<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Reviewing the Interrelation Between Information Security and Culture: Toward an Agenda for Future Research</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sebastian Hengstler</string-name>
          <email>s.hengstler@stud.uni-goettingen.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Natalya Pryazhnykova</string-name>
          <email>pryazhnykova@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>16th International Conference on Wirtschaftsinformatik</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Chair of Information Security and Compliance, University of Goettingen</institution>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <fpage>52</fpage>
      <lpage>77</lpage>
      <abstract>
        <p>The main goal of this paper is to provide a review of existing research on the interrelationships between information security and culture. The results of this study are based on a structured literature review of current research on the interrelationships between information security and culture, published between 2000 and 2020 (September). Our results show that current research has focused on four core themes: (1) the influence of culture on information security policy compliance behavior, (2) information security culture in organizations, (3) the influence of culture on information security awareness programs and (4) the effect of culture on information security governance. Our results show, that so far, the mentioned topics have been investigated from different perspectives. However, our results offer potential for future research, e.g. in the connections between information security and individual cultural values or in the area of information security awareness.</p>
      </abstract>
      <kwd-group>
        <kwd>Information Security and Culture</kwd>
        <kwd>Literature Review</kwd>
        <kwd>Information Security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Information security represents a field of increasing scholarly interest from a practical
and theoretical perspective and includes various critical dimensions, which need to be
considered to ensure a high level of information security e.g. in organizations [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
Important mechanisms to guarantee information security are technical measures, such
as firewalls, to protect networks or various authorization measures for hardware
protection [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        However, it is a well-known fact that attacks on information security systems in
private or professional usage start at the weakest point which is failure caused by an
individual [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. This is the reason, why measures to ensure compliant behavior of
employees in various organizations are becoming increasingly crucial [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        Existing studies analyze a variety of mechanisms that influence the compliance
behavior of employees, such as the social environment of an individual, the use of
informal and formal sanctions to ensure compliance or the use of threat and coping
appraisals [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Furthermore, existing research presents, that contextual differences are
an essential factor to consider, when designing information security measures to
achieve compliance behavior [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Besides the distinction between different types of
information security breaches, culture is an important contextual component of current
information security research [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        Over the last two decades, culture has been analyzed from different angles in the
context of information security and there are different approaches in research, which
aim to explain how these two aspects relate. The results of existing literature reviews
in the field of information security and culture show a variety of different outcomes.
Mahfuth et al. (2017) analyzed existing research regarding information security,
organizational culture and the relation of these two fields. [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Karlsson and Åström
(2015) provide an overview of the research in the area of information security culture
[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. Hina and Dominic (2020) identify information security and culture as current
trending topic in information security research [
        <xref ref-type="bibr" rid="ref53 ref8">8</xref>
        ]. In summary, there are recent
approaches, which analyze the interrelations between information security and culture
from different perspectives. However, we believe that a comprehensive overview that
represents the different perspectives and top themes of information security culture
research is still missing, but can help to provide a more complete view on the relation
of culture and information security [
        <xref ref-type="bibr" rid="ref54 ref9">9</xref>
        ].
      </p>
      <p>
        The aim of this paper is to summarize existing research about information security
and culture in order to increase the understanding of the influence of culture and its
relevance to information security. The scope of this paper is to identify the current
research themes in this field, and to provide further directions for future research. In
our analysis, we build on existing cultural concepts to identify interrelations between
culture and information security research. We used the approach of Leidner and
Kayworth (2006) to analyze the interrelations between culture and information security,
in combination with the process for a structured literature analysis of Webster and
Watson (2002) [
        <xref ref-type="bibr" rid="ref10 ref54 ref55 ref9">9, 10</xref>
        ].
      </p>
      <p>With our research, we aim to contribute to current literature in providing a
comprehensive view on the current state of the interrelation between information
security and culture research. Our study provides an overview not only about analyzed
cultural levels and artefacts, but also used research approaches (methods and theories).
In addition to that, we identified overlapping and less analyzed aspects in existing
research. We identified both major and minor gaps in the literature and provided
implications for further research.</p>
      <p>This study is structured as follows. In section 2, we defined the relevant concepts of
culture we used in our literature analysis. In section 3, the literature analysis process is
explained. We described outcomes of this paper and defined focus themes in
information security and culture research in section 4. An overview about potential
future research is presented in section 5. The paper concludes in section 6.</p>
    </sec>
    <sec id="sec-2">
      <title>The Concept of Culture</title>
      <p>
        In other research areas such as Social Studies or Psychology, culture is understood as a
summary of ideologies, beliefs, basic assumptions, shared norms and values, that have
an influence on the collective will [
        <xref ref-type="bibr" rid="ref11 ref12 ref56 ref57">11, 12</xref>
        ]. Other approaches analyze the construct of
culture from a different perspective and focus on individual cultural dimensions, which
describe the individual components of culture [
        <xref ref-type="bibr" rid="ref13 ref58">13</xref>
        ]. Schein's (1997) three-level model
of culture shows a model to explain culture within organizations [
        <xref ref-type="bibr" rid="ref14 ref59">14</xref>
        ]. Due to these
differences and the fact, that the concept of culture is characterized by its many
meanings and possible interpretations, it is rather challenging to define an overall
definition of the concept of culture [
        <xref ref-type="bibr" rid="ref15 ref60">15</xref>
        ]. The first modern interpretation was made by
Edward Tylor, who described culture as the collection of all skills and habits such as
knowledge, beliefs or laws, which are shaped by society [
        <xref ref-type="bibr" rid="ref16 ref61">16</xref>
        ]. Hofstede specified the
shaping of behavior by society and defined culture as a collective coding of the mind
by which the members of a group distinguish themselves from the members of other
groups [
        <xref ref-type="bibr" rid="ref12 ref57">12</xref>
        ]. Because of the fact that culture includes all rules, norms and the code of
conduct of a collective, it has an influence on the behavior of the individuals of a group
and is consequently controlling behavior [
        <xref ref-type="bibr" rid="ref17 ref62">17</xref>
        ].
      </p>
      <p>
        In the area of information systems, the extent to which these are related to the topic
of culture was also investigated. Leidner and Kayworth (2006), for example, analyzed
different approaches in the area of information systems and culture in terms of their
underlying theoretical cultural artifacts. They pointed out, that a relation between
information systems and these cultural artefacts can occur on several levels of culture.
