2019
DOI: 10.24251/hicss.2019.769
|View full text |Cite
|
Sign up to set email alerts
|

For What Technology Can’t Fix: Building a Model of Organizational Cybersecurity Culture

Abstract: Organizational cybersecurity requires more than just the latest technology. To secure an organization, all members of the organization must act to reduce risk. Leaders have a special responsibility to understand, shape and align the beliefs, values, and attitudes of the entire organization with overall security goals. Managers need practical solutions for dealing with the human side of cybersecurity. The model presented in this paper describes organizational cybersecurity culture, the factors that contribute t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
25
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
5
4

Relationship

0
9

Authors

Journals

citations
Cited by 36 publications
(26 citation statements)
references
References 8 publications
1
25
0
Order By: Relevance
“…[5] A consciously developed culture of data protection can increase cyberresiliency. [3] In environments that function on trust and collective responsibility, peer monitoring reduces ISP violation intention. [14]…”
Section: Individualitymentioning
confidence: 99%
See 1 more Smart Citation
“…[5] A consciously developed culture of data protection can increase cyberresiliency. [3] In environments that function on trust and collective responsibility, peer monitoring reduces ISP violation intention. [14]…”
Section: Individualitymentioning
confidence: 99%
“…Building awareness and a culture of trust around information security improve the chances that ISP will be implemented consistently. [3] Costly data breaches could be mitigated, decreased, or avoided altogether.…”
Section: Introductionmentioning
confidence: 99%
“…Sharing this view, we perceive that providing managers with the adequate tool to operate is the way forward. Also, studies on the social impact on information security address the influence of external systems in their culture models [19] demonstrating the need for the multiscale visibility our solution provides. Finally, formalizing human involvement in applying security processes as well as supporting diversity of security approaches through genericity are essential.…”
Section: Related Work and Problematicmentioning
confidence: 99%
“…Finally, a set of policies, procedures, guidelines and standards is of little use if they are not used and implemented by employees. In this respect, the establishment of a cybersecurity culture can make a decisive contribution to increasing cyber resilience and steering employee behavior in the right direction (Huang and Pearlson, 2019).…”
Section: Organizational Aspects Of Cybersecuritymentioning
confidence: 99%