Library and Information Science Research

Library and Information Science Research

The Role of Information Security in Improving Human, Surveillance, and Environmental Security Components

Document Type : Original Article

Authors
1 Associate Professor, Department of Knowledge and Information Science, Shahid Bahonar University of Kerman, Kerman, Iran.
2 Assistant Professor, Iranian Research Institute for Information Science & Technology (IranDoc), Tehran, Iran
3 M.S.c. in Knowledge and Information Science, Islamic Azad University, Kerman Branch, Kerman, Iran
Abstract
Abstract
Introduction: In today's knowledge-based economy, organizations increasingly regard knowledge and information as their most valuable strategic assets. However, these assets are highly vulnerable to a wide range of security threats. The rapid expansion of digital technologies and electronic data exchange has significantly increased the exposure of sensitive information to cyberattacks, data breaches, and unauthorized access. Business and public organizations routinely generate, collect, process, and store vast amounts of information, making effective information security management essential for protecting critical organizational assets. Information security management encompasses the policies, procedures, and controls required to safeguard the confidentiality, integrity, and availability of information against potential threats and vulnerabilities. An Information Security Management System (ISMS) provides a systematic framework for managing sensitive organizational information, minimizing security risks, and ensuring business continuity through the proactive mitigation of security incidents. Moreover, an ISMS enables organizations to identify, assess, and address security risks while demonstrating their commitment to information security and privacy. The implementation of an ISMS typically involves information security professionals, including Chief Information Security Officers, IT Operations Managers, Security Coordinators, Security Analysts, and IT administrators, who are responsible for establishing and maintaining appropriate technical and organizational controls. These controls may include security policies, procedures, governance structures, software, and hardware mechanisms designed to protect information assets. Among the internationally recognized frameworks for information security management, ISO/IEC 27002, entitled Information Security, Cybersecurity and Privacy Protection—Information Security Controls, provides comprehensive guidance on the selection, implementation, and management of information security controls. Accordingly, the present study aims to evaluate the status of information security management practices in government organizations in Kerman, Iran, based on the human security, monitoring security, and environmental security components of the ISO/IEC 27002 standard. .
Methodology: This study employed a descriptive survey research design. Data were collected using a researcher-developed questionnaire based on the ISO/IEC 27002 standard for information security management. The study population comprised 176 information technology specialists, senior managers, and middle managers employed in government organizations in Kerman, Iran. The sample size was determined using Cochran’s formula, resulting in a sample of 120 participants selected from the Departments of Education, the Kerman Governorate, the Tax Affairs Organization, the Agricultural Jihad Organization, and the Department of Industry, Mine and Trade. These organizations were purposively selected to facilitate access to relevant data and information. The questionnaire was developed in accordance with the components of the ISO/IEC 27002 standard, an internationally recognized framework for information security management. It focused on six key domains encompassing 19 subcomponents related to human and environmental security: (1) information security organization (2 subcomponents), (2) human resource security management (3 subcomponents), (3) physical and environmental security management (2 subcomponents), (4) access control (7 subcomponents), (5) information security incident management (2 subcomponents), and (6) compliance management (3 subcomponents). Because the study focused on organizational personnel and security policies, these six domains were incorporated into the research instrument. All items were measured using a five-point Likert scale. The content validity of the questionnaire was confirmed by experts, yielding a content validity coefficient of 0.93. The reliability of the instrument was assessed using Cronbach’s alpha, demonstrating satisfactory internal consistency. Data were analyzed using SPSS software. Descriptive statistics were employed to summarize the data, while inferential analyses were conducted after verifying the assumptions of normality using the Kolmogorov–Smirnov test and homogeneity of variances. One-way analysis of variance (ANOVA) was used to test the research hypotheses, and the Friedman test was applied to rank the dimensions of information security management.
Findings: The results of the Kolmogorov–Smirnov test confirmed that all research variables satisfied the assumption of normality. At the 95% confidence level (α = 0.05), the null hypothesis of normal distribution was not rejected, justifying the use of parametric statistical tests. Accordingly, one-sample Student’s t-tests were conducted to examine the main research hypothesis and to compare the mean scores of each dimension of information security management with the expected benchmark. The findings from the six sub-hypotheses indicated that five dimensions—human resource security management, physical and environmental security, access control, information security incident management, and compliance management—achieved mean scores that were significantly higher than the expected level (p < 0.05). In contrast, the information security organization dimension performed below the expected level, indicating a relative weakness in organizational security governance. Overall, the results support the main research hypothesis, demonstrating that the overall performance of information security management in the government organizations of Kerman, as assessed against the ISO/IEC 27002 standard, is significantly above the expected level.
Discussion & Conclusion: The findings of the study indicate that information security policy management is not adequately implemented in government organizations in Kerman. Among the organizations examined, the highest level of performance in this dimension was observed in the Governorate, whereas the lowest level was reported in the Agricultural Jihad Organization. These findings suggest that the fundamental theoretical principles underlying information security policy management have not received sufficient attention within these organizations. An effective information security policy should reflect managerial commitment and clearly define the organization’s strategic approach to information security management. However, the results indicate that key elements, including the overall objectives, scope, significance, and framework of information security, have not been sufficiently established. Furthermore, information security policies are not systematically reviewed and updated at predetermined intervals, which may reduce their effectiveness in addressing evolving security challenges. Based on the findings, several recommendations are proposed. These include developing a comprehensive information security management plan aligned with environmental, access control, and human resource security requirements; providing specialized and continuous training programs for managerial and technical personnel; strengthening legal frameworks for controlling and monitoring information security activities; maintaining continuous records of security incidents; accurately defining access levels to information resources; ensuring compliance with intellectual property rights in the use of organizational information resources; and facilitating information sharing in accordance with information security management principles.
Keywords

