Title :
Effectiveness of information systems security in IT organizations in Malaysia
Author :
Al-Salihy, Wafaa ; Ann, Jannet ; Sures, R.
Author_Institution :
Network Res. Group, Univ. Sci. Malaysia, Penang, Malaysia
Abstract :
As computers become more and more pervasive, information technology (IT) organizations have become so dependent on information systems (IS) for their daily operations and strategic purposes thus intensify the need for IS security. The lack of concern for IS security is evident that organizations are often victimized by computer abuse incidents. Studies on information systems security in Malaysia´s IT industry context is very insufficient. This paper will focus on how deterrent actions, preventive actions and organizational actions lead to IS security effectiveness in an IT organization. A survey of Association of Computer and Multimedia Industry of Malaysia (PIKOM) members were conducted. Based on the results of the statistical analysis, a conceptual model of IS security was developed using statistical package for social sciences (SPSS) 8.0. To test the effectiveness of the conceptual model, a case study was done on a typical IT organization to review its IS security status. Finally, findings from this case study were compared with the results from the statistical analysis. The results from the statistical analysis shows that systems environment security control, codes of ethics, security software control and top management support have a positive significant effect on the level of security effectiveness whereas disincentives certainty and organizational maturity was found to have negative significant effect on the level of security effectiveness. Findings from the case study shows that disincentives certainty, systems environment security control, security software control and organizational maturity are key factors contributing to IS security effectiveness while codes of ethics and top management support are insignificant to IS security effectiveness.
Keywords :
DP industry; information systems; security of data; social sciences; statistical analysis; Association of Computer and Multimedia Industry of Malaysia; IS; IT organization; codes of ethics; deterrent action; disincentives certainty; information system security; information technology; organizational action; organizational maturity; preventive action; security software control; statistical analysis; statistical package for social science; systems environment security control; top management support; Computer industry; Computer security; Control systems; Environmental management; Ethics; Information security; Information systems; Information technology; Pervasive computing; Statistical analysis;
Conference_Titel :
Communications, 2003. APCC 2003. The 9th Asia-Pacific Conference on
Print_ISBN :
0-7803-8114-9
DOI :
10.1109/APCC.2003.1274451