Examples of this are a connection in the context of IT culture, the IT adoption process
and cultural dependencies in IT management. In their analysis they distinguish between
the national, organizational, and individual levels of analysis and name several cultural
artefacts, which are used in research to analyze the interrelation between culture and
information systems [
        <xref ref-type="bibr" rid="ref54 ref9">9</xref>
        ]. The national unit of analysis is described as the analysis of
cultural orientation, based on a samples nationality, where different countries are
chosen as the object of the study [
        <xref ref-type="bibr" rid="ref12 ref57">12</xref>
        ]. At the organizational level, studies analyze
cultural differences in different organizational units, e.g. in different companies [
        <xref ref-type="bibr" rid="ref14 ref59">14</xref>
        ].
The analysis of smaller groups or individuals describes the study of individual behavior
or within social groups [
        <xref ref-type="bibr" rid="ref18 ref63">18</xref>
        ]. As a subdiscipline of information systems research, we
can relate these findings to current topics in information security research [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]. For
example, topics such as security culture, compliance behavior or security management
can also be identified in the security domain, which show similarities to existing
information systems research in other research streams. To make the results of our
analysis comparable to existing research, we adapt Leidner and Kayworth's (2006)
approach and analyze the identified literature, based on used cultural artifacts and their
level of analysis [
        <xref ref-type="bibr" rid="ref54 ref9">9</xref>
        ].
      </p>
      <p>
        Literature Analysis Process
For the literature analysis we adapt the methodological approach established in the field
of information systems research according to Webster and Watson (2002) [
        <xref ref-type="bibr" rid="ref10 ref55">10</xref>
        ], which
provides a solution for the systematic identification and analysis of relevant literature.
The following plan was used for the consistent implementation of the methodological
approach in our literature analysis. Firstly, the subject area was defined and our target
group for our research was specified. At this point, our intention was to determine the
current state of the research about the influence of culture on information security.
Therefore, we concentrated on research outcomes, that shed light on the connection
between these two topics. The scope of our literature review is to identify central topics
in the interrelation of these research areas. We address mainly specialized scholars
analyzing the effect of culture on information security or scholars interested in
crosscultural research in the field of information security.
      </p>
      <p>
        Secondly, we conceptualized the core elements that will be used for the systematic
categorization of identified literature. In order to classify and analyze the identified
literature with respect to our research purpose, we have transferred the common
characteristics of this research area from existing literature reviews, namely the
methodological approach, cultural level of analysis, underlying theories and considered
cultural artefacts, and used them in the form of a concept matrix for the analysis of our
identified literature [
        <xref ref-type="bibr" rid="ref12 ref13 ref54 ref57 ref58 ref9">9, 12, 13</xref>
        ].Thirdly, we specified characteristics, which we wanted
to analyze, the databases selection and the definition of our search terms.
      </p>
      <p>
        Since research in the field of information security and culture is published in
conference proceedings as well as in international journals, we used different databases.
The databases EbscoHost, Aisel and AbiInform were used to obtain a broad coverage
of both international journals and conference proceedings in our research area. Forward
and backward search was conducted with the database Web-of-Science. Generally,
publications in relevant journals and conferences of information security research were
considered in our analysis. Publications from other disciplines in our research area were
also included if they were of high relevance (e.g. high citation rate). We followed the
orientation of Karlsson and Åström (2015) and considered literature published since
2000 [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. In order to identify potentially relevant literature, we analyzed the keywords,
the abstract and the title of the respective studies. The use of the search queries in the
different databases resulted in a list of 461 publications, including duplicates. After
deleting duplicates and articles with incorrect content that were not in the focus of our
analysis, we received a list of 103 articles to be analyzed. 53 of these articles were
identified in the initial search, 37 in the forward search and 13 in the backward search.
In total, 58 articles where published in information systems or computer science
journals and 45 articles on related conferences. A list of our search terms and constructs
used to classify the results is shown in Table 1.
      </p>
      <p>In a fourth step, we analyzed the identified literature according to the identified
characteristics. We considered articles published between 2000 and 2020
(September). An Overview about the considered articles per journal/conference is
shown in table 2.</p>
      <p>Amount
1
2
9
2
2
15
6
2
2
1
2
1
1
1
1
1
1
2
1
1
1
1
Conference Title
International Conference on Research and Innovation in Information Systems
(ICRIIS)
Pacific Asia Conference on Information Systems (PACIS)
American Conference on Information Systems (AMCIS)
European Conference on Information Systems (ECIS)
International Conference on Information Systems (ICIS)
Human Aspects of Information Security &amp; Assurance (HAISA)
International Social Security Association (ISSA)
International Conference on Information Security and Cryptology (ICISC)
IEEE World Congress On Computer Applications and Information Systems (WCCAIS)
Australian Information Security Management Conference (AISM)
International Carnahan Conference on Security Technology (ICCST)
Conference on Information Security for South Africa (ISSA)
Hawaii International Conference on System Sciences (HICSS)
Wireless Internet Service Providers Conference (WISP)
International Information Management Association Conference (IIMA)
Mediterranean Conference on Information Systems (MCIS)
International Conference for Internet Technology and Secured Transactions (ICITS)
Workshop on Governance of Technology, Information and Policies
European Conference on Information Warfare and Security (ECIW)
International Conference on Availability, Reliability and Security
Amount
1
5
6
4
1
2
3
3
1
6
1
1
1
4
1
1
1
1
1
1</p>
      <p>Finally, the identified topics of existing literature were discussed, and current trends
and further research potential were presented. We describe the last two steps in the
following chapters.
4</p>
    </sec>
    <sec id="sec-3">
      <title>Results</title>
      <p>
        A total of 103 articles were analyzed in this literature review. Among them, 28 articles
examined culture at the national level in the context of information security and 63
examined culture at the organizational level. There were 8 studies that examined culture
at the individual/subunit level in the context of information security. Over 71% of the
studies on the national cultural level used Hofstede's culture dimensions [
        <xref ref-type="bibr" rid="ref12 ref57">12</xref>
        ]. The
organizational level studies often do not use explicit cultural artifacts (68%). The most
represented cultural artifact at the organizational level is Schein's (1992) model of
organizational culture (12%) [
        <xref ref-type="bibr" rid="ref14 ref59">14</xref>
        ]. No explicit cultural artifacts were studied on the
individual/subunit cultural level. Additionally, we categorized the articles by their
scientific approach. Overall, there are two trends which were identified for the
methodological approaches. 23% of the articles rely on conceptual frameworks. 32%
of the identified articles used a questionnaire-based, quantitative methodological
approach. Other methodological approaches are less represented. In terms of used
theories, many articles have a more theory generating nature and do not use an existing
theory (66%) for their studies. The types of theories do not indicate a focus.
