Information security policy compliance model for public sector
Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the w...
| मुख्य लेखक: | |
|---|---|
| स्वरूप: | थीसिस |
| भाषा: | अंग्रेज़ी |
| प्रकाशित: |
2017
|
| विषय: | |
| ऑनलाइन पहुंच: | http://eprints.utm.my/91983/1/FuadHarrizAbdMRAZAK2017.pdf |
| _version_ | 1846218445626015744 |
|---|---|
| author | Abd. Rahim, Fuad Harriz |
| author_facet | Abd. Rahim, Fuad Harriz |
| author_sort | Abd. Rahim, Fuad Harriz |
| description | Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the weakest link in information security thus factor that affect their intention towards compliance behaviour should be identified. The purpose of this research is to identify factors from recent researches that uses the most common compliance model used in social psychology and technological domain. These factors would then be built up into a proposed model where it will be validated with the survey questionnaire result from an IT department that consists of administrative and IT professionals. This research uses quantitative approach as it is the most used research design used in this domain and statistics software will be used to determine the frequencies, reliability, and the correlation of the factors towards compliance intention. According to 214 respondents, eleven factors have been concluded to have significant impact towards compliance intention that is perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy, attitude, subjective norm, perceived usefulness, perceived ease of use, awareness and punishment while rewards have insignificant relation. The result from this research would support the proposed model that will act as a guidance in public sector to solve issues regarding employee behaviour that impacts information security policy compliance. |
| format | Thesis |
| id | uthm-91983 |
| institution | Universiti Teknologi Malaysia |
| language | English |
| publishDate | 2017 |
| record_format | eprints |
| spelling | uthm-919832021-08-30T05:11:06Z http://eprints.utm.my/91983/ Information security policy compliance model for public sector Abd. Rahim, Fuad Harriz QA75 Electronic computers. Computer science T58.5-58.64 Information technology Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the weakest link in information security thus factor that affect their intention towards compliance behaviour should be identified. The purpose of this research is to identify factors from recent researches that uses the most common compliance model used in social psychology and technological domain. These factors would then be built up into a proposed model where it will be validated with the survey questionnaire result from an IT department that consists of administrative and IT professionals. This research uses quantitative approach as it is the most used research design used in this domain and statistics software will be used to determine the frequencies, reliability, and the correlation of the factors towards compliance intention. According to 214 respondents, eleven factors have been concluded to have significant impact towards compliance intention that is perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy, attitude, subjective norm, perceived usefulness, perceived ease of use, awareness and punishment while rewards have insignificant relation. The result from this research would support the proposed model that will act as a guidance in public sector to solve issues regarding employee behaviour that impacts information security policy compliance. 2017 Thesis NonPeerReviewed application/pdf en http://eprints.utm.my/91983/1/FuadHarrizAbdMRAZAK2017.pdf Abd. Rahim, Fuad Harriz (2017) Information security policy compliance model for public sector. Masters thesis, Universiti Teknologi Malaysia, Razak Faculty of Technology and Informatics. http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:134275 |
| spellingShingle | QA75 Electronic computers. Computer science T58.5-58.64 Information technology Abd. Rahim, Fuad Harriz Information security policy compliance model for public sector |
| title | Information security policy compliance model for public sector |
| title_full | Information security policy compliance model for public sector |
| title_fullStr | Information security policy compliance model for public sector |
| title_full_unstemmed | Information security policy compliance model for public sector |
| title_short | Information security policy compliance model for public sector |
| title_sort | information security policy compliance model for public sector |
| topic | QA75 Electronic computers. Computer science T58.5-58.64 Information technology |
| url | http://eprints.utm.my/91983/1/FuadHarrizAbdMRAZAK2017.pdf |
| url-record | http://eprints.utm.my/91983/ http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:134275 |
| work_keys_str_mv | AT abdrahimfuadharriz informationsecuritypolicycompliancemodelforpublicsector |