The Experts below are selected from a list of 270 Experts worldwide ranked by ideXlab platform

Anat Hovav - One of the best experts on this subject based on the ideXlab platform.

  • ECIS - EMPLOYEES´ COMPLIANCE WITH BYOD Security POLICY: INSIGHTS FROM REACTANCE, ORGANIZATIONAL JUSTICE, AND PROTECTION MOTIVATION THEORY
    2014
    Co-Authors: Frida Ferdani Putri, Anat Hovav
    Abstract:

    The trend of bring your own device (BYOD) has been rapidly adopted by organizations. Despite the pros and cons of BYOD adoption, this trend is expected to inevitably keep increasing. Yet, BYOD has raised significant concerns about information system Security as employees use their personal devices to access organizational resources. This study aims to examine employees' intention to comply with an organization’s IS Security policy in the context of BYOD. We derived our research model from reactance, protection motivation and organizational justice theories. The results of this study demonstrate that an employee’s perceived response efficacy and perceived justice positively affect an employee’s intention to comply with BYOD Security policy. Perceived Security threat appraisal was found to marginally promote the intention to comply. Conversely, perceived freedom threat due to imposed Security policy negatively affects an employee’s intention to comply with the Security policy. We also found that an employee’s perceived cost associated with compliance behavior positively affects an employee’s perceptions of threat to an individual freedom. An interesting double-edged sword effect of a Security Awareness Program was confirmed by the results. BYOD Security Awareness Program increases an employee’s response efficacy (a positive effect) and response cost (a negative effect). The study also demonstrates the importance of having an IT support team for BYOD, as it increases an employee’s response-efficacy and perceived justice.

  • employees compliance with byod Security policy insights from reactance organizational justice and protection motivation theory
    European Conference on Information Systems, 2014
    Co-Authors: Frida Ferdani Putri, Anat Hovav
    Abstract:

    The trend of bring your own device (BYOD) has been rapidly adopted by organizations. Despite the pros and cons of BYOD adoption, this trend is expected to inevitably keep increasing. Yet, BYOD has raised significant concerns about information system Security as employees use their personal devices to access organizational resources. This study aims to examine employees' intention to comply with an organization’s IS Security policy in the context of BYOD. We derived our research model from reactance, protection motivation and organizational justice theories. The results of this study demonstrate that an employee’s perceived response efficacy and perceived justice positively affect an employee’s intention to comply with BYOD Security policy. Perceived Security threat appraisal was found to marginally promote the intention to comply. Conversely, perceived freedom threat due to imposed Security policy negatively affects an employee’s intention to comply with the Security policy. We also found that an employee’s perceived cost associated with compliance behavior positively affects an employee’s perceptions of threat to an individual freedom. An interesting double-edged sword effect of a Security Awareness Program was confirmed by the results. BYOD Security Awareness Program increases an employee’s response efficacy (a positive effect) and response cost (a negative effect). The study also demonstrates the importance of having an IT support team for BYOD, as it increases an employee’s response-efficacy and perceived justice.

Susan D. Hansche - One of the best experts on this subject based on the ideXlab platform.

  • Information system Security training : Making it happen : Part 2 of 2
    Information Systems Security, 2001
    Co-Authors: Susan D. Hansche
    Abstract:

    This article is the second of a two-part series on the importance of providing both Security Awareness and information systems Security training to all employees, regardless of their job responsibilities. Part 1, (ISS, January/February 2001) discussed the process of designing and developing a Security Awareness Program. The Security Awareness Program should be the first step in the information system Security Awareness and training Program. In conjunction with the Awareness Program, the information Security professional should design a training Program. When designing and developing an information technology (IT) Security training Program, there is a wide range of options that are based on specific job requirements and the daily management, operation, and protection of the information system. This article describes a framework to help develop an information system Security training Program that will match your organization's needs.

  • Designing a Security Awareness Program: Part 1
    Information Systems Security, 2001
    Co-Authors: Susan D. Hansche
    Abstract:

    Abstract This article represents the first of a two-part series on the importance of providing both Security Awareness and information systems Security training to all employees, regardless of their job responsibilities. In this first article, the focus is on the first step of providing computer and information system Security—developing and implementing an effective Security Awareness Program. Readers may ask why Security Awareness is not considered the same as training. The simple answer is because the desired outcome of each is different.

Hennie A. Kruger - One of the best experts on this subject based on the ideXlab platform.

  • SAISMC - The Use of an Information Security Vocabulary Test to Assess Information Security Awareness - An Exploratory Study
    2010
    Co-Authors: Hennie A. Kruger, Lynette Drevin, Tjaart Steyn
    Abstract:

    The dependence on human involvement and human behavior to protect information assets makes it necessary to have an information Security Awareness Program to make people aware of their roles and responsibilities towards information Security. The aim of this paper is to examine the feasibility of an information Security vocabulary test as an aid to assess Awareness levels and to help with the identification of suitable areas or topics to be included in an information Security Awareness Program. The use of such a vocabulary test is illustrated and results obtained suggest that information Security Awareness vocabulary tests are useful and should be considered when planning and developing an information Security Awareness Program.

