• Sean Maynard

Information Security Culture

The effect that an organisations security culture has on the security of the organisation is profound. This area of research investigates security culture and its relationship to organisation culture, and to security practice within organisations. Security Culture can be defined as everything that people have, people think, and people do around security as members of the organisation.

What is Security Culture

In the last few years, research in security culture has been expanding rapidly. Much of this research however has a limited focus and often only concentrates on the attitudes and behaviour of end-users as well as on how management can influence these aspects of security culture to improve the end-user's adherence to security policies. However the impact of security culture in an organisation goes further than just the influence on security policy. The fact that many security incidents experienced by organisations are caused by their employees is a compelling argument for organisations to be concerned with security culture. The presence of a good security culture in an organisation should help to empower employees with regards to information security. In terms of research, the concept of security culture, whilst it has been discussed for over a decade, is still in its infancy. As such, there are many definitions as to what security culture is: "the totality of pattern of beliefs, values and practices that contribute to the protection of all kind of information" (Dhillon 1995), "the way that things are done" (Martins & Eloff 2002), "all socio-cultural measures that support technical security measures" (Schlienger 2003). More recently, security culture has been defined more in terms of security related values, beliefs and actions in relation to the protection of organizational information (Ramachandran, 2007).

Measuring Security Culture

Given that security culture helps to guide employee behaviour towards what security practices are required by the organisation, and that little research has been completed that determines the relationship between security culture and security practices, it is little wonder that presently there is no way of measuring an organisations security culture. Work is currently in progress on determining the relationship between security and organisational culture, and between organisational culture and organisational security practices (see Lim et al. 2010, 2012).


Dr Sean Maynard
School of Computing and Information Systems, University of Melbourne, Parkville, Vic 3000, Australia