model used in social psychology and technological domain. These factors would then be built up into a proposed model where it will be validated with the survey questionnaire result from an IT department that consists of administrative and IT professionals. This research uses quantitative approach as it is the most used research design used in this domain and statistics software will be used to determine the frequencies, reliability, and the correlation of the factors towards compliance intention. According to 214 respondents, eleven factors have been concluded to have significant impact towards compliance intention that is perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy, attitude, subjective norm, perceived usefulness, perceived ease of use, awareness and punishment while rewards have insignificant relation. The result from this research would support the proposed model that will act as a guidance in public sector to solve issues regarding employee behaviour that impacts information security policy compliance. 2017 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/91983/1/FuadHarrizAbdMRAZAK2017.pdf Abd. Rahim, Fuad Harriz (2017) Information security policy compliance model for public sector. Masters thesis, Universiti Teknologi Malaysia, Razak Faculty of Technology and Informatics. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:134275
spellingShingle QA75 Electronic computers. Computer science
T58.5-58.64 Information technology
Abd. Rahim, Fuad Harriz
Information security policy compliance model for public sector
title Information security policy compliance model for public sector
title_full Information security policy compliance model for public sector
title_fullStr Information security policy compliance model for public sector
title_full_unstemmed Information security policy compliance model for public sector
title_short Information security policy compliance model for public sector
title_sort information security policy compliance model for public sector
topic QA75 Electronic computers. Computer science
T58.5-58.64 Information technology
url http://eprints.utm.my/91983/1/FuadHarrizAbdMRAZAK2017.pdf
url-record http://eprints.utm.my/91983/
http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:134275
work_keys_str_mv AT abdrahimfuadharriz informationsecuritypolicycompliancemodelforpublicsector