05165nam a22003617i 4500952013800000952011200138999001700250003000800267005001700275006001900292007000300311008004100314020002200355040002300377090002900400100002800429245015900457264003400616264001200650300007300662336002100735337002500756338002300781347002400804500005500828502007200883504004000955520368200995610005504677650004404732650001104776942001604787 00102lcc40708REFa20000b20000cREFd2020-02-26l0oFSKKP .A34 2019 r ThesispT000000349r2020-08-13 00:00:00w2020-02-26yTHESIS 00102lcc4071a20000b20000d2020-02-26l0oCD 12344pT000000350r2021-02-16 00:00:00w2020-02-26yTHESIS c92099d92105MY-KuUP20251125105524.0a||||fr|||| 001 0 ta200226t20192019my ||||f ma|| 001 0 eng d aTHE0008530(Local) aUMPbengcUMPerda aFSKKP .A34 2019 r Thesis0 aAkhyari Nasir,eauthor.12aA dimension-based information security culture model for information security policy compliance behavior in Malaysian public universities /cAkhyari Nasir01aKuantan, Pahang :bUMP,c201904a© 2019 axviii, 270 pages :billustrations (some color) ;c30 cm. +e1 CD-ROM atext2rdacontent aunmediated2rdamedia avolume2rdacarrier atext filebPDF2rda aFaculty of Computer Systems & Software Engineering aThesis (Doctor of Philosophy) -- Universiti Malaysia Pahang –2019 aIncludes bibliographical references3 aDue to the increase of information security incidents and attacks caused by employees’ behavior, scholars and experts recommended the establishment of a positive Information Security Culture (ISC) to guide employees’ behavior towards complying with Information Security Policy (ISP) established in the organization. However, it is still unclear as to what elements or aspects required for a positive ISC formation, which would effectively influences ISP compliance behavior. Current studies still could not provide a conclusive finding on the actual influence of ISC towards ISP compliance behavior for suggesting ISC model that effectively influences ISP compliance behavior. The inconsistency of dimensions and approaches in conceptualizing the ISC are the main gaps in current studies. ISC literature indicates that different sets of dimensions used to conceptualize ISC in various studies. Apart from that, since some studies suggested ISC depends on cultural differences and national culture, previous findings could not be generalized to Malaysian organizations and employees. This research addresses these issues by developing an ISC model based on new formulated dimensions for employee’s ISP compliance behavior in Malaysian Public Universities. In this study, ISC was conceptualized as a dimension-based concept formed by seven dimensions formulated based on widely accepted concepts of Organizational Culture and ISC. The formulated dimensions not only covered all levels in these concepts, the dimensions were also covered most of ISC key factors in current literature. This ISC concept then was integrated with the most significant behavioral theory in ISP compliance behavior literature, which is Theory of Planned Behavior to thoroughly examine and demonstrate the effectiveness of new ISC concept in influencing employees’ ISP compliance behavior. The model was tested in public university settings in Malaysia, whereby a questionnaire-based survey was conducted to collect data from the employees using convenient sampling technique due to homogeneity of the population. This study employed Structural Equation Modeling (SEM) to validate the research model. Partial Least Squares (PLS) modeling technique was used to analyze the data via SmartPLS 3.0 software package. The findings show that all seven formulated dimensions are relevant and significant (weightage>0.1 and t-values>1.65, p-values<0.001) in contributing towards ISC concept used in the model. The ISC concept based on these seven dimensions was also found to be significant in influencing employees’ ISP compliance behavior (R2=0.449). These findings suggest that seven aspects represented by seven dimensions in the study could be used as guidelines to assess and establish a positive ISC in guiding employees’ security behavior in organizations especially in public universities in Malaysia. The findings also reveal that the most important aspect in establishing a positive ISC is Information Security Knowledge. Moreover, behavioral factors of Attitude, Normative Belief and SelfEfficacy were found to be significant in mediating the relationship between ISC and employee’s ISP compliance intention. These findings provide new insights and knowledge on standard issues regarding the concept of ISC based on its dimensions. They also provide a clear understanding on ISC influence towards employees’ security behavior. The model could also be used by Information Security Management (ISM) as guidelines to plan and establish effective ISC strategies and to predict security behavior in obtaining higher level of information security and its systems in Malaysian organizations.20aFaculty of Computer Systems & Software Engineering 0aUniversities and collegesxDisertations 0aTheses 2lcccTHESIS