• DocumentCode
    185665
  • Title

    Development of Users´ Information Security Awareness Questionnaire (UISAQ) — Ongoing work

  • Author

    Velki, T. ; Solic, K. ; Ocevcic, H.

  • Author_Institution
    Fac. of Teacher Educ., J.J. Strossmayer Univ., Osijek, Croatia
  • fYear
    2014
  • fDate
    26-30 May 2014
  • Firstpage
    1417
  • Lastpage
    1421
  • Abstract
    The user is still weakest link regarding information security matters, but studies on this subject are rare. The aim of this work is to develop general Users´ Information Security Awareness Questionnaire (UISAQ). Development consists of selecting suitable items for which is assumed that measure the level of security awareness and testing impact of each item in measurement. Questionnaire consisted of 4 parts with total of 37 items. Results showed that first part of questionnaire, that examine the common user´s risk behavior, should consist of 17 items (3 items had low factor loadings) separate in 3 subscales. Second part of questionnaire, which consisted of 6 items that measured the level of user´s information security, had high internal consistency (k=6, α=0.89) and a satisfactory factor loadings. Third part of questionnaire, which consisted of 5 items that measured the level of user´s beliefs about information security, should consist of 3 items (2 items significantly disrupted internal consistency) with high factor loadings and good internal consistency (α=0.76). Descriptive statistics showed that all the questions (n=6) in the fourth part of the questionnaire, which had examined the password quality and security, had a full range of answers and that normal distribution wasn´t significantly violated. Although developed questionnaire requires more work and validation, first results showed that UISAQ has potential to become a good and reliable measure of users´ security awareness in the future.
  • Keywords
    information systems; message authentication; UISAQ; high internal consistency; information system; password quality; password security; satisfactory factor loadings; security awareness level measurement; testing impact level measurement; users information security awareness questionnaire; Computers; Information security; Instruments; Loading; Reliability; Sensitivity;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information and Communication Technology, Electronics and Microelectronics (MIPRO), 2014 37th International Convention on
  • Conference_Location
    Opatija
  • Print_ISBN
    978-953-233-081-6
  • Type

    conf

  • DOI
    10.1109/MIPRO.2014.6859789
  • Filename
    6859789