Acessibilidade / Reportar erro

RELATIONSHIP BETWEEN CULTURE AND INFORMATION SECURITY: HOW TO AVOID FAILURES ARISING FROM THE “BRAZILIAN WAY”?

Several researchers have sought to understand what drives individuals to comply with information security policies (ISP) defined by organizations. One of these currents argues that culture represents an important factor, highlighting, however, the presence of studies involving organizational culture to the detriment of national culture. Given the cultural specificities of the country, studying the relationship between its cultural aspects and compliance with ISP's can bring insights to information security managers in Brazilian organizations. Thus, the aim of this study was to analyze how the information security culture influences individuals in complying with information security policies and at reducing the occurrence of security failures associated with the “Brazilian way”. The study was carried out through a survey with 196 employees from different Brazilian organizations. The results indicated that the awareness of information security positively influences the individuals' planned behavior and negatively the influence of the “Brazilian way”, both influencing the compliance with the information security standards established by the organization. We also identified a strong relationship between compliance with the rules and the reduction of security failures associated with the “Brazilian way”.

Keywords:
Information Security; Culture; Organizational Culture; National Culture; Brazilian way.


Escola de Administração da UFRGS Escola de Administração da UFRGS, Rua Washington Luis, 855 - 2° Andar, 90010-460 Porto Alegre/RS - Brasil, Fone: (55 51) 3308-3823, Fax: (55 51) 3308 3991 - Porto Alegre - RS - Brazil
E-mail: read@ea.ufrgs.br