پژوهشنامه کتابداری و اطلاع رسانی

پژوهشنامه کتابداری و اطلاع رسانی

نقش امنیت اطلاعات در بهبود مؤلفه‌های امنیت انسانی، نظارتی و محیطی

نوع مقاله : مقاله پژوهشی

نویسندگان
1 دانشیار، گروه علم اطلاعات و دانش‌شناسی، دانشگاه شهید باهنر کرمان، کرمان، ایران
2 استادیار، پژوهشگاه علوم و فناوری اطلاعات ایران(ایرانداک)، تهران، ایران.
3 کارشناسی ارشد علم اطلاعات و دانش‌شناسی، دانشگاه آزاد اسلامی واحد کرمان، کرمان، ایران
چکیده
مقدمه و هدف: امنیت اطلاعات با اجرای مجموعه‌ای مناسب از نظارت‌ها، شامل سیاست‌ها، قوانین، فرآیندها، رویه‌ها، ساختارهای سازمانی و عملکردهای نرم‌افزاری و سخت‌افزاری حاصل می‌شود. ایزو/ آی‌ای‌سی 27002، استاندارد امنیت اطلاعات است که توسط سازمان بین‌المللی استاندارد با عنوان امنیت اطلاعات، امنیت سایبری و حفاظت از حریم خصوصی و کنترل‌های امنیت اطلاعات منتشر شده است. هدف این پژوهش، ارزیابی وضعیت فعالیت مدیریت امنیت اطلاعات در سازمان‌های دولتی شهر کرمان بر مبنای مؤلفه‌های امنیت انسانی، نظارت و محیطی استاندارد ایزو/ آی‌ای‌سی 27002 است.
روش‌ها: روش پژوهش حاضر توصیفی‌ـ‌پیمایشی است و برای جمع‌آوری داده‌ها از پرسشنامۀ استاندارد ایزو/ آی‌ای‌سی 27002، استفاده شده است. جامعۀ آماری پژوهش شامل، 176 نفر از کارشناسان فناوری اطلاعات و مدیران اصلی و میانی شاغل در سازمان‌های دولتی شهر کرمان است. نمونۀ جامعه آماری با استفاده از فرمول کوکران، شامل، 120 نفر از سازمان‌های آموزش‌وپرورش، استانداری کرمان، امور مالیاتی، جهاد کشاورزی و صنایع و معادن که با هدف دسترسی به آمار و اطلاعات انتخاب شده‌اند، تعیین شد. تحلیل داده‌ها از طریق آمار توصیفی و استنباطی و با استفاده از نرم‌افزار آماری اس‌پی‌اس‌اس صورت گرفته است.
یافته‌ها: با توجه به نتایج به‌دست‌آمده از فرضیۀ پژوهش، به‌دلیل آنکه p- مقدار به‌دست‌آمده از آزمون کمتر از سطح معنی‌داری تحقیق (05/0) است می‌توان بیان کرد که میانگین نمرۀ عملکرد مدیریت امنیت اطلاعات در سازمان‌های دولتی شهر کرمان بر مبنای استاندارد ایزو/ آی‌ای‌سی 27002 بالاتر از حد انتظار است.
بحث و نتیجه‌گیری: تدوین برنامۀ مدیریت امنیت اطلاعات براساس مؤلفه‌های مورد بررسی ازنظر مسائل محیطی، دسترسی، و نیروی انسانی؛ برگزاری دوره‌های آموزشی مناسب و تخصصی برای نیروی انسانی سازمان‌ها در سطوح مدیریتی و کارشناسی؛ ملاحظات حقوقی در کنترل و نظارت بر فعالیت مدیریت امنیت اطلاعات؛ ثبت رخدادهای امنیتی به‌صورت مستمر؛ تعیین سطوح دسترسی به منابع اطلاعاتی به‌صورت دقیق؛ رعایت حقوق مالکیت فکری سازمان‌ها در زمینۀ بهره‌گیری از منابع اطلاعاتی؛ اشتراک‌گذاری اطلاعات با رعایت الزامات مدیریت امنیت اطلاعات از زمرۀ پیشنهادهای پژوهشی است.
اصالت: نتایج حاصل از این پژوهش براساس استاندارد ایزو/ آی‌ای‌سی 27002 نقش مؤثری در برنامه‌ریزی و مدیریت سازمان‌های خدماتی متعدد دارد.
کلیدواژه‌ها

