Faizan Ali, R. and Dominic, P.D.D. and Hina, S. and Naseer, S. (2024) Fostering information security policies compliance with ISA-95-based framework: an empirical study of oil and gas employees. International Journal of Information Security, 23 (2). pp. 1197-1213.
Full text not available from this repository.Abstract
Oil and gas (O&G) organizations are progressively being digitalized in order to facilitate substantial information flow to remain competitive in the information age. This critical sector is spearheading the establishment of technical security measures to mitigate information security risks, yet employee behavioral influence remains an ongoing challenge in assuring information security. Existing studies of this domain primarily focus on employee behavior reshaping through multiple psychological theories. However, these studies ignore how these critical infrastructures implement information security. Most such infrastructures follow the International Society of Automation (ISA)-95 levels of automation and implement information security controls in line with these levels. This research paper proposed a theoretical framework to enhance information security policy compliance (ISPC) at level 4 to level 2 automation level in O&G organizations. To support the hypotheses, data were collected from 13 Malaysian O&G organizations. A total of 254 O&G employees participated in the survey and the structural equation modeling technique was used for data analysis. The study confirmed that ISA-95-based organizational governance factors and social bonding could enhance ISPC in O&G organizations. However, risk assessment and involvement factors have shown less support to the notion. For information systems practitioners, this study has shown how to enhance ISPC in O&G organizations through ISA-95-based organizational governance and social bonding. © The Author(s), under exclusive licence to Springer-Verlag GmbH, DE 2023.
Item Type: | Article |
---|---|
Additional Information: | cited By 0 |
Uncontrolled Keywords: | Personnel; Risk assessment; Security of data; Security systems, Empirical studies; Information security policies; International society; International society of automation-95; Oil and gas; Oil and gas organization; Organisational; Organizational governance; Policy compliance; Social bonding, Automation |
Depositing User: | Mr Ahmad Suhairi UTP |
Date Deposited: | 04 Jun 2024 14:19 |
Last Modified: | 04 Jun 2024 14:19 |
URI: | https://khub.utp.edu.my/scholars/id/eprint/19770 |