      </p>
      <p>Furthermore, we were able to identify overall focus themes within the analyzed
articles dealing with the interrelations between information security and culture: (1) the
influence of culture on information security policy compliance behavior, (2)
information security culture in organizations, (3) the influence of culture on information
security awareness programs and (4) the effect of culture on information security
governance. We were not able to assign three identified articles to the mentioned
articles and did not consider them in more detail. The following chapters describe the
identified focus topics in more detail. A list of the identified and characterized
literature, based on our observed concepts of theories, methods, cultural artifacts, and
cultural level of analysis is listed in the appendix (Tables 4-7).
4.1</p>
      <sec id="sec-3-1">
        <title>The Influence of Culture on Information Security Policy Compliance</title>
      </sec>
      <sec id="sec-3-2">
        <title>Behavior</title>
        <p>
          A total of 30 papers dealt with the influence of culture on information security policy
compliance behavior. 18 of these studies focused on the national cultural level, 11 on
the organizational cultural level, and one on the individual/subunit cultural level. The
majority of the articles used a questionnaire-based, quantitative approach (18), whereas
7 articles chose a qualitative approach. Meta-analyses (1), commentaries (2) typologies
(1), case studies (2), and mixed method approaches (1) are less represented. Most
articles do not explicit use a theory and are more theory generating in nature (11). The
most frequently used theories are the theory of planned behavior (3) and the deterrence
theory (4). Other theories are represented sporadically. At the national cultural level,
13 of 18 articles used Hofstede's cultural dimensions as cultural artifacts [
          <xref ref-type="bibr" rid="ref12 ref57">12</xref>
          ]. At the
organizational level, hardly any culture artifacts have been used.
        </p>
        <p>
          The topic “influence of culture on information security policy compliance behavior
includes articles that primarily focus on the analysis of cultural differences regarding
information security compliance behavior of employees. There is only one study, which
considers individual cultural values when analyzing information security compliance
behavior with respect to cultural differences. On a national cultural level, the research
focus lies in the analysis of the effectiveness of different theoretical mechanisms on
compliance behavior along national cultures. In this area, different theories such as
deterrence theory or the theory of planned behavior are analyzed [
          <xref ref-type="bibr" rid="ref19 ref19 ref20 ref21 ref64 ref64 ref65 ref66">19–21</xref>
          ]. The focus is
mainly on the analysis of 7 different cultures and does not show a big variety [
          <xref ref-type="bibr" rid="ref22 ref67">22</xref>
          ]. On
the organizational culture level, research in this topic area focuses on organizational
concepts that positively influence information security behavior and thereby contribute
to a positive security culture in organizations. For example, knowledge sharing [
          <xref ref-type="bibr" rid="ref23 ref68">23</xref>
          ],
discipline and agility [
          <xref ref-type="bibr" rid="ref24 ref69">24</xref>
          ], and morale within an organization are examined in terms of
their positive impact on behavior [
          <xref ref-type="bibr" rid="ref25 ref70">25</xref>
          ].
4.2
A total amount of 39 papers have dealt with information security culture in
organizations. 32 studies focused on the organizational cultural level, 6 on the
individual/subunit cultural level, and one study on a national cultural level.
Predominantly, conceptual frameworks were developed within the articles (14). There
is also a focus on conducting literature reviews (5), qualitative studies and case studies
(5), and questionnaire-based quantitative studies (7). Most articles do not use explicit
theory and are more theory generating in nature (34). At the organizational cultural
level, Schein's (1992) organizational behavior theory was frequently used (7) [
          <xref ref-type="bibr" rid="ref14 ref59">14</xref>
          ].
Most articles do not mention explicitly cultural artifacts (26).
        </p>
        <p>
          The theme “information security culture in organizations” includes articles, focusing
on concepts and influencing factors of an information security culture within
organizations, namely conceptualization of cultural models, their validation and the
analysis of factors influencing a security culture and their effects. At the individual or
subunit level, the crucial point lies in identifying different cultural subgroups within an
organization, e.g. through different professional backgrounds [
          <xref ref-type="bibr" rid="ref26 ref27 ref71 ref72">26, 27</xref>
          ]. Another aspect
of an information security culture is the analysis of influencing factors on such cultural
subgroups [
          <xref ref-type="bibr" rid="ref28 ref29 ref73 ref74">28, 29</xref>
          ]. On an organizational cultural level, some articles focus on the
analysis of illusory concepts of an organizational culture and their application in the
information security culture domain [
          <xref ref-type="bibr" rid="ref30 ref31 ref32 ref75 ref76 ref77">30–32</xref>
          ]. Another core issue is the analysis of
factors that influence an information security culture [
          <xref ref-type="bibr" rid="ref33 ref34 ref35 ref78 ref79 ref80">33–35</xref>
          ]. Furthermore, similarities
between the traditional view of organizational cultures and an information security
culture are in focus of current research as well [
          <xref ref-type="bibr" rid="ref36 ref37 ref81 ref82">36, 37</xref>
          ]. Other articles concentrate on
the managerial impact on information security culture, such as the role of CISO's [
          <xref ref-type="bibr" rid="ref38 ref83">38</xref>
          ]
or managerial guidelines to lead in a security culture [
          <xref ref-type="bibr" rid="ref31 ref76">31</xref>
          ].
4.3
        </p>
        <p>The Influence of Culture on Information Security Awareness</p>
        <p>
          Programs
The influence of culture on information security awareness (ISA) programs was
covered by a total of 8 articles. There were two studies with a focus on organizational
cultural level, one study on the individual/subunit cultural level and five studies on
national cultural level. Predominantly, mostly questionnaire-based, quantitative studies
were carried out (5). Two articles conducted an experiment for their study and one
article used a qualitative approach. A total of four studies chose Hofstede's culture
dimensions as culture artifacts [
          <xref ref-type="bibr" rid="ref12 ref57">12</xref>
          ]. Other cultural artifacts, such as the organizational
behavior theory [
          <xref ref-type="bibr" rid="ref14 ref59">14</xref>
          ] and aspects from the competing value framework were used as
well [
          <xref ref-type="bibr" rid="ref39 ref84">39</xref>
          ]. In the context of this topic, different ways of approaching information
security and culture were identified. On the one hand, correlations between information
security awareness measures and the security culture of an organization are analyzed.