AITooq, R., Barnawi, N., & Alhamed, A. (2024). Enhancing Organizational Success through Knowledge Sharing and Information Security Governance: A Comprehensive Survey. Proceedings of the 10 th World Congress on Electrical Engineering and Computer Systems and Sciences (EECSS'24), Barcelona, Spain - August 19 - 21. doi:10.11159/cist24.163
Akello, B. O. (2024). Organizational information security threats: Status and challenges. World Journal of Advanced Engineering Technology and Sciences, 11(1), 148–162.
Alam, M., & Xiao, N. (2022). How Does Organizational Justice Work Across National Culture? Effects of Procedural and Distributive Justice on Information Security Policy Compliance Across National Culture.
Alotaibi, F. M., Al-Dhaqm, A., Yafooz, W. M., & Al-Otaibi, Y. D. (2023). A Novel Administration Model for Managing and Organising the Heterogeneous Information Security Policy Field. Applied Sciences, 13(17), 9703.
Angraini, Alias, R. A., & Okfalisa. (2021). Information Security Policy Compliance: An Exploration of User Behaviour and Organizational Factors. Paper presented at the International Conference of Reliable Information and Communication Technology.
Antoniou, G. S. (2018). A Framework for the Governance of Information Security: Can it be Used in an Organization. Paper presented at the SoutheastCon 2018.
Benqdara, S. (2023). Building an Information Security Awareness Program for a Private Financial Organization: Case from Libya. International Journal of Computer Applications, 975, 8887.
Chen, H., & Hai, Y. (2024). Exploring the critical success factors of information security management: a mixed-method approach. Information & Computer Security.
Choppara, M., Varanasi, A., Minocha, J., & Sameera, K. H. (2022). Digitalised Information Security in Data Communication in Organizational Flow. International Journal for Research in Applied Science & Engineering Technology (IJRASET), 10(6), 2825–2829.
Ciekanowski, M., Żurawski, S., Ciekanowski, Z., Pauliuchuk, Y., & Czech, A. (2024). Chief information security officer: a vital component of organizational information security management.
da Veiga, A., Astakhova, L. V., Botha, A., & Herselman, M. (2020). Defining organisational information security culture—Perspectives from academia and industry. Computers & Security, 92, 101713. doi:https://doi.org/10.1016/j.cose.2020.101713
Ejigu, K., Siponen, M., & Muluneh, T. (2021). Influence of Organizational Culture on Employees Information Security Policy Compliance in Ethiopian Companies. Paper presented at the Pacific Asia Conference on Information Systems.
Elattresh, U. J., Ramadan, K., & Tokeser, U. (2019). Factors Effecting Information Security Management and their impacts on Organization performance in the work environment: Case study; Hatif Libya Company (HLC). Australian Journal of Basic and Applied Sciences, 13(10), 99–107.
Farid, G., Warraich, N. F., & Iftikhar, S. (2023). Digital information security management policy in academic libraries: A systematic review (2010–2022). Journal of Information Science, 0(0), 01655515231160026. doi:10.1177/01655515231160026
Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness of organizations and its influence on performance. Journal of Information Security and Applications, 58, 102726. doi:https://doi.org/10.1016/j.jisa.2020.102726
Hutchinson, G., & Ophoff, J. (2020, 2020//). A Descriptive Review and Classification of Organizational Information Security Awareness Research. Paper presented at the Information and Cyber Security, Cham.
Ibnugraha, P. D., Nugroho, L. E., & Santosa, P. I. (2021). Risk model development for information security in organization environment based on business perspectives. International Journal of Information Security, 20(1), 113–126. doi:10.1007/s10207-020-00495-7
