The University of Southampton
University of Southampton Institutional Repository

An information security governance framework for the organisations in the kingdom of Saudi Arabia

An information security governance framework for the organisations in the kingdom of Saudi Arabia
An information security governance framework for the organisations in the kingdom of Saudi Arabia
Due to the ever-changing threats to the confidentiality, integrity and availability of information in an organisation, information security should be addressed from the highest level of the organisation and regarded as a governance challenge that needs effective direction and control. Consequently, information security governance has become essential for organisations to ensure objectives are achieved, risks are managed appropriately, and resources are used responsibly. Although organisations in the Kingdom of Saudi Arabia acknowledge the importance of governing information security for their ability to survive and thrive, there is inadequate implementation of information security governance in the majority of organisations. The absence of the crucial practices for the successful implementation of information security governance addresses the need to investigate the critical success factors for such implementation in the Saudi Arabian organisations. Therefore, this research has developed a framework to support the implementation of information security governance and the Kingdom of Saudi Arabia’s vision of a thriving economy for 2030. The factors in this framework were identified by reviewing the literature as well as industrial best practice frameworks. Based on the review conducted, the proposed framework was developed to understand the practices required to direct and control information security within the governance areas for the organisations to survive and thrive. Once the framework was developed, it was reviewed by interviewing 15 information security governance experts from the Kingdom of Saudi Arabia. After updating the framework according to their recommendations, the framework was confirmed by distributing a questionnaire to 33 practitioners from Saudi organisations. The findings revealed that the factors were statistically significant. Driving from the confirmed framework, an information security governance maturity assessment instrument was developed to measure the maturity level of information security governance implementation in organisations. The instrument was developed by using the Goal Question Metrics approach, after which the instrument content was validated by using the Content Validity Ratio. Subsequently, case studies were conducted in four Saudi organisations in order to evaluate the practicality of the developed instrument. The instrument was used to assess the maturity status of information security governance in Saudi organisations that have started governing their information security as a part of their corporate governance. Afterwards, the practicality of the instrument was evaluated through a questionnaire that was distributed to the committee members who used the instrument and through interviews with the Information Security directors. The findings validate a good level of practicality for the instrument in measuring the maturity of information security governance. This thesis presents a detailed discussion on the development and validation of the information security governance framework and the information security governance maturity assessment instrument.
University of Southampton
Gashgari, Ghada Abdalaziz A
aced4509-d54a-401d-aad9-61c8f97834bf
Gashgari, Ghada Abdalaziz A
aced4509-d54a-401d-aad9-61c8f97834bf
Wills, Gary
3a594558-6921-4e82-8098-38cd8d4e8aa0

Gashgari, Ghada Abdalaziz A (2019) An information security governance framework for the organisations in the kingdom of Saudi Arabia. University of Southampton, Doctoral Thesis, 248pp.

Record type: Thesis (Doctoral)

Abstract

Due to the ever-changing threats to the confidentiality, integrity and availability of information in an organisation, information security should be addressed from the highest level of the organisation and regarded as a governance challenge that needs effective direction and control. Consequently, information security governance has become essential for organisations to ensure objectives are achieved, risks are managed appropriately, and resources are used responsibly. Although organisations in the Kingdom of Saudi Arabia acknowledge the importance of governing information security for their ability to survive and thrive, there is inadequate implementation of information security governance in the majority of organisations. The absence of the crucial practices for the successful implementation of information security governance addresses the need to investigate the critical success factors for such implementation in the Saudi Arabian organisations. Therefore, this research has developed a framework to support the implementation of information security governance and the Kingdom of Saudi Arabia’s vision of a thriving economy for 2030. The factors in this framework were identified by reviewing the literature as well as industrial best practice frameworks. Based on the review conducted, the proposed framework was developed to understand the practices required to direct and control information security within the governance areas for the organisations to survive and thrive. Once the framework was developed, it was reviewed by interviewing 15 information security governance experts from the Kingdom of Saudi Arabia. After updating the framework according to their recommendations, the framework was confirmed by distributing a questionnaire to 33 practitioners from Saudi organisations. The findings revealed that the factors were statistically significant. Driving from the confirmed framework, an information security governance maturity assessment instrument was developed to measure the maturity level of information security governance implementation in organisations. The instrument was developed by using the Goal Question Metrics approach, after which the instrument content was validated by using the Content Validity Ratio. Subsequently, case studies were conducted in four Saudi organisations in order to evaluate the practicality of the developed instrument. The instrument was used to assess the maturity status of information security governance in Saudi organisations that have started governing their information security as a part of their corporate governance. Afterwards, the practicality of the instrument was evaluated through a questionnaire that was distributed to the committee members who used the instrument and through interviews with the Information Security directors. The findings validate a good level of practicality for the instrument in measuring the maturity of information security governance. This thesis presents a detailed discussion on the development and validation of the information security governance framework and the information security governance maturity assessment instrument.

Text
Final Submission Thesis
Restricted to Repository staff only until 20 April 2025.
Available under License University of Southampton Thesis Licence.
Text
Permission to deposit thesis - form
Restricted to Repository staff only

More information

Published date: November 2019

Identifiers

Local EPrints ID: 447759
URI: http://eprints.soton.ac.uk/id/eprint/447759
PURE UUID: 428a4430-d3d5-41f4-a940-eccb4c22134b
ORCID for Gary Wills: ORCID iD orcid.org/0000-0001-5771-4088

Catalogue record

Date deposited: 19 Mar 2021 17:33
Last modified: 17 Mar 2024 02:43

Export record

Contributors

Author: Ghada Abdalaziz A Gashgari
Thesis advisor: Gary Wills ORCID iD

Download statistics

Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.

View more statistics

Atom RSS 1.0 RSS 2.0

Contact ePrints Soton: eprints@soton.ac.uk

ePrints Soton supports OAI 2.0 with a base URL of http://eprints.soton.ac.uk/cgi/oai2

This repository has been built using EPrints software, developed at the University of Southampton, but available to everyone to use.

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we will assume that you are happy to receive cookies on the University of Southampton website.

×