Back to results

Abertay University

The socio-organisational factors that shape guardianship experience of information security management in organisations

Abstract

dc:description.abstract

To become more effective and efficient organisations are increasing their utilisation of information and information systems, which has made them more vulnerable to various kinds of attacks from cybercriminals; a major consequence of which are security breaches. Further, despite previous studies showing insecure behaviour as a major cause, information security if often viewed as a technical problem only, where socio-organisational factors are often overlooked. Therefore, the primary aim of this qualitative research is to investigate how socio-organisational factors influence security behaviour in organisations and to describe the experiences of guardians of information security management. In this context, guardians are defined as those actors who are responsible for protecting information in organisations. In total there were 86 in-depth interviews conducted with three groups of guardians: security managers, who experience guardianship by managing an organisation’s information security; end users, who experience guardianship by using an organisation’s security controls; and security testers, who experience guardianship by testing the level of information security in organisations via the practice of security testing. The emergent findings showed that the willingness and capability of end users towards protecting information in organisations was influenced by numerous socio-organisational factors connecting to: (1) the security behaviour of upper management; (2) the effective development and implementation of security policies; (3) the effective development and implementation of SETA programmes; (4) the effective use of monitoring and enforcement practices; and (5) the usability of technical security controls. In addition, the effectiveness of security managers towards managing end user security behaviour was influenced by upper management support for information security. Lastly, the findings showed that security testing comprised numerous sequential stages, which can be mapped using the universal crime script; where the goals and objectives for each stage, as well the required use of tools and tactics used by different security testers, were successfully mapped.

Degree

thesis:*
Name dc:type.qualificationname
PhD
Level dc:type.qualificationlevel
Doctoral Thesis
Grantor dc:publisher.institution
Abertay University
Year dc:date.issued
2020

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Johnstone, Jason
Advisors dc:contributor.advisor
  • De Paoli, Stefano
  • Ferguson, Robert

Rights

Language dc:language
eng

Identifiers

dc:identifier.*
Identifier
oai:rke.abertay.ac.uk:studenttheses/655bb38f-225c-4f9f-8cc0-8ae0f6f3a552
OAI identifier oai:identifier
oai:rke.abertay.ac.uk:studenttheses/655bb38f-225c-4f9f-8cc0-8ae0f6f3a552

Chain of custody

source
Harvested from
Abertay University
Base URL
rke.abertay.ac.uk/ws/oai
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Johnstone, Jason. The socio-organisational factors that shape guardianship experience of information security management in organisations. Doctoral Thesis thesis, Abertay University, 2020. https://rke.abertay.ac.uk/en/studentTheses/655bb38f-225c-4f9f-8cc0-8ae0f6f3a552