Ifeyinwa Nkemdilim, O., Aguboshim, F. C., & Nwajikwa, C. S. (2022). MANAGING ORGANISATION INFORMATION SECURITY SYSTEMS, CONFLICTS, AND INTEGRITY FOR SUSTAINABLE AFRICA TRANSFORMATION. ANSPOLY JOURNAL OF INNOVATIVE DEVELOPMENT (AJID), 1(2), 30–39.
Kaaria, A. G. (2023). Human Resource Information Systems Information Security and Organizational Performance of Commercial State Corporations in Kenya. East African Journal of Information Technology, 6(1), 256–278.
Karlsson, M., Karlsson, F., Åström, J., & Denk, T. (2022). The effect of perceived organizational culture on employees’ information security compliance. Information & Computer Security, 30(3), 382–401.
Kaur, J., Dhillon, G., & Picoto, W. N. (2021). The role of organizational competence on information security job performance.
Khando, K., Gao, S., Islam, S. M., & Salman, A. (2021). Enhancing employees information security awareness in private and public organisations: A systematic literature review. Computers & Security, 106, 102267. doi:https://doi.org/10.1016/j.cose.2021.102267
Kinnunen, H., & Siponen, M. (2018). Developing organization-specific information security policies by using critical thinking. Paper presented at the Pacific Asia Conference on Information Systems.
Kitsios, F., Chatzidimitriou, E., & Kamariotou, M. (2023). The ISO/IEC 27001 information security management standard: how to extract value from data in the IT sector. Sustainability, 15(7), 5828.
Lin, C., & Luo, X. (2021). Toward a unified view of dynamic information security behaviors: insights from organizational culture and sensemaking. ACM SIGMIS Database: The DATABASE for Advances in Information Systems, 52(1), 65–90.
Lincke, S. (2024). Information Security Planning: A Practical Approach: Springer Nature.
Liu, C., Liang, H., Wang, N., & Xue, Y. (2022). Ensuring employees' information security policy compliance by carrot and stick: the moderating roles of organizational commitment and gender. Information Technology & People, 35(2), 802–834. doi:10.1108/ITP-09-2019-0452
Lopes, A., Reis, L., São Mamede, H., & Santos, A. (2022, 2022//). Information Security Threat Assessment Using Social Engineering in the Organizational Context – Literature Review. Paper presented at the Information Systems and Technologies, Cham.
Ma, X. (2022). IS professionals’ information security behaviors in Chinese IT organizations for information security protection. Information Processing & Management, 59(1), 102744. doi:https://doi.org/10.1016/j.ipm.2021.102744
Marzban, m. h., Sharifzadeh, r., & Poorebrahimi, A. (2025). Identifying the Human-Nonhuman Components of Information Security Culture: A Qualitative Study Based on Actor-Network Theory (ANT). Human Information Interaction, 12(2), 46–70. Retrieved from http://hii.khu.ac.ir/article-1-3225-fa.html. [In Persian]
Mousavi, M. Z., & Kumar, S. (2019). Analysis of key factors for organization information security. Paper presented at the 2019 International Conference on Machine Learning, Big Data, Cloud and Parallel Computing (COMITCon).
Nan, H., Chen, D., & Bing, Z. (2026). Application of fuzzy data mining and network information security based on sensor networks in enterprise human resource management. International Journal of System Assurance Engineering and Management, 1–9.
Nowicka, J., Ciekanowski, Z., & Milewska, A. (2024). Information Security Management as the Basis for the Functioning of an Organization.
Orozova, D., Kaloyanova, K., & Todorova, M. (2019). Introducing information security concepts and standards in higher education. TEM Journal, 8(3), 1017.
