Information security policy compliance model for public sector

Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the w...

Full description

Saved in:
Bibliographic Details
Main Author: Abd. Rahim, Fuad Harriz
Format: Thesis
Language:English
Published: 2017
Subjects:
Online Access:http://eprints.utm.my/id/eprint/91983/1/FuadHarrizAbdMRAZAK2017.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
id my-utm-ep.91983
record_format uketd_dc
spelling my-utm-ep.919832021-08-30T05:11:06Z Information security policy compliance model for public sector 2017 Abd. Rahim, Fuad Harriz QA75 Electronic computers. Computer science T58.5-58.64 Information technology Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the weakest link in information security thus factor that affect their intention towards compliance behaviour should be identified. The purpose of this research is to identify factors from recent researches that uses the most common compliance model used in social psychology and technological domain. These factors would then be built up into a proposed model where it will be validated with the survey questionnaire result from an IT department that consists of administrative and IT professionals. This research uses quantitative approach as it is the most used research design used in this domain and statistics software will be used to determine the frequencies, reliability, and the correlation of the factors towards compliance intention. According to 214 respondents, eleven factors have been concluded to have significant impact towards compliance intention that is perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy, attitude, subjective norm, perceived usefulness, perceived ease of use, awareness and punishment while rewards have insignificant relation. The result from this research would support the proposed model that will act as a guidance in public sector to solve issues regarding employee behaviour that impacts information security policy compliance. 2017 Thesis http://eprints.utm.my/id/eprint/91983/ http://eprints.utm.my/id/eprint/91983/1/FuadHarrizAbdMRAZAK2017.pdf application/pdf en public http://dms.library.utm.my:8080/vital/access/manager/Repository/vital:134275 masters Universiti Teknologi Malaysia, Razak Faculty of Technology and Informatics Razak Faculty of Technology and Informatics
institution Universiti Teknologi Malaysia
collection UTM Institutional Repository
language English
topic QA75 Electronic computers
Computer science
T58.5-58.64 Information technology
spellingShingle QA75 Electronic computers
Computer science
T58.5-58.64 Information technology
Abd. Rahim, Fuad Harriz
Information security policy compliance model for public sector
description Technical aspect of security is inadequate to ensure information security within organization thus requires for adoption of information security policy. Policy without compliance from the employee of an organization would be useless where it requires desirable behaviours. Human are known to be the weakest link in information security thus factor that affect their intention towards compliance behaviour should be identified. The purpose of this research is to identify factors from recent researches that uses the most common compliance model used in social psychology and technological domain. These factors would then be built up into a proposed model where it will be validated with the survey questionnaire result from an IT department that consists of administrative and IT professionals. This research uses quantitative approach as it is the most used research design used in this domain and statistics software will be used to determine the frequencies, reliability, and the correlation of the factors towards compliance intention. According to 214 respondents, eleven factors have been concluded to have significant impact towards compliance intention that is perceived severity, perceived vulnerability, maladaptive rewards, response efficacy, self-efficacy, attitude, subjective norm, perceived usefulness, perceived ease of use, awareness and punishment while rewards have insignificant relation. The result from this research would support the proposed model that will act as a guidance in public sector to solve issues regarding employee behaviour that impacts information security policy compliance.
format Thesis
qualification_level Master's degree
author Abd. Rahim, Fuad Harriz
author_facet Abd. Rahim, Fuad Harriz
author_sort Abd. Rahim, Fuad Harriz
title Information security policy compliance model for public sector
title_short Information security policy compliance model for public sector
title_full Information security policy compliance model for public sector
title_fullStr Information security policy compliance model for public sector
title_full_unstemmed Information security policy compliance model for public sector
title_sort information security policy compliance model for public sector
granting_institution Universiti Teknologi Malaysia, Razak Faculty of Technology and Informatics
granting_department Razak Faculty of Technology and Informatics
publishDate 2017
url http://eprints.utm.my/id/eprint/91983/1/FuadHarrizAbdMRAZAK2017.pdf
_version_ 1747818548771684352