Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q)

نویسندگان

  • Kathryn Parsons
  • Agata McCormac
  • Marcus A. Butavicius
  • Malcolm Robert Pattinson
  • Cate Jerram
چکیده

It is increasingly acknowledged that many threats to an organisation’s computer systems can be attributed to the behaviour of computer users. To quantify these human-based information security vulnerabilities, we are developing the Human Aspects of Information Security Questionnaire (HAIS-Q). The aim of this paper was twofold. The first aim was to outline the conceptual development of the HAIS-Q, including validity and reliability testing. The second aim was to examine the relationship between knowledge of policy and procedures, attitude towards policy and procedures and behaviour when using a work computer. Results from 500 Australian employees indicate that knowledge of policy and procedures had a stronger influence on attitude towards policy and procedure than selfreported behaviour. This finding suggests that training and education will be more effective if it outlines not only what is expected (knowledge) but also provides an understanding of why this is important (attitude). Plans for future research to further develop and test the HAIS-Q are outlined. Crown Copyright a 2014 Published by Elsevier Ltd. All rights reserved.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Test-retest reliability and internal consistency of the Human Aspects of Information Security Questionnaire (HAIS-Q)

This paper reports on an evaluation of the test-retest reliability and internal consistency of the Human Aspects of Information Security Questionnaire (HAIS-Q), a measure designed to capture an individual’s knowledge, attitude and self-reported behaviour towards information security in the workplace. The analyses focused on responses from 197 working Australians, who completed two iterations of...

متن کامل

The Development of the Human Aspects of Information Security Questionnaire (HAIS-Q)

The Human Aspects of Information Security Questionnaire (HAIS-Q) is being developed using a hybrid inductive, exploratory approach, for the purpose of evaluating information security threats caused by employees within organisations. This study reports on the conceptual development and pre-testing of the HAIS-Q. Results from 500 Australian employees were then used to examine the reliability of t...

متن کامل

The Information Security Awareness of Bank Employees

This paper presents research that assessed the Information Security Awareness (ISA) of employees of an Australian bank and compared these results with an identical survey of the Australian general workforce. The objective of this study was to establish a form of construct validity, specifically known-groups validity, of the Human Aspects of Information Security Questionnaire (HAIS-Q). For the p...

متن کامل

Naïve and Accidental Behaviours that Compromise Information Security: What the Experts Think

The aim of the present study was twofold. First it aimed to elicit Information Security (InfoSec) experts’ perceptions about the most important naïve and accidental behaviours that could compromise the InfoSec of an organisation. The second aim was to use these findings to assess the relevance of behaviours that are currently measured by the Human Aspects of Information Security Questionnaire (...

متن کامل

Province The Relationship between Time Management and Work Ethic in the Management of Social Security and Employee Productivity Hormozgan –Iran

The productivity of the most attractive terms of applications in various fields, particularly management. In this regard, human resources productivity plays a key role in any organization.  This study aimed to investigate the relationship between work ethics and productivity of human resources management, time management .Time do research hypotheses using questionnaire distributed among m...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Computers & Security

دوره 42  شماره 

صفحات  -

تاریخ انتشار 2014