Petrič, G., & Orehek, Š. (2024). Expressing opinions about information security in an organization: the spiral of silence theory perspective. Information & Computer Security, ahead-of-print(ahead-of-print). doi:10.1108/ICS-04-2024-0083
Pietrek, G. W., & Skelnik, K. (2023). CYBERSECURITY AND THE SCOPE OF DESIGNING INFORMATION SECURITY SYSTEMS IN THE ORGANIZATION. Journal of Modern Science, 51(2).
Rohan, R., Pal, D., Hautamäki, J., Funilkul, S., Chutimaskul, W., & Thapliyal, H. (2023). A systematic literature review of cybersecurity scales assessing information security awareness. Heliyon, 9(3). doi:10.1016/j.heliyon.2023.e14234
Shafiei Nikabadi, M., Toghi, S., & Hakaki, A. (2021). A Combined Approach of FMEA and Gray Theory to Rank Aspects of Information Security Risk Management. Business Intelligence Management Studies, 9(34), 191–214. doi:10.22054/ims.2020.46866.1602. [In Persian]
Shiau, W.-L., Wang, X., & Zheng, F. (2023). What are the trend and core knowledge of information security? A citation and co-citation analysis. Information & Management, 60(3), 103774. doi:https://doi.org/10.1016/j.im.2023.103774
Shkarlet, S., Lytvynov, V., Dorosh, M., Trunova, E., & Voitsekhovska, M. (2020, 2020//). The Model of Information Security Culture Level Estimation of Organization. Paper presented at the Mathematical Modeling and Simulation of Systems, Cham.
Stanojević, M., & Izgarević, D. (2025). THE ROLE OF HUMAN RESOURCE MANAGEMENT IN ENHANCING CORPORATE INFORMATION SECURITY CULTURE. MEGATREND REVIJA MEGATREND REVIEW, 105.
Tahmasebi Limooni, S., & Fallah Kordabadi, M. (2019). IInvestigating the Situation of Information Security Architecture in Mazandaran Public Libraries Based on ISO / IEC 27002 Standard. Digital and Smart Libraries Research, 6(2), 35–50. doi:10.30473/mrs.2020.50639.1412
Talebi, H., & Taboli, H. (2024). Implementing a Structural-Interpretive Model for Information Security Management in Iranian Governmental Organizations: An Art-Islamic Approach. Islamic Art Studies, 21(56), 331–348. doi:10.22034/ias.2021.300790.1696
Varsos, D. S., Giannakou, S. A., & Assimakopoulos, N. A. (2018). A systems approach to information security for the twenty-first century organization. Acta Europeana Systemica, 8, 167–178.
vazife, z., Mahdi, M., & Vakili, N. (2019). Model for Feasibility Study and Effective Deployment of Information Security Management Systems Based on Meta-Synthesis Technique. Business Intelligence Management Studies, 7(26), 71–99. doi:10.22054/ims.2019.9717
Vedadi, A., Warkentin, M., Straub, D. W., & Shropshire, J. (2024). Fostering information security compliance as organizational citizenship behavior. Information & Management, 61(5), 103968. doi:https://doi.org/10.1016/j.im.2024.103968
Wagner, T. L. (2023). Neutralization Techniques’ Effect on US Employees’ Intent to Violate Organizational Information Security Policy: A Quantitative Study. Capella University,
Weng, W. (2024). A Beginner’s Guide to Informatics and Artificial Intelligence. doi:https://doi.org/10.1007/978-981-97-1477-3_9
Yazdanmehr, A., Jawad, M., Benbunan-Fich, R., & Wang, J. (2024). The role of ethical climates in employee information security policy violations. Decision Support Systems, 177, 114086. doi:https://doi.org/10.1016/j.dss.2023.114086
 
ارسال نظر در مورد این مقاله
نام را وارد کنید.
نشانی پست الکترونیکی را به درستی وارد کنید.
وابستگی سازمانی را به درستی وارد کنید.
توضیحات را وارد کنید (حداقل 50 حرف)
CAPTCHA Image
شناسه امنیتی را به درستی وارد کنید.

مقالات آماده انتشار، پذیرفته شده
انتشار آنلاین از 03 مرداد 1405

  • تاریخ دریافت 29 فروردین 1405
  • تاریخ بازنگری 25 اردیبهشت 1405
  • تاریخ پذیرش 03 مرداد 1405