Main Article Content

The Impact of Organizational Culture on Information Security Policy Compliance


Kibrom Ejigu
Mikko Siponen
Tilahun Muluneh

Abstract

The objective of this study is to explore how organizational culture affects employee compliance with information security policies. To accomplish this goal, the authors developed a theoretical model and collected survey data from employees who work in organizations that have information security policies. We employed a quantitative survey research approach. We conducted our study at the commercial bank of Ethiopia (CBE). The collected data was analysed using analysis of moment structures (Cardoso and Ramos) software.  The findings show that organizational culture significantly affects employee compliance with information security policies. Additionally, the study emphasizes the importance of considering the dominant organizational culture when trying to embed an information security policy. The contribution of this study lies in providing empirical evidence of the influence of organizational culture on information security compliance. To limit the scope of the study, the sample used in this research focuses only on organizational factors in Ethiopia. It is recommended that future studies be conducted in other countries to validate the results and ensure the generalizability of the findings. Practically speaking, creating a culture that supports information security practices is crucial for organizations, as technical and management measures alone cannot fully address the human aspect of information security. To better understand and enhance organizational behaviour regarding information security, companies should examine their organizational culture and how it impacts the effectiveness of implementing information security policies.


Journal Identifiers


eISSN: 2520-7997
print ISSN: 0379-2897