The authors show that the security culture can have an influence on the individual
awareness behavior of employees [
          <xref ref-type="bibr" rid="ref40 ref85">40</xref>
          ]. On the other hand, there are studies which
investigate the influence of different organizational factors on ISA from different
cultural perspectives. This includes the analysis of the impact of factors, such as
security culture or competing values on the awareness of employees [
          <xref ref-type="bibr" rid="ref41 ref86">41</xref>
          ]. At the
national cultural level, studies have been mainly conducted with the purpose to analyze
the effectiveness of theoretical mechanisms, such as social norms and attitude values
[
          <xref ref-type="bibr" rid="ref41 ref86">41</xref>
          ] or fear appeals [
          <xref ref-type="bibr" rid="ref42 ref87">42</xref>
          ] on information security awareness in different countries.
4.4
        </p>
        <p>The Effect of Culture on Information Security Governance
The effect of culture on information security governance was analyzed by a total of 21
articles. There were 17 studies with a focus on organizational cultural level and 4
studies on national cultural level. Most of the analyzed studies focused on qualitative
research approaches (5) and case studies (6). Most articles did not explicit outline
mentioned theoretical approach or specific used cultural artefacts.</p>
        <p>
          National cultural level studies in this theme focus on analyzing national cultural values
on the effectiveness of security measures [
          <xref ref-type="bibr" rid="ref43 ref88">43</xref>
          ] and what national-level factors need to
be considered while implementing them [
          <xref ref-type="bibr" rid="ref44 ref89">44</xref>
          ]. Other studies at the national level analyze
the influence of national culture on corporate structure [
          <xref ref-type="bibr" rid="ref45 ref90">45</xref>
          ] and information security
risk management [
          <xref ref-type="bibr" rid="ref46 ref91">46</xref>
          ]. At the organizational level of analysis, several focus themes can
be identified.
        </p>
        <p>
          On the one hand, current research is concerned with the relationship between culture
and information security management. This includes the analysis of what effect
management behavior can have on information security and its culture in the
organization [
          <xref ref-type="bibr" rid="ref47 ref48 ref92 ref93">47, 48</xref>
          ] and the influence of culture on information security management
itself [
          <xref ref-type="bibr" rid="ref49 ref94">49</xref>
          ]. Another element is the description of governance structures and their
constituents for information security, considering cultural factors. This consists of the
influence of culture on organizational structures, the implementation of information
security measures [
          <xref ref-type="bibr" rid="ref50 ref95">50</xref>
          ] and the differences within these structures in different
organizations [
          <xref ref-type="bibr" rid="ref51 ref96">51</xref>
          ]. Closely related are articles dealing with the design of information
security policies, predominantly with the consideration of cultural differences [
          <xref ref-type="bibr" rid="ref52 ref53 ref8 ref97">8, 52</xref>
          ].
Another subtopic regarding the effect of culture on information security governance are
Assessments. Articles describe not only the design and validation of assessment tools
for information security culture, but also the implementation of monitoring methods for
information security in a cross-cultural context [
          <xref ref-type="bibr" rid="ref98 ref99">53, 54</xref>
          ].
5
        </p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Directions for Future Research</title>
      <p>Our study examined the current focus of analyses regarding the interrelation of culture
and information security. In our literature review, we identified 103 relevant articles
and were able to identify four focus themes concerning the interrelation between culture
and information security. According to the outcomes of this study, the potential for
further research can be identified.</p>
      <p>
        Within the topic “the influence of culture on information security policy compliance
behavior” there is a strong focus regarding the national cultural level of analysis and
the testing of the effectiveness of various theories in respect of different national
cultures. The focus lies mainly in theories established in security research, such as
deterrence theory or the theory of planned behavior. Additionally, the individual
characteristics of the culture of individual employees have not yet been taken into
account. Future research in the field of the relation of culture and information security
behavior should include: (1) The investigation of further theoretical mechanisms and
their cultural dependency regarding information security behavior, such as theories
explaining the shaping process of behavior by social factors [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]. (2) A focus on the
influence of individual manifestations of cultural artifacts on behavior, in order not to
make assumptions about dependencies between culture and individual behavior based
on only national cultural values [
        <xref ref-type="bibr" rid="ref100">55</xref>
        ].
      </p>
      <p>
        The topic of information security culture in organizations includes articles about the
structure of a security culture within organizations and its influencing factors. Research
in this area could benefit from an increased use of established organizational culture
theories or culture artifacts not only to validate the already developed information
security culture frameworks but also to draw parallels to organizational culture [
        <xref ref-type="bibr" rid="ref35 ref80">35</xref>
        ].
Furthermore, previous studies have predominantly focused on looking at the whole
organization and its security culture. Differences in individual sub-units, such as
different professions or demographic or geographic factors are poorly represented The
focus of future research in this area should therefore provide: (1) A validation of the
previously developed frameworks in the security culture environment, taking into
account established cultural artifacts in the organizational culture domain. (2) A more
specific investigation of security culture in different sub-units of organizations and their
factors influencing each other [
        <xref ref-type="bibr" rid="ref26 ref71">26</xref>
        ].
      </p>
      <p>
        The theme about the influence of culture on information security awareness
programs has been poorly established in current research, with only 8 articles published
Overall, it is visible that the relationships between cultural artifacts and ISA have been
lack of analysis. On a national cultural level, it is evident, that culture has an influence
on ISA. Rather a few studies exist in connection with organizational factors, culture
and ISA, as well as the influence of individual cultural values on ISA. Accordingly, our
proposal for future research in this area broadly determined. We suggest that future
research on the relationship between culture and ISA should focus on: (1) The
interrelationships of culture at the national, organizational, and individual/subunit
levels with ISA, taking into account established ISA approaches, in order to provide
more insights into the interrelationships of these two aspects [
        <xref ref-type="bibr" rid="ref40 ref85">40</xref>
        ].
      </p>
      <p>
        Articles examining the effect of culture on information security governance are
characterized by the study of factors influencing culture on governance structures or
structures of the organization itself. Likewise, a relatively large number of articles on
the influence of culture on information security management can be identified. What
has been less considered so far is the conceptualization and review of methods and tools
for reviewing security measures under consideration of cultural differences in order to
build an international, cross-cultural monitoring of the effectiveness of security
measures [
        <xref ref-type="bibr" rid="ref50 ref95">50</xref>
        ]. Consequently, we suggest that future research focus on the relationship
between cultural artifacts and the conceptualization and review of assessment and
monitoring approaches. Our results are summarized in table 3.