AITooq, R., Barnawi, N., & Alhamed, A. (2024). Enhancing Organizational Success through Knowledge Sharing and Information Security Governance: A Comprehensive Survey. Proceedings of the 10 th World Congress on Electrical Engineering and Computer Systems and Sciences (EECSS'24), Barcelona, Spain - August 19 - 21. doi:10.11159/cist24.163
Akello, B. O. (2024). Organizational information security threats: Status and challenges. World Journal of Advanced Engineering Technology and Sciences, 11(1), 148–162.
Alam, M., & Xiao, N. (2022). How Does Organizational Justice Work Across National Culture? Effects of Procedural and Distributive Justice on Information Security Policy Compliance Across National Culture.
Alotaibi, F. M., Al-Dhaqm, A., Yafooz, W. M., & Al-Otaibi, Y. D. (2023). A Novel Administration Model for Managing and Organising the Heterogeneous Information Security Policy Field. Applied Sciences, 13(17), 9703.
Angraini, Alias, R. A., & Okfalisa. (2021). Information Security Policy Compliance: An Exploration of User Behaviour and Organizational Factors. Paper presented at the International Conference of Reliable Information and Communication Technology.
Antoniou, G. S. (2018). A Framework for the Governance of Information Security: Can it be Used in an Organization. Paper presented at the SoutheastCon 2018.
Benqdara, S. (2023). Building an Information Security Awareness Program for a Private Financial Organization: Case from Libya. International Journal of Computer Applications, 975, 8887.
Chen, H., & Hai, Y. (2024). Exploring the critical success factors of information security management: a mixed-method approach. Information & Computer Security.
Choppara, M., Varanasi, A., Minocha, J., & Sameera, K. H. (2022). Digitalised Information Security in Data Communication in Organizational Flow. International Journal for Research in Applied Science & Engineering Technology (IJRASET), 10(6), 2825–2829.
Ciekanowski, M., Żurawski, S., Ciekanowski, Z., Pauliuchuk, Y., & Czech, A. (2024). Chief information security officer: a vital component of organizational information security management.
da Veiga, A., Astakhova, L. V., Botha, A., & Herselman, M. (2020). Defining organisational information security culture—Perspectives from academia and industry. Computers & Security, 92, 101713. doi:https://doi.org/10.1016/j.cose.2020.101713
Ejigu, K., Siponen, M., & Muluneh, T. (2021). Influence of Organizational Culture on Employees Information Security Policy Compliance in Ethiopian Companies. Paper presented at the Pacific Asia Conference on Information Systems.
Elattresh, U. J., Ramadan, K., & Tokeser, U. (2019). Factors Effecting Information Security Management and their impacts on Organization performance in the work environment: Case study; Hatif Libya Company (HLC). Australian Journal of Basic and Applied Sciences, 13(10), 99–107.
Farid, G., Warraich, N. F., & Iftikhar, S. (2023). Digital information security management policy in academic libraries: A systematic review (2010–2022). Journal of Information Science, 0(0), 01655515231160026. doi:10.1177/01655515231160026
Hasan, S., Ali, M., Kurnia, S., & Thurasamy, R. (2021). Evaluating the cyber security readiness of organizations and its influence on performance. Journal of Information Security and Applications, 58, 102726. doi:https://doi.org/10.1016/j.jisa.2020.102726
Hutchinson, G., & Ophoff, J. (2020, 2020//). A Descriptive Review and Classification of Organizational Information Security Awareness Research. Paper presented at the Information and Cyber Security, Cham.
