Understanding the information security culture of organizations: Results of a Survey

  • Pedro Santos Universidade Federal de Pernambuco
  • Mariana Peixoto Universidade Federal de Pernambuco
  • Jéssyka Vilela Universidade Federal de Pernambuco


A strong information security culture in organizations contributes to reduce incidents related to leaks of sensitive and private information. Considering that one of the main factors that cause such leaks is human action, it is necessary to evaluate the current state of organizations’ culture. This work aims to identify methods for assessing the culture of information security in organizations and to characterize the current state of this topic. We conducted a survey using an evaluation instrument proposed in the literature that includes dimensions to assess the information security culture. The survey received 75 responses, mostly from employees of private institutions. We observed that there is a need for training of employees on information security, and there is incongruity between knowing, understanding and applying the procedures described in the information security policy. This work provided an understanding of the current status of the information security culture in organizations whose results can be expanded and used in future studies to improve security practices in organizations.

Palavras-chave: Information Security, Culture, Survey, ISCA, Organizations.