The purpose of this study was to analyze current research on the relationships between
information security and culture. Our study focuses on the interrelationships between
information security and culture and thus represents an extension to existing literature
reviews in the security context. By applying a structural framework, it provides an
overview of the current state of research and its core topics, as well as existing research
gaps. Based on the literature we identified, we were able to identify open points in the
identified core topics and highlight potential for future research. Overall, limitations
remain to be identified in the context of our study. Our findings are limited to the
selected areas of outlets and keywords that we considered in our search for relevant
literature. Future research in specific research areas, will need to be further elaborated
to include a wider scope of other, IS conferences, and journals potentially relevant to
the specific case.
53. Da Veiga, A.: The Influence of Information Security Policies on Information Security
      </p>
      <p>Culture: Illustrated through a Case Study. In: HAISA, pp. 22–33 (2015)
54. Johnsen, S.O., Hansen, C.W., Nordby, Y., Dahl, M.B.: Measurement and Improvement of</p>
      <p>Information Security Culture. Measurement and Control 39, 52–56 (2006)
55. Yoo, B., Donthu, N., Lenartowicz, T.: Measuring Hofstede’s five dimensions of cultural
values at the individual level: Development and validation of CVSCALE. Journal of
international consumer marketing 23, 193–210 (2011)</p>
    </sec>
    <sec id="sec-5">
      <title>Appendix A: Analyzed Articles</title>
      <p>NA
NA
Information Security Culture in Organizations
Paper
(Da Veiga and
Eloff, 2010)
(Amjad et al. 2017)
(Ashenden and
Sasse, 2013)</p>
      <p>Level of
Analysis
Organizational
Organizational
Organizational</p>
      <p>Method
Conceptual
Framework
Literature
Review
Qualitative
Hofstedes Cultural
Dimensions
Cross-Cultural
Framework (CVF)
Hofstedes Cultural
Dimensions
Hofstedes Cultural
Dimensions
Hofstedes Cultural
Dimensions
Organizational behavior
theory (Schein)
NA
NA
Hofstedes Cultural
Dimensions
Organizational behavior
theory (Schein)
Hofstedes Cultural
Dimensions</p>
      <p>NA
NA
NA</p>
      <p>NA
NA
NA
(Da Veiga and
Martins, 2017)
(AlHogail, 2015)
(Lim et al. 2010)</p>
      <p>Organizational
(Van Niekerk and
Von Solms, 2010)
(Dhillon et al.
2016)
(Ruighaver et al.
2007)</p>
      <p>Dimensions of
Organizational
Culture
Organizational
Culture
Framework
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
NA
Theory of cultural
message streams
Organizational Cultural
Framework
NA
(Malcolmson,
2009)
(Ramachandran et
al. 2008)
(Schlienger and
Teufel, 2003)
(Zakaria, 2004)
NA
NA
NA
NA
NA
NA
PMT
NA
NA
NA
NA
NA
OISCM Model
ISCA
Questionnaire
NA
NA
NA
NA
NA
NA
Organizational Cultural
Framework
Organizational Cultural
Framework
NA
Organizational Cultural
Framework
Hofstedes Cultural
Dimensions
NA
Organizational Cultural
Framework
NA
Organizational Cultural
Framework
Organizational Cultural
Framework
The Influence of Culture on Information Security Awareness Programs
Paper
(Lin and
HsienCheng, 2014)
(Plachkinova and
Andrés, 2015)
Organizational
Organizational</p>
      <p>Experiment</p>
      <p>SETA
National
National
Individual</p>
      <p>Experiment
Survey
Survey
NA
NA
NA
HAIS-Q
NA
Competing Value
Framework (Cameron &amp;
Quinn 2006)
Hofstedes Cultural
Dimensions
NA
Organizational Security
Culture Measure.
The Effect of Culture on Information Security Governance
Theory</p>
      <p>Hofstedes Cultural Dimensions
NA
NA
NA
NA
NA
NA
NA
NA
NA
Schein (1992)
(Ali and National Conceptual
Brooks, 2009) Framework
(Hu et al. 2012) Organizational Survey
(D Arcy et al.
2007)
(Lapke and
Dhillon, 2008)
(Hina et al.
2020)
(Corriss, 2010)
(Dojkovski et
al. 2007)
(Ghernaouti et
al. 2010)
(Johnsen et al.
2006)
(Luo et al.
2009)
NA
Broken
Window
Theory
NA
NA
NA
NA</p>
      <p>Straub 2002
NA
Circuits of Power (Clegg 2002)
NA
NA
NA
NA
Hudson (2002)
Hofstedes Cultural Dimensions</p>
    </sec>
    <sec id="sec-6">
      <title>Appendix B: Identified Articles</title>
      <p>Lin, H.-C.: An investigation of the effects of cultural differences on physicians’ perceptions of
information technology acceptance as they relate to knowledge management systems. Computers
in Human Behavior 38, 368–380 (2014)
Werlinger, R., Hawkey, K., Beznosov, K.: An integrated view of human, organizational, and
technological challenges of IT security management. Info Mngmnt &amp; Comp Security 17, 4–19
(2009)
Veiga, A.D., Eloff, J.H.P.: An Information Security Governance Framework. Information
Systems Management 24, 361–372 (2007)
Mahfuth, A., Yussof, S., Baker, A.A., Ali, N.'a.: A systematic literature review: Information
security culture. In: Social transformation through data science. ICRIIS 2017 : 5th International
Conference on Research and Innovation in Information Systems : Adya Hotel, Langkawi, Kedah,
16-17th July 2017, pp. 1–6. IEEE, Piscataway, NJ (2017)
Da Veiga, A., Eloff, J.H.P.: A framework and assessment instrument for information security
culture. Computers &amp; Security 29, 196–207 (2010)
Amankwa, E., Loock, M., Kritzinger, E.: Establishing information security policy compliance
culture in organizations. Info and Computer Security 26, 420–436 (2018)
J. Malcolmson: What is security culture? Does it differ in content from general organisational
culture? In: 43rd Annual 2009 International Carnahan Conference on Security Technology, pp.
361–366 (2009)</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1. Moody, G.D.,
          <string-name>
            <surname>Siponen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pahnila</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Toward a Unified Model of Information Security Policy Compliance</article-title>
          .
          <source>MIS Quarterly</source>
          <volume>42</volume>
          ,
          <fpage>285</fpage>
          -
          <lpage>311</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>D</given-names>
            <surname>'Arcy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Hovav</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          :
          <article-title>Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures</article-title>
          .