Ibnugraha, P. D., Nugroho, L. E., & Santosa, P. I. (2021). Risk model development for information security in organization environment based on business perspectives. International Journal of Information Security, 20(1), 113–126. doi:10.1007/s10207-020-00495-7
Ifeyinwa Nkemdilim, O., Aguboshim, F. C., & Nwajikwa, C. S. (2022). MANAGING ORGANISATION INFORMATION SECURITY SYSTEMS, CONFLICTS, AND INTEGRITY FOR SUSTAINABLE AFRICA TRANSFORMATION. ANSPOLY JOURNAL OF INNOVATIVE DEVELOPMENT (AJID), 1(2), 30–39.
Kaaria, A. G. (2023). Human Resource Information Systems Information Security and Organizational Performance of Commercial State Corporations in Kenya. East African Journal of Information Technology, 6(1), 256–278.
Karlsson, M., Karlsson, F., Åström, J., & Denk, T. (2022). The effect of perceived organizational culture on employees’ information security compliance. Information & Computer Security, 30(3), 382–401.
Kaur, J., Dhillon, G., & Picoto, W. N. (2021). The role of organizational competence on information security job performance.
Khando, K., Gao, S., Islam, S. M., & Salman, A. (2021). Enhancing employees information security awareness in private and public organisations: A systematic literature review. Computers & Security, 106, 102267. doi:https://doi.org/10.1016/j.cose.2021.102267
Kinnunen, H., & Siponen, M. (2018). Developing organization-specific information security policies by using critical thinking. Paper presented at the Pacific Asia Conference on Information Systems.
Kitsios, F., Chatzidimitriou, E., & Kamariotou, M. (2023). The ISO/IEC 27001 information security management standard: how to extract value from data in the IT sector. Sustainability, 15(7), 5828.
Lin, C., & Luo, X. (2021). Toward a unified view of dynamic information security behaviors: insights from organizational culture and sensemaking. ACM SIGMIS Database: The DATABASE for Advances in Information Systems, 52(1), 65–90.
Lincke, S. (2024). Information Security Planning: A Practical Approach: Springer Nature.
Liu, C., Liang, H., Wang, N., & Xue, Y. (2022). Ensuring employees' information security policy compliance by carrot and stick: the moderating roles of organizational commitment and gender. Information Technology & People, 35(2), 802–834. doi:10.1108/ITP-09-2019-0452
Lopes, A., Reis, L., São Mamede, H., & Santos, A. (2022, 2022//). Information Security Threat Assessment Using Social Engineering in the Organizational Context – Literature Review. Paper presented at the Information Systems and Technologies, Cham.
Ma, X. (2022). IS professionals’ information security behaviors in Chinese IT organizations for information security protection. Information Processing & Management, 59(1), 102744. doi:https://doi.org/10.1016/j.ipm.2021.102744
Marzban, m. h., Sharifzadeh, r., & Poorebrahimi, A. (2025). Identifying the Human-Nonhuman Components of Information Security Culture: A Qualitative Study Based on Actor-Network Theory (ANT). Human Information Interaction, 12(2), 46–70. Retrieved from http://hii.khu.ac.ir/article-1-3225-fa.html. [In Persian]
Mousavi, M. Z., & Kumar, S. (2019). Analysis of key factors for organization information security. Paper presented at the 2019 International Conference on Machine Learning, Big Data, Cloud and Parallel Computing (COMITCon).
Nan, H., Chen, D., & Bing, Z. (2026). Application of fuzzy data mining and network information security based on sensor networks in enterprise human resource management. International Journal of System Assurance Engineering and Management, 1–9.
Nowicka, J., Ciekanowski, Z., & Milewska, A. (2024). Information Security Management as the Basis for the Functioning of an Organization.
Orozova, D., Kaloyanova, K., & Todorova, M. (2019). Introducing information security concepts and standards in higher education. TEM Journal, 8(3), 1017.
