信息安全文化对信息安全治理能力的影响(案例研究:PT XYZ)

K. Suwandi, Johan Setiawan
{"title":"信息安全文化对信息安全治理能力的影响(案例研究:PT XYZ)","authors":"K. Suwandi, Johan Setiawan","doi":"10.53748/jmis.v1i2.19","DOIUrl":null,"url":null,"abstract":"Objective – To analyze the relationship between a company’s information security approach/culture with its information security governance capabilities based on COBIT 5 framework and provide recommendations that can be used to improve the company's information security capabilities per COBIT 5 standard. \nMethodology – The research uses qualitative and quantitative methods by conducting interviews and distributing questionnaires to 3 members of the IT Department at PT XYZ. \nFindings – The research found that the measured COBIT 5 processes (APO13 and DSS05) failed to reach the expected target (level 4), with each DSS05 and APO13 can only reach level 1 and 2 respectively. In addition, several flaws were also found in the company’s information security culturethat may have contributed directly or indirectly to the current state of the company’s information security capabilities. \nNovelty – In this study, the researchers expand the previous study on information security culture conducted in 2010 by performing a security audit on a company's IT department to analyze the connection between corporate culture, especially information security culture and the capability level of information security governance. The company thus can make improvements or corrections to its information security approach/culture based on the recommendations provided with COBIT 5 framework. \nKeywords: Capability Level; COBIT; Governance; Information Security Culture. ","PeriodicalId":331767,"journal":{"name":"Journal of Multidisciplinary Issues","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2021-08-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Influence of Information Security Culture on the Information Security Governance Capabilities (Case Study: PT XYZ)\",\"authors\":\"K. Suwandi, Johan Setiawan\",\"doi\":\"10.53748/jmis.v1i2.19\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Objective – To analyze the relationship between a company’s information security approach/culture with its information security governance capabilities based on COBIT 5 framework and provide recommendations that can be used to improve the company's information security capabilities per COBIT 5 standard. \\nMethodology – The research uses qualitative and quantitative methods by conducting interviews and distributing questionnaires to 3 members of the IT Department at PT XYZ. \\nFindings – The research found that the measured COBIT 5 processes (APO13 and DSS05) failed to reach the expected target (level 4), with each DSS05 and APO13 can only reach level 1 and 2 respectively. In addition, several flaws were also found in the company’s information security culturethat may have contributed directly or indirectly to the current state of the company’s information security capabilities. \\nNovelty – In this study, the researchers expand the previous study on information security culture conducted in 2010 by performing a security audit on a company's IT department to analyze the connection between corporate culture, especially information security culture and the capability level of information security governance. The company thus can make improvements or corrections to its information security approach/culture based on the recommendations provided with COBIT 5 framework. \\nKeywords: Capability Level; COBIT; Governance; Information Security Culture. \",\"PeriodicalId\":331767,\"journal\":{\"name\":\"Journal of Multidisciplinary Issues\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-08-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Multidisciplinary Issues\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.53748/jmis.v1i2.19\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Multidisciplinary Issues","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.53748/jmis.v1i2.19","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

目标-分析公司的信息安全方法/文化与其基于COBIT 5框架的信息安全治理能力之间的关系,并根据COBIT 5标准提供可用于改进公司信息安全能力的建议。研究方法:本研究采用定性和定量方法,通过对PT XYZ IT部门的3名成员进行访谈和分发调查问卷。研究发现,测量的COBIT 5过程(APO13和DSS05)未能达到预期目标(4级),每个DSS05和APO13只能分别达到1级和2级。此外,在公司的信息安全文化中也发现了一些缺陷,这些缺陷可能直接或间接地导致了公司信息安全能力的现状。新颖性——在本研究中,研究者扩展了2010年对信息安全文化的研究,对某公司的IT部门进行了安全审计,分析了企业文化,尤其是信息安全文化与信息安全治理能力水平之间的联系。因此,公司可以根据COBIT 5框架提供的建议对其信息安全方法/文化进行改进或更正。关键词:能力水平;COBIT;治理;资讯保安文化。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Influence of Information Security Culture on the Information Security Governance Capabilities (Case Study: PT XYZ)
Objective – To analyze the relationship between a company’s information security approach/culture with its information security governance capabilities based on COBIT 5 framework and provide recommendations that can be used to improve the company's information security capabilities per COBIT 5 standard. Methodology – The research uses qualitative and quantitative methods by conducting interviews and distributing questionnaires to 3 members of the IT Department at PT XYZ. Findings – The research found that the measured COBIT 5 processes (APO13 and DSS05) failed to reach the expected target (level 4), with each DSS05 and APO13 can only reach level 1 and 2 respectively. In addition, several flaws were also found in the company’s information security culturethat may have contributed directly or indirectly to the current state of the company’s information security capabilities. Novelty – In this study, the researchers expand the previous study on information security culture conducted in 2010 by performing a security audit on a company's IT department to analyze the connection between corporate culture, especially information security culture and the capability level of information security governance. The company thus can make improvements or corrections to its information security approach/culture based on the recommendations provided with COBIT 5 framework. Keywords: Capability Level; COBIT; Governance; Information Security Culture. 
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Impact of Implementing the Unification of The IT Section into One Division Using a Change Management Strategy at PT XYZ SENTIMENT ANALYSIS OF COMMENTS ON SEXUAL HARASSMENT IN COLLEGES ON FOUR POPULAR SOCIAL MEDIA MEASUREMENT OF CAPABILITY LEVEL AT PT SENTRAL ELECTRIC USING COBIT 5 FRAMEWORK Analysis of Search Engine Optimization Application on Markas Gamers' Website The Effect of Religiosity on Muslim Consumer’s Switching Behavior in Greater Jakarta Area
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1