TitleIssues and Trends in Information Security Policy Compliance
Publication TypeConference Paper
Year of Publication2019
AuthorsBhaharin, S. H., Mokhtar, U. A., Sulaiman, R., Yusof, M. M.
Conference Name2019 6th International Conference on Research and Innovation in Information Systems (ICRIIS)
Keywordscompliance, computer security, Industry 4.0, information and communication technology, information governance, information leakage threats, Information security, information security incidents, information security management, information security policy, information security policy compliance, ISP, organizational information security policies, Organizations, Personnel, policy-based governance, pubcrawl, security behaviour, security of data, Security Policies Analysis, Standards organizations, threats
AbstractIn the era of Industry 4.0 (IR 4.0), information leakage has become a critical issue for information security. The basic approach to addressing information leakage threats is to implement an information security policy (ISP) that defines the standards, boundaries, and responsibilities of users of information and technology of an organization. ISPs are one of the most commonly used methods for controlling internal user security behaviours, which include, but not limited to, computer usage ethics; organizational system usage policies; Internet and email usage policies; and the use of social media. Human error is the main security threat to information security, resulting from negligence, ignorance, and failure to adhere to organizational information security policies. Information security incidents are a problem related to human behaviour because technology is designed and operated by humans, presenting the opportunities and spaces for human error. In addition to the factor of human error as the main source of information leakage, this study aims to systematically analyse the fundamental issues of information security policy compliance. An analysis of these papers identifies and categories critical factor that effect an employee's attitude toward compliance with ISP. The human, process, technology element and information governance should be thought as a significant scope for more efficiency of information security policy compliance and in any further extensive studies to improve on information security policy compliance. Therefore, to ensure these are properly understood, further study is needed to identity the information governance that needs to be included in organizations and current best practices for developing an information security policy compliance within organizations.
Citation Keybhaharin_issues_2019