Petrič, G., & Orehek, Š. (2024). Expressing opinions about information security in an organization: the spiral of silence theory perspective. Information & Computer Security, ahead-of-print(ahead-of-print). doi:10.1108/ICS-04-2024-0083
Pietrek, G. W., & Skelnik, K. (2023). CYBERSECURITY AND THE SCOPE OF DESIGNING INFORMATION SECURITY SYSTEMS IN THE ORGANIZATION. Journal of Modern Science, 51(2).
Rohan, R., Pal, D., Hautamäki, J., Funilkul, S., Chutimaskul, W., & Thapliyal, H. (2023). A systematic literature review of cybersecurity scales assessing information security awareness. Heliyon, 9(3). doi:10.1016/j.heliyon.2023.e14234
Shafiei Nikabadi, M., Toghi, S., & Hakaki, A. (2021). A Combined Approach of FMEA and Gray Theory to Rank Aspects of Information Security Risk Management. Business Intelligence Management Studies, 9(34), 191–214. doi:10.22054/ims.2020.46866.1602. [In Persian]
Shiau, W.-L., Wang, X., & Zheng, F. (2023). What are the trend and core knowledge of information security? A citation and co-citation analysis. Information & Management, 60(3), 103774. doi:https://doi.org/10.1016/j.im.2023.103774
Shkarlet, S., Lytvynov, V., Dorosh, M., Trunova, E., & Voitsekhovska, M. (2020, 2020//). The Model of Information Security Culture Level Estimation of Organization. Paper presented at the Mathematical Modeling and Simulation of Systems, Cham.
Stanojević, M., & Izgarević, D. (2025). THE ROLE OF HUMAN RESOURCE MANAGEMENT IN ENHANCING CORPORATE INFORMATION SECURITY CULTURE. MEGATREND REVIJA MEGATREND REVIEW, 105.
Tahmasebi Limooni, S., & Fallah Kordabadi, M. (2019). IInvestigating the Situation of Information Security Architecture in Mazandaran Public Libraries Based on ISO / IEC 27002 Standard. Digital and Smart Libraries Research, 6(2), 35–50. doi:10.30473/mrs.2020.50639.1412
Talebi, H., & Taboli, H. (2024). Implementing a Structural-Interpretive Model for Information Security Management in Iranian Governmental Organizations: An Art-Islamic Approach. Islamic Art Studies, 21(56), 331–348. doi:10.22034/ias.2021.300790.1696
Varsos, D. S., Giannakou, S. A., & Assimakopoulos, N. A. (2018). A systems approach to information security for the twenty-first century organization. Acta Europeana Systemica, 8, 167–178.
vazife, z., Mahdi, M., & Vakili, N. (2019). Model for Feasibility Study and Effective Deployment of Information Security Management Systems Based on Meta-Synthesis Technique. Business Intelligence Management Studies, 7(26), 71–99. doi:10.22054/ims.2019.9717
Vedadi, A., Warkentin, M., Straub, D. W., & Shropshire, J. (2024). Fostering information security compliance as organizational citizenship behavior. Information & Management, 61(5), 103968. doi:https://doi.org/10.1016/j.im.2024.103968
Wagner, T. L. (2023). Neutralization Techniques’ Effect on US Employees’ Intent to Violate Organizational Information Security Policy: A Quantitative Study. Capella University,
Weng, W. (2024). A Beginner’s Guide to Informatics and Artificial Intelligence. doi:https://doi.org/10.1007/978-981-97-1477-3_9
Yazdanmehr, A., Jawad, M., Benbunan-Fich, R., & Wang, J. (2024). The role of ethical climates in employee information security policy violations. Decision Support Systems, 177, 114086. doi:https://doi.org/10.1016/j.dss.2023.114086
 
Send comment about this article
Enter Name.
Enter a valid email address.
Enter a vaid affiliation.
Enter comments (At leaset 10 words)
CAPTCHA Image
Enter Security Code Correctly.

Articles in Press, Accepted Manuscript
Available Online from 25 July 2026

  • Receive Date 18 April 2026
  • Revise Date 15 May 2026
  • Accept Date 25 July 2026