          <source>Journal of Business Ethics</source>
          <volume>89</volume>
          ,
          <fpage>59</fpage>
          -
          <lpage>71</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Siponen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vance</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Neutralization: New Insights into the Problem of Employee Information Systems Security Policy Violations</article-title>
          .
          <source>MIS Quarterly</source>
          <volume>34</volume>
          ,
          <issue>487</issue>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Puhakainen</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Siponen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : Improving Employees'
          <source>Compliance Through Information Systems Security Training: An Action Research Study. MIS Quarterly</source>
          <volume>34</volume>
          ,
          <issue>757</issue>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Aurigemma</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mattson</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Generally Speaking, Context Matters: Making the Case for a Change from Universal to Particular ISP Research</article-title>
          .
          <source>Journal of the Association for Information Systems</source>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Karlsson</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Åström</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Karlsson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Information security culture - state-of-the-art review between 2000 and 2013</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>23</volume>
          ,
          <fpage>246</fpage>
          -
          <lpage>285</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Mahfuth</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yussof</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Baker</surname>
            ,
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ali</surname>
          </string-name>
          , N.'
          <article-title>a.: A systematic literature review: Information security culture</article-title>
          . In:
          <article-title>Social transformation through data science</article-title>
          .
          <source>ICRIIS 2017 : 5th International Conference on Research and Innovation in Information Systems : Adya Hotel</source>
          , Langkawi, Kedah,
          <fpage>16</fpage>
          -17th
          <source>July</source>
          <year>2017</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . IEEE, Piscataway, NJ (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Hina</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dominic</surname>
          </string-name>
          , P.D.D.:
          <article-title>Information security policies' compliance: a perspective for higher education institutions</article-title>
          .
          <source>Journal of Computer Information Systems</source>
          <volume>60</volume>
          ,
          <fpage>201</fpage>
          -
          <lpage>211</lpage>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Leidner</surname>
            ,
            <given-names>D.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kayworth</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Review: a review of culture in information systems research: toward a theory of information technology culture conflict</article-title>
          .
          <source>MIS Quarterly</source>
          <volume>30</volume>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Jane</surname>
            <given-names>Webster</given-names>
          </string-name>
          , Richard T. Watson:
          <article-title>Analyzing the Past to Prepare for the Future: Writing a Literature Review</article-title>
          .
          <source>MIS Quarterly</source>
          <volume>26</volume>
          (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Straub</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Loch</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Evaristo</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Karahanna</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Srite</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Toward a Theory-Based Measurement of Culture</article-title>
          .
          <source>Journal of Global Information Management</source>
          <volume>10</volume>
          ,
          <fpage>13</fpage>
          -
          <lpage>23</lpage>
          (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Hofstede</surname>
          </string-name>
          , G.:
          <article-title>Culture's consequences. Comparing values, behaviors, institutions, and organizations across nations</article-title>
          .
          <source>Sage Publ, Thousand Oaks</source>
          , Calif. (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Nonaka</surname>
          </string-name>
          , I.:
          <article-title>A Dynamic Theory of Organizational Knowledge Creation</article-title>
          .
          <source>Organization Science</source>
          <volume>5</volume>
          ,
          <fpage>14</fpage>
          -
          <lpage>37</lpage>
          (
          <year>1994</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Schein</surname>
            ,
            <given-names>E.H.</given-names>
          </string-name>
          :
          <article-title>Organizational culture and leadership</article-title>
          . Jossey-Bass, San Francisco (
          <year>1997</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Sabel</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rietz</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          : Interkulturelle Kompetenz:
          <article-title>Einfluss der Kultur auf das internationale Management. Einfluss der Kultur auf das internationale Management</article-title>
          . Diplomica Verlag GmbH, Hamburg (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Tylor</surname>
            ,
            <given-names>E.B.</given-names>
          </string-name>
          :
          <article-title>Primitive culture. Researches into the development of mythology, philosophy, religion, art, and custom</article-title>
          . Cambridge Univ. Press, Cambridge (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17. Keller, E. von: Die kulturvergleichende Managementforschung. Gegenstand, Ziele, Methoden, Ergebnisse und Erkenntnisprobleme einer Forschungsrichtung. Haupt, Bern (
          <year>1982</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Karahanna</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Evaristo</surname>
            ,
            <given-names>J.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Srite</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Levels of Culture and Individual Behavior</article-title>
          .
          <source>Journal of Global Information Management</source>
          <volume>13</volume>
          ,
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Dinev</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nam</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>User behaviour towards protective information technologies: the role of national cultural differences</article-title>
          .
          <source>Info Systems J</source>
          <volume>19</volume>
          ,
          <fpage>391</fpage>
          -
          <lpage>412</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Hovav</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          :
          <article-title>Applying an extended model of deterrence across cultures: An investigation of information systems misuse in the U.S. and South Korea</article-title>
          .
          <source>Information &amp; Management</source>
          <volume>49</volume>
          ,
          <fpage>99</fpage>
          -
          <lpage>110</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Hovav</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>A Cross-Cultural Analysis of Security Countermeasure Effectiveness</article-title>
          .
          <source>In: WISP</source>
          <year>2007</year>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Cram</surname>
            ,
            <given-names>W.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Proudfoot</surname>
            ,
            <given-names>J.G.</given-names>
          </string-name>
          :
          <article-title>Seeing the Forest and the Trees: A Meta-Analysis of the Antecedents to Information Security Policy Compliance</article-title>
          .
          <source>MISQ 43</source>
          ,
          <fpage>525</fpage>
          -
          <lpage>554</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <given-names>Rocha</given-names>
            <surname>Flores</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            ,
            <surname>Antonsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            ,
            <surname>Ekstedt</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          :
          <article-title>Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>43</volume>
          ,
          <fpage>90</fpage>
          -
          <lpage>110</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>AlKalbani</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Deng</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kam</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Organisational Security Culture and Information Security Compliance for E-Government Development: The Moderating Effect of Social Pressure</article-title>
          . In: PACIS, p.
          <volume>65</volume>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Amankwa</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Loock</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kritzinger</surname>
          </string-name>
          , E.:
          <article-title>Establishing information security policy compliance culture in organizations</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>26</volume>
          ,
          <fpage>420</fpage>
          -
          <lpage>436</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Ramachandran</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rao</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goles</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dhillon</surname>
          </string-name>
          , G.:
          <article-title>Variations in Information Security Cultures across Professions: A Qualitative Study</article-title>
          .
          <source>CAIS 33</source>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Ramachandran</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rao</surname>
            ,
            <given-names>S.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goles</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Information Security Cultures of Four Professions: A Comparative Study</article-title>
          .
