Title
Information Security Practice In Saudi Arabia: Case Study On Saudi Organizations
Abstract
Purpose Information security of an organization is influenced by the deployed policy and procedures. Information security policy reflects the organization's attitude to the protection of its information assets. The purpose of this paper is to investigate the status of the information security policy at a subset of Saudi's organizations by understanding the perceptions of their information technology's employees.Design/methodology/approach A descriptive and statistical approach has been used to describe the collected data and characteristics of the IT employees and managers to understand the information security policy at the surveyed organizations. The author believes that understanding the IT employees' views gives a better understanding of the organization's status of information security policy.Findings It has been found that most of the surveyed organizations have established information security policy and deployed fair technology; however, many of such policies are not enforced and publicized effectively and efficiently which degraded the deployed technology for such protection. In addition, the clarity and the comprehensibility of such policies are questionable as indicated by most of the IT employees' responses. A comparison with similar studies at Middle Eastern and European countries has shown similar findings and shares the same concerns.Originality/value The findings of this research suggest that the Saudi Communications and Information Technology Commission should develop a national framework for information security to guide the governmental and non-governmental organizations as well as the information security practitioners on the good information security practices in terms of policy and procedures to help the organizations to avoid any vulnerability that may lead to violations on the security of their information.
Year
DOI
Venue
2018
10.1108/ICS-01-2018-0006
INFORMATION AND COMPUTER SECURITY
Keywords
DocType
Volume
Information security, Case study, Information security policy, Information security in Saudi Arabia, Information security management, Information security procedures
Journal
26
Issue
ISSN
Citations 
5
2056-4961
0
PageRank 
References 
Authors
0.34
0
1
Name
Order
Citations
PageRank
Zakarya A. Alzamil1141.66