“…Evidence to date has shown that the majority of failures in information security, especially in the healthcare sector (Masrom and Rahimly, 2015), arise as a result of human and organisational factors (Chang and Ho, 2006). A range of issues, including poor management (Wood, 1995), ignorance on behalf of top and middle management (Straub and Welke, 1998), employees' misuse of information systems (Siponen, 2000), a failure to comply with information security policy (Stanton et al, 2005), and the lack of an organisational information security strategy (Bakari et al, 2007) have each been shown to directly or indirectly precipitate information security failures. In response, information security management (ISM) offers procedures and standards to protect information systems from unauthorised access and protect information from disclosure, disruption, modification, or destruction (Cazemier et al, 2000).…”