          <source>In: Proceedings of the 41st Annual Hawaii International Conference on System Sciences (HICSS</source>
          <year>2008</year>
          ), p.
          <fpage>454</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2008</year>
          - 2008)
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28. van Niekerk,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Solms</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>von: A holistic framework for the fostering of an information security sub-culture in organizations</article-title>
          .
          <source>In: Issa</source>
          ,
          <volume>1</volume>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martins</surname>
          </string-name>
          , N.:
          <article-title>Defining and identifying dominant information security cultures and subcultures</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>70</volume>
          ,
          <fpage>72</fpage>
          -
          <lpage>94</lpage>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          30.
          <string-name>
            <surname>Nel</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drevin</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Key elements of an information security culture in organisations</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>27</volume>
          ,
          <fpage>146</fpage>
          -
          <lpage>164</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          31. van Niekerk,
          <string-name>
            <given-names>J.F.</given-names>
            ,
            <surname>Solms</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>von: Information security culture: A management perspective</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>29</volume>
          ,
          <fpage>476</fpage>
          -
          <lpage>486</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          32.
          <string-name>
            <surname>Williams</surname>
            ,
            <given-names>P.A.</given-names>
          </string-name>
          :
          <article-title>What Does Security Culture Look Like For Small Organizations? Security Research Institute (SRI)</article-title>
          , Edith Cowan University (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          33. Al Natheer,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Chan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>Nelson</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.</surname>
          </string-name>
          :
          <article-title>Understanding and measuring information security culture (</article-title>
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          34.
          <string-name>
            <surname>Dojkovski</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lichtenstein</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warren</surname>
            ,
            <given-names>M.J.</given-names>
          </string-name>
          :
          <article-title>Fostering information security culture in small and medium size enterprises: an interpretive study in Australia (</article-title>
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          35.
          <string-name>
            <surname>Dhillon</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Syed</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pedron</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          :
          <article-title>Interpreting information security culture: An organizational transformation case study</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>56</volume>
          ,
          <fpage>63</fpage>
          -
          <lpage>69</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          36.
          <string-name>
            <surname>Ruighaver</surname>
            ,
            <given-names>A.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maynard</surname>
            ,
            <given-names>S.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chang</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Organisational security culture: Extending the end-user perspective</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>26</volume>
          ,
          <fpage>56</fpage>
          -
          <lpage>62</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          37.
          <string-name>
            <surname>Ruighaver</surname>
            ,
            <given-names>A.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maynard</surname>
            ,
            <given-names>S.B.</given-names>
          </string-name>
          :
          <article-title>Organizational Security Culture: More Than Just an EndUser Phenomenon</article-title>
          . In:
          <string-name>
            <surname>Fischer-Hübner</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rannenberg</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yngström</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lindskog</surname>
          </string-name>
          , S. (eds.) Security and Privacy in Dynamic Environments, pp.
          <fpage>425</fpage>
          -
          <lpage>430</lpage>
          . Springer US, Boston, MA (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          38.
          <string-name>
            <surname>Ashenden</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sasse</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>CISOs and organisational culture: Their own worst enemy?</article-title>
          <source>Computers &amp; Security</source>
          <volume>39</volume>
          ,
          <fpage>396</fpage>
          -
          <lpage>405</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          39.
          <string-name>
            <surname>Cameron</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quinn</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          , DeGraff, J.,
          <string-name>
            <surname>Thakor</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Competing Values Leadership</article-title>
          . Edward Elgar Publishing (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          40. Wiley,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>McCormac</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Calic</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          :
          <article-title>More than the individual: Examining the relationship between culture and Information Security Awareness</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>88</volume>
          ,
          <issue>101640</issue>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          41.
          <string-name>
            <surname>Lin</surname>
          </string-name>
          , H.-C.:
          <article-title>An investigation of the effects of cultural differences on physicians' perceptions of information technology acceptance as they relate to knowledge management systems</article-title>
          .
          <source>Computers in Human Behavior</source>
          <volume>38</volume>
          ,
          <fpage>368</fpage>
          -
          <lpage>380</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          42.
          <string-name>
            <surname>M. Karjalainen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Siponen</surname>
            , Petri Puhakainen,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Sarker: One Size Does Not Fit All: Different Cultures Require Different Information Systems Security</surname>
          </string-name>
          <article-title>Interventions</article-title>
          . In: PACIS (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          43.
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hovav</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Galletta</surname>
            ,
            <given-names>D.:</given-names>
          </string-name>
          <article-title>User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach</article-title>
          .
          <source>Information Systems Research</source>
          <volume>20</volume>
          ,
          <fpage>79</fpage>
          -
          <lpage>98</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          44.
          <string-name>
            <surname>Shaaban</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Conrad</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Democracy, culture and information security: a case study in Zanzibar</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>21</volume>
          ,
          <fpage>191</fpage>
          -
          <lpage>201</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref45">
        <mixed-citation>
          45.
          <string-name>
            <surname>Ali</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brooks</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>A situated cultural approach for cross‐cultural studies in IS</article-title>
          .
          <source>Journal of Enterprise Information Management</source>
          <volume>22</volume>
          ,
          <fpage>548</fpage>
          -
          <lpage>563</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref46">
        <mixed-citation>
          46.
          <string-name>
            <surname>Tsohou</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Karyda</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kokolakis</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiountouzis</surname>
          </string-name>
          , E.:
          <article-title>Formulating information systems risk management strategies through cultural theory</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>14</volume>
          ,
          <fpage>198</fpage>
          -
          <lpage>217</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref47">
        <mixed-citation>
          47.
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dinev</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hart</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cooke</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Managing Employee Compliance with Information Security Policies: The Critical Role of Top Management and Organizational Culture*</article-title>
          .
          <source>Decision Sciences</source>
          <volume>43</volume>
          ,
          <fpage>615</fpage>
          -
          <lpage>660</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref48">
        <mixed-citation>
          48.
          <string-name>
            <surname>Knapp</surname>
            ,
            <given-names>K.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marshall</surname>
            ,
            <given-names>T.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kelly</surname>
            <given-names>Rainer</given-names>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Nelson</given-names>
            <surname>Ford</surname>
          </string-name>
          ,
          <string-name>
            <surname>F.</surname>
          </string-name>
          :
          <article-title>Information security: management's effect on culture and policy</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>14</volume>
          ,
          <fpage>24</fpage>
          -
          <lpage>36</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref49">
        <mixed-citation>
          49.
