Institutional Repository

An information security framework for reducing information security costs and sustaining information security culture

Show simple item record

dc.contributor.advisor Loock, Marianne
dc.contributor.advisor Kritzinger, Elmarie
dc.contributor.advisor Singh, S.
dc.contributor.author Govender, Sunthoshan G.
dc.date.accessioned 2023-10-31T10:49:05Z
dc.date.available 2023-10-31T10:49:05Z
dc.date.issued 2023-06-13
dc.identifier.uri https://hdl.handle.net/10500/30610
dc.description.abstract As the velocity and volume of data breaches increases, information security is a cornerstone to the sustainability of business functionality in organisations. The focus of traditional information security has been to address concerns through the implementation of technology. Nonetheless, the profound catalyst behind data breaches often stems from the influence of individuals on information security, necessitating human involvement to bolster the intricate array of information security technologies. Elevating the information security culture among staff members should stand as a pivotal impetus in tandem with the enhancement of information security technology. This leads to a greater need to focus on sociological solutions with lesser emphasis on technological solutions. This research aims to concentrate on mitigating the risks associated with information security breaches through the enhancement of information security culture, while decreasing the overall expenses tied to managing information security within organisations. The study was conducted using Design Science Research Methodology (DSRM), wherein artefacts, including three models, a framework and a supporting evaluation tool were developed. Through the DSRM process, these artefacts were evaluated, tested and iteratively improved. The results obtained from the assessments of the framework and tool demonstrated their efficacy in enabling organisations to derive value by assessing their security posture, prioritising cost-reduction endeavours, and formulating strategies to enhance information security culture. The practical significance of this research lies in the fact that the developed framework and tool offer a streamlined and comprehensive approach to appraising an organisation's information security status, particularly emphasising nontechnical aspects for improvement. What sets these artefacts apart is their unique integration of elements that emphasise the human impact on information security, aligning with both cost-reduction goals and the enhancement of security assessment within an organisation. Through testing, second iterations of the framework and tool were designed along with a web-based application for using the framework. Information was also gathered to be able to determine a roadmap to further improve the framework and tool over time. en
dc.format.extent 1 online resource (xxiii, 286 leaves) : illustrations (chiefly color), color graphs
dc.language.iso en en
dc.subject Information security en
dc.subject Information security architecture en
dc.subject Information security assessment en
dc.subject Information security culture en
dc.subject Information security cost en
dc.subject Information security framework en
dc.subject Information security risk en
dc.subject Organisational behaviour en
dc.subject Organisational culture en
dc.subject Design science research en
dc.subject.ddc 005.8
dc.subject.lcsh Computer networks -- Security measures en
dc.subject.lcsh Computer security -- Management en
dc.subject.lcsh Information technology -- Cost effectiveness en
dc.subject.lcsh Computer network architectures en
dc.subject.lcsh Computer security -- Cost effectiveness
dc.subject.other UCTD
dc.title An information security framework for reducing information security costs and sustaining information security culture en
dc.type Thesis en
dc.description.department School of Computing en
dc.description.degree Ph. D. (Information Systems)


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search UnisaIR


Browse

My Account

Statistics