  • Consensus ranking - An ICT Security Awareness case study
    Computers & Security, 2008
    Co-Authors: Hennie A. Kruger, Wayne D. Kearney
    Abstract:

    There are many disciplines where the problem of consensus ranking plays a vital role. Decision-makers are frequently asked to express their preferences for a group of objects, e.g. new projects, new products, candidates in an election, etc. The basic problem then becomes one of combining the individual rankings into a group choice or consensus ranking. The objective of this paper is to report on the application of two management science methodologies to the problem of identifying the most important areas to be included in an Information Communications Technology (ICT) Security Awareness Program. The first methodology is based on the concept of minimizing the distance (disagreement) between individual rankings, while the second one employs a heuristic approach. A real-world case study from the mining industry is presented to illustrate the methods.

  • An Empirical Assessment of Factors Impeding Effective Password Management
    Journal of Information Privacy and Security, 2008
    Co-Authors: Hennie A. Kruger, Lynette Drevin, Tjaart Steyn, B. Dawn Medlin
    Abstract:

    AbstractSince passwords are one of the main mechanisms used to protect data and information, it is important to ensure that passwords are managed correctly and that those factors which will have a significant impact on password management are identified and prioritized. Therefore, in order for an information and communication technology (ICT) overall Security Program to be successful, a Security Awareness Program or component must be included. The aim of this paper is to perform an exploratory study with the objective of introducing certain fundamental causes that may impact password management. Empirical results, followed by a survey as well as the application of several management science techniques are presented.

  • ISSA - A Framework for Evaluating ICT Security Awareness.
    2006
    Co-Authors: Hennie A. Kruger, Lynette Drevin, Tjaart Steyn
    Abstract:

    ICT resources are important assets of any organization and the protection of these resources are equally important. To be able to protect themselves and their profitability, many organizations have established information Security Awareness Programs. In order for a Security Awareness Program to add value to an organization and at the same time make a contribution to the field of information Security it is necessary to have a set of methods to study and measure its effect. This paper gives an overview of a suggested framework for evaluating ICT Security Awareness. Following a brief description of the framework, a more detailed overview on the identification of areas to be evaluated, using a value focused assessment, will be presented. Comments on possible system generated information, that may be used to assist with the evaluation of Security behavior of users, will also be presented.

  • ISSA - Measuring Information Security Awareness - A West Africa Gold Mining Environment Case.
    2005
    Co-Authors: Hennie A. Kruger, Wayne D. Kearney
    Abstract:

    AngloGold Ashanti is an international gold mining company that has recently implemented an information Security Awareness Program worldwide at all of their operations. Following the implementation, there was a normal business need to evaluate and measure the success and effectiveness of the Program. A measuring tool that can be applied globally and that addressed AngloGold Ashanti’s unique requirements was developed and applied at the mining sites located in the West Africa region. The objective of this paper is, firstly, to give a brief overview on the measuring tool developed and, secondly to report on the application and results in the West Africa region.

Frida Ferdani Putri - One of the best experts on this subject based on the ideXlab platform.

  • ECIS - EMPLOYEES´ COMPLIANCE WITH BYOD Security POLICY: INSIGHTS FROM REACTANCE, ORGANIZATIONAL JUSTICE, AND PROTECTION MOTIVATION THEORY
    2014
    Co-Authors: Frida Ferdani Putri, Anat Hovav
    Abstract:

    The trend of bring your own device (BYOD) has been rapidly adopted by organizations. Despite the pros and cons of BYOD adoption, this trend is expected to inevitably keep increasing. Yet, BYOD has raised significant concerns about information system Security as employees use their personal devices to access organizational resources. This study aims to examine employees' intention to comply with an organization’s IS Security policy in the context of BYOD. We derived our research model from reactance, protection motivation and organizational justice theories. The results of this study demonstrate that an employee’s perceived response efficacy and perceived justice positively affect an employee’s intention to comply with BYOD Security policy. Perceived Security threat appraisal was found to marginally promote the intention to comply. Conversely, perceived freedom threat due to imposed Security policy negatively affects an employee’s intention to comply with the Security policy. We also found that an employee’s perceived cost associated with compliance behavior positively affects an employee’s perceptions of threat to an individual freedom. An interesting double-edged sword effect of a Security Awareness Program was confirmed by the results. BYOD Security Awareness Program increases an employee’s response efficacy (a positive effect) and response cost (a negative effect). The study also demonstrates the importance of having an IT support team for BYOD, as it increases an employee’s response-efficacy and perceived justice.

