TY - JOUR
T1 - Information Security Awareness Raising Strategy Using Fuzzy AHP Method with HAIS-Q and ISO/IEC 27001:2013
T2 - A Case Study of XYZ Financial Institution
AU - Styoutomo, Yohan Adhi
AU - Ruldeviyani, Yova
N1 - Publisher Copyright:
© 2023 CommIT Journal . All rights reserved.
PY - 2023
Y1 - 2023
N2 - XYZ financial institution is a government institution that receives and processes transaction reports from banks and remittances, so its data classification is very confidential. However, during the Work from Home (WFH) policy in the Covid-19 pandemic, XYZ financial institution has received many spam/phishing attacks. Hence, this incident shows that some employees need an awareness of information security. The research offers a different Information Security Awareness (ISA) questionnaire using the Human Aspects of the Information Security Questionnaire (HAIS-Q) and ISO/IEC 27001:2013 as focus areas. The research uses the theory of Knowledge, Attitude, and Behavior (KAB) to determine the dimensions that need improvement and priority ranking using Fuzzy Analytical Hierarchy Process (FAHP). Furthermore, the research conducts a Focus Group Discussion (FGD) to explore the root causes of employee behavior. The FGD results show that there are still employees who do not know about information security, such as password combinations and length, so limited knowledge affects employees’ attitudes and behaviors. The research results from 34 respondents show that the employees’ information security awareness level is in the moderate category (78.8%). They still need to increase their awareness of information security, especially in managing passwords, using email and the Internet, and reporting incidents. Recommendations have been prepared to improve the dimensions and areas that have yet to be categorized as good. In the future, the ISA questionnaire is expected to be used in other organizations.
AB - XYZ financial institution is a government institution that receives and processes transaction reports from banks and remittances, so its data classification is very confidential. However, during the Work from Home (WFH) policy in the Covid-19 pandemic, XYZ financial institution has received many spam/phishing attacks. Hence, this incident shows that some employees need an awareness of information security. The research offers a different Information Security Awareness (ISA) questionnaire using the Human Aspects of the Information Security Questionnaire (HAIS-Q) and ISO/IEC 27001:2013 as focus areas. The research uses the theory of Knowledge, Attitude, and Behavior (KAB) to determine the dimensions that need improvement and priority ranking using Fuzzy Analytical Hierarchy Process (FAHP). Furthermore, the research conducts a Focus Group Discussion (FGD) to explore the root causes of employee behavior. The FGD results show that there are still employees who do not know about information security, such as password combinations and length, so limited knowledge affects employees’ attitudes and behaviors. The research results from 34 respondents show that the employees’ information security awareness level is in the moderate category (78.8%). They still need to increase their awareness of information security, especially in managing passwords, using email and the Internet, and reporting incidents. Recommendations have been prepared to improve the dimensions and areas that have yet to be categorized as good. In the future, the ISA questionnaire is expected to be used in other organizations.
KW - Fuzzy Analytical Hierarchy Process (FAHP)
KW - Human Aspects of the Information Security Questionnaire (HAIS-Q)
KW - Information Security Awareness
KW - ISO/IEC 27001:2013
UR - http://www.scopus.com/inward/record.url?scp=85174516245&partnerID=8YFLogxK
U2 - 10.21512/commit.v17i2.8272
DO - 10.21512/commit.v17i2.8272
M3 - Article
AN - SCOPUS:85174516245
SN - 1979-2484
VL - 17
SP - 133
EP - 149
JO - CommIT Journal
JF - CommIT Journal
IS - 2
ER -