Our mission is to create a pool of knowledge for effective policy, research & development in Malawi

Information Security Awareness: Generic Content, Tools and Techniques

Type: Computer ScienceThesesMasters Theses
Author: Hope Mauwa
Year of Publishing: 2006
Keywords: Information Security Awareness Programmes, ISO/IEC 17799, ISO/IEC 13335-3
In today’s computing environment, awareness programmes play a much more important role in organizations’ complete information security programmes. Information security awareness programmes are there to change behaviour or reinforce good security practices, and provide a baseline of security knowledge for all information users. Security awareness is a learning process, which changes individual and organizational attitudes and perceptions so that the importance of security and the adverse consequences of its failure are realized. Therefore, with proper awareness, employees become the most effective layer in an organization’s security defence.

With the important role that these awareness programmes play in organizations’ complete information security programmes, it is a must that all organizations that are serious about information security must implement it. But though awareness programmes have become increasing important, the level of awareness in most organizations is still low. It seems that the current approach of developing these programmes does not satisfy the needs of most organizations. Therefore, another approach, which tries to meet the needs of most organizations, is proposed in this project as part of the solution of raising the level of awareness programmes in organizations.


Note: The whole thesis can be downloaded at www.nmmu.ac.za/documents/theses/HOPE%20MAUWA.pdf
F & P