  • employees compliance with byod Security policy insights from reactance organizational justice and protection motivation theory
    European Conference on Information Systems, 2014
    Co-Authors: Frida Ferdani Putri, Anat Hovav
    Abstract:

    The trend of bring your own device (BYOD) has been rapidly adopted by organizations. Despite the pros and cons of BYOD adoption, this trend is expected to inevitably keep increasing. Yet, BYOD has raised significant concerns about information system Security as employees use their personal devices to access organizational resources. This study aims to examine employees' intention to comply with an organization’s IS Security policy in the context of BYOD. We derived our research model from reactance, protection motivation and organizational justice theories. The results of this study demonstrate that an employee’s perceived response efficacy and perceived justice positively affect an employee’s intention to comply with BYOD Security policy. Perceived Security threat appraisal was found to marginally promote the intention to comply. Conversely, perceived freedom threat due to imposed Security policy negatively affects an employee’s intention to comply with the Security policy. We also found that an employee’s perceived cost associated with compliance behavior positively affects an employee’s perceptions of threat to an individual freedom. An interesting double-edged sword effect of a Security Awareness Program was confirmed by the results. BYOD Security Awareness Program increases an employee’s response efficacy (a positive effect) and response cost (a negative effect). The study also demonstrates the importance of having an IT support team for BYOD, as it increases an employee’s response-efficacy and perceived justice.

Tjaart Steyn - One of the best experts on this subject based on the ideXlab platform.

  • A vocabulary test to assess information Security Awareness
    Information Management & Computer Security, 2010
    Co-Authors: Hennie Kruger, Lynette Drevin, Tjaart Steyn
    Abstract:

    Purpose – The dependence on human involvement and human behavior to protect information assets necessitates an information Security Awareness Program to make people aware of their roles and responsibilities towards information Security. The purpose of this paper is to examine the feasibility of an information Security vocabulary test as an aid to assess Awareness levels and to assist with the identification of suitable areas or topics to be included in an information Security Awareness Program. Design/methodology/approach – A questionnaire has been designed to test and illustrate the feasibility of a vocabulary test. The questionnaire consists of two sections – a first section to perform a vocabulary test and a second one to evaluate respondents’ behavior. Two different class groups of students at a university were used as a sample. Findings – The research findings confirmed that the use of a vocabulary test to assess Security Awareness levels will be beneficial. A significant relationship between knowledge of concepts (vocabulary) and behavior was observed. Originality/value – The paper introduces a new approach to evaluate people’s information Security Awareness levels by employing an information Security vocabulary test. This new approach can assist management to plan and evaluate interventions and to facilitate best practice in information Security. Aspects of cognitive psychology and language were taken into account in this research project, indicating the interaction and influence between apparently different disciplines.

  • SAISMC - The Use of an Information Security Vocabulary Test to Assess Information Security Awareness - An Exploratory Study
    2010
    Co-Authors: Hennie A. Kruger, Lynette Drevin, Tjaart Steyn
    Abstract:

    The dependence on human involvement and human behavior to protect information assets makes it necessary to have an information Security Awareness Program to make people aware of their roles and responsibilities towards information Security. The aim of this paper is to examine the feasibility of an information Security vocabulary test as an aid to assess Awareness levels and to help with the identification of suitable areas or topics to be included in an information Security Awareness Program. The use of such a vocabulary test is illustrated and results obtained suggest that information Security Awareness vocabulary tests are useful and should be considered when planning and developing an information Security Awareness Program.

  • An Empirical Assessment of Factors Impeding Effective Password Management
    Journal of Information Privacy and Security, 2008
    Co-Authors: Hennie A. Kruger, Lynette Drevin, Tjaart Steyn, B. Dawn Medlin
    Abstract:

    AbstractSince passwords are one of the main mechanisms used to protect data and information, it is important to ensure that passwords are managed correctly and that those factors which will have a significant impact on password management are identified and prioritized. Therefore, in order for an information and communication technology (ICT) overall Security Program to be successful, a Security Awareness Program or component must be included. The aim of this paper is to perform an exploratory study with the objective of introducing certain fundamental causes that may impact password management. Empirical results, followed by a survey as well as the application of several management science techniques are presented.

  • ISSA - A Framework for Evaluating ICT Security Awareness.
    2006
    Co-Authors: Hennie A. Kruger, Lynette Drevin, Tjaart Steyn
    Abstract:

    ICT resources are important assets of any organization and the protection of these resources are equally important. To be able to protect themselves and their profitability, many organizations have established information Security Awareness Programs. In order for a Security Awareness Program to add value to an organization and at the same time make a contribution to the field of information Security it is necessary to have a set of methods to study and measure its effect. This paper gives an overview of a suggested framework for evaluating ICT Security Awareness. Following a brief description of the framework, a more detailed overview on the identification of areas to be evaluated, using a value focused assessment, will be presented. Comments on possible system generated information, that may be used to assist with the evaluation of Security behavior of users, will also be presented.