In a 'trusting' environment, everyone is responsible for information security

  • Authors:
  • Patricia A. H. Williams

  • Affiliations:
  • School of Computer and Information Science, Edith Cowan University, 2 Bradford Street, Mt Lawley, Western Australia 6050, Australia

  • Venue:
  • Information Security Tech. Report
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Information security is important in any organisation and particularly where personal and medical information is routinely recorded. Further, where the organisational culture revolves around trust, as in the medical environment, insider threats, both malicious and non-malicious, are difficult to manage. International research has shown that changing security culture and increasing awareness is necessary as technical resolutions are not sufficient to control insider threats. This area of information security is both important and topical in view of the recently publicised breaches of patient health information. Ensuring that all staff assumes responsibility for information security, particularly as part of an information security governance framework, is one practical solution to the problem of insider threats.