Journal of Information System Security
Volume 6, Number 4 (2010)
Pages 319
ISSN 1551-0123
Kerry-Lynn Thomson — Nelson Mandela Metropolitan University, South Africa
Information Institute Publishing, Washington DC, USA




One of the major difficulties in implementing and ensuring good information security practices in an organisation is, very often, the indifferent or ignorant attitude and behaviour of employees. Employees often do not understand the importance of, and the role they should play in, the protection of information assets in an organisation. This is as a result of the fact that the goals of employees in an organisation are often not aligned with the goals of management. Ideally, the alignment of management and employee goals should occur through the creation of an Information Security Obedient Culture. This paper will explore the flow of knowledge creation, both at an organisational and individual level, which is necessary in the shaping of an Information Security Obedient Culture.




Information Security, Corporate Culture, Knowledge Creation, Information Security Obedience, Information Security Conscience




