Show simple item record

dc.contributor.advisorLang, Michael
dc.contributor.advisorTygar, Doug
dc.contributor.authorConnolly, Lena
dc.date.accessioned2016-08-19T12:53:42Z
dc.date.available2016-08-19T12:53:42Z
dc.date.issued2015-08-18
dc.identifier.urihttp://hdl.handle.net/10379/5977
dc.description.abstractAn increasing number of information security breaches in organisations presents a serious threat to the security of personal and commercially sensitive information. Recent research shows that humans are the weakest link in the security chain and the root cause of a great portion of security breaches. This dissertation draws on the General Deterrence Theory and prior research on organisational and national culture and examines how procedural security countermeasures, including security education and an information security policy, and cultural factors affect employee security behaviour in organisational settings. In particular, this research project answers the following questions: • How do security countermeasures affect employee security behaviour in organisational settings? • How does perceived organisational culture affect employee security behaviour in organisational settings? • How does perceived national culture affect employee security behaviour in organisational settings? Data for this research project were collected from 19 individuals, nine from organisations located in the United States and ten in Ireland, through qualitative interviews. Organisations and study participants were purposely selected. The principle of theoretical sampling guided data collection. Study’s findings demonstrate that procedural security countermeasures, including security education and an information security policy, tend to lead to compliant behaviour. Furthermore, organisational culture values of solidarity and people-orientation incline to promote compliance with information security requirements, while sociability and task-orientation lean towards non-compliant behaviour. Additionally, flat structure is associated with the improved information security in organisations because employees are empowered to bring up various issues related to information security. Finally, comparative analysis suggests differences in two data sets. In particular, employees in observed organisations located in the United States tend to be more compliant with information security rules than their counterparts from observed organisations located in Ireland. Further, group non-compliance is a more prevalent occurrence in observed organisations located in Ireland as opposed to observed cases located in the United States. Finally, it appears that employees in observed organisations located in the United States tend to put higher emphasis on information security value than employees in observed cases located in Ireland.en_IE
dc.rightsAttribution-NonCommercial-NoDerivs 3.0 Ireland
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/3.0/ie/
dc.subjectInformation systems securityen_IE
dc.subjectNational cultureen_IE
dc.subjectOrganisational cultureen_IE
dc.subjectProcedural security countermeasuresen_IE
dc.subjectEmployee security behaviouren_IE
dc.subjectBusiness information systemsen_IE
dc.titleAn investigation of employee security behaviour in organisational settings: the effect of procedural security countermeasures and cultural factorsen_IE
dc.typeThesisen_IE
dc.local.noteAn increasing number of information security breaches in organisations presents a serious threat to the security of personal and commercially sensitive information. Recent research shows that humans are the weakest link in the security chain and the root cause of a great portion of security breaches.en_IE
dc.local.finalYesen_IE
nui.item.downloads1557


Files in this item

Thumbnail
Thumbnail

This item appears in the following Collection(s)

Show simple item record

Attribution-NonCommercial-NoDerivs 3.0 Ireland
Except where otherwise noted, this item's license is described as Attribution-NonCommercial-NoDerivs 3.0 Ireland