Analyzing Information Security Culture: Increased Trust by an Appropriate Information Security Culture

  • Authors:
  • Thomas Schlienger;Stephanie Teufel

  • Affiliations:
  • -;-

  • Venue:
  • DEXA '03 Proceedings of the 14th International Workshop on Database and Expert Systems Applications
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security culture encompasses all socio-cultural measuresthat support technical security measures, so thatinformation security becomes a natural aspect in the dailyactivities of every employee. The cultural concept helps toincrease trust between the different actors concerninginformation security within an organization. We start withthe explanation of the "organizational culture concept",asking how it can be used to implement information securityculture. To create, maintain and change security culture,certain measuring instruments are necessary. Wediscuss several ways and methods to analyze organizationalculture. Furthermore we ask, to what extent theycould be used in the context of security culture and whatspecial problems might arise. Finally, the possible implementationis discussed in the context of an ongoingsurvey from which we present some results.