Analyzing information security culture: increased trust by an appropriate information security culture

Security culture encompasses all socio-cultural measures that support technical security measures, so that information security becomes a natural aspect in the daily activities of every employee. The cultural concept helps to increase trust between the different actors concerning information security within an organization. We start with the explanation of the "organizational culture concept," asking how it can be used to implement information security culture. To create, maintain and change security culture, certain measuring instruments are necessary. We discuss several ways and methods to analyze organizational culture. Furthermore, we ask to what extent they could be used in the context of security culture and what special problems might arise. Finally, the possible implementation is discussed in the context of an ongoing survey from which we present some results.