          <string-name>
            <surname>Werlinger</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hawkey</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Beznosov</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>An integrated view of human, organizational, and technological challenges of IT security management</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>17</volume>
          ,
          <fpage>4</fpage>
          -
          <lpage>19</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref50">
        <mixed-citation>
          50.
          <string-name>
            <given-names>Da</given-names>
            <surname>Veiga</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Eloff</surname>
          </string-name>
          ,
          <string-name>
            <surname>J.H.P.:</surname>
          </string-name>
          <article-title>A framework and assessment instrument for information security culture</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>29</volume>
          ,
          <fpage>196</fpage>
          -
          <lpage>207</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref51">
        <mixed-citation>
          51.
          <string-name>
            <surname>Dojkovski</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lichtenstein</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warren</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Developing information security culture in small and medium size enterprises: Australian case studies</article-title>
          .
          <source>In: ECIW2008-7th European Conference on Information Warfare and Security: ECIW2008</source>
          . Reading: Academic Conferences Limited, pp.
          <fpage>55</fpage>
          -
          <lpage>66</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref52">
        <mixed-citation>
          52.
          <string-name>
            <surname>Lapke</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <source>Power Relationships in Information Systems Security Policy Formulation and Implementation</source>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref53">
        <mixed-citation>
          8.
          <string-name>
            <surname>Bess</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Understanding information security culture for strategic use: a case study</article-title>
          .
          <source>AMCIS 2009 Proceedings</source>
          ,
          <volume>219</volume>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref54">
        <mixed-citation>
          9.
          <string-name>
            <surname>Alnatheer</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nelson</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Proposed framework for understanding information security culture and practices in the Saudi context (</article-title>
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref55">
        <mixed-citation>
          10.
          <string-name>
            <surname>AlHogail</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mirza</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Information security culture: A definition and a literature review</article-title>
          .
          <source>In: 2014 World Congress on Computer Applications and Information Systems (WCCAIS)</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          . IEEE (
          <year>2014</year>
          - 2014)
        </mixed-citation>
      </ref>
      <ref id="ref56">
        <mixed-citation>
          11.
          <string-name>
            <surname>AlHogail</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mirza</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>A FRAMEWORK OF INFORMATION SECURITY CULTURE CHANGE</article-title>
          .
          <source>Journal of Theoretical &amp; Applied Information Technology</source>
          <volume>64</volume>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref57">
        <mixed-citation>
          12.
          <string-name>
            <surname>Zakaria</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          :
          <article-title>Internalisation of Information Security Culture amongst Employees through Basic Security Knowledge</article-title>
          . In:
          <string-name>
            <surname>Fischer-Hübner</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rannenberg</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yngström</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lindskog</surname>
          </string-name>
          , S. (eds.) Security and Privacy in Dynamic Environments, pp.
          <fpage>437</fpage>
          -
          <lpage>441</lpage>
          . Springer US, Boston, MA (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref58">
        <mixed-citation>
          13. van Niekerk,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Solms</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>von: Understanding Information Security Culture: A Conceptual Framework</article-title>
          . In: ISSA, pp.
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref59">
        <mixed-citation>
          14. van Niekerk,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Solms</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>von: A holistic framework for the fostering of an information security sub-culture in organizations</article-title>
          .
          <source>In: Issa</source>
          ,
          <volume>1</volume>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref60">
        <mixed-citation>
          15.
          <string-name>
            <given-names>Ernest</given-names>
            <surname>Chang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            ,
            <surname>Lin</surname>
          </string-name>
          , C.‐S.:
          <article-title>Exploring organizational culture for information security management</article-title>
          .
          <source>Industr Mngmnt &amp; Data Systems</source>
          <volume>107</volume>
          ,
          <fpage>438</fpage>
          -
          <lpage>458</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref61">
        <mixed-citation>
          16.
          <string-name>
            <surname>Martins</surname>
          </string-name>
          , N.,
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>An Information Security Culture Model Validated with Structural Equation Modelling</article-title>
          . In: HAISA, pp.
          <fpage>11</fpage>
          -
          <lpage>21</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref62">
        <mixed-citation>
          17.
          <string-name>
            <surname>Dojkovski</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lichtenstein</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warren</surname>
            ,
            <given-names>M.J.</given-names>
          </string-name>
          :
          <article-title>Fostering information security culture in small and medium size enterprises: an interpretive study in Australia (</article-title>
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref63">
        <mixed-citation>
          18.
          <string-name>
            <given-names>Da</given-names>
            <surname>Veiga</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          :
          <article-title>The Influence of Information Security Policies on Information Security Culture: Illustrated through a Case Study</article-title>
          .
          <source>In: HAISA</source>
          , pp.
          <fpage>22</fpage>
          -
          <lpage>33</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref64">
        <mixed-citation>
          19.
          <string-name>
            <surname>Dinev</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nam</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>User behaviour towards protective information technologies: the role of national cultural differences</article-title>
          .
          <source>Info Systems J</source>
          <volume>19</volume>
          ,
          <fpage>391</fpage>
          -
          <lpage>412</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref65">
        <mixed-citation>
          20.
          <string-name>
            <surname>Martins</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Da</surname>
            <given-names>Veiga</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Eloff</surname>
          </string-name>
          ,
          <string-name>
            <surname>J.H.P.</surname>
          </string-name>
          :
          <article-title>Information security culture-validation of an assessment instrument</article-title>
          .
          <source>Southern African Business Review</source>
          <volume>11</volume>
          ,
          <fpage>147</fpage>
          -
          <lpage>166</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref66">
        <mixed-citation>
          21.
          <string-name>
            <surname>McCoy</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Galletta</surname>
            ,
            <given-names>D.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>King</surname>
            ,
            <given-names>W.R.</given-names>
          </string-name>
          :
          <article-title>Integrating National Culture into IS Research: The Need for Current Individual Level Measures</article-title>
          .
          <source>CAIS</source>
          <volume>15</volume>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref67">
        <mixed-citation>
          22.
          <string-name>
            <surname>Ramachandran</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rao</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goles</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dhillon</surname>
          </string-name>
          , G.:
          <article-title>Variations in Information Security Cultures across Professions: A Qualitative Study</article-title>
          .
          <source>CAIS 33</source>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref68">
        <mixed-citation>
          23.
          <string-name>
            <surname>Dinev</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nam</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>User behaviour towards protective information technologies: the role of national cultural differences</article-title>
          .
          <source>Info Systems J</source>
          <volume>19</volume>
          ,
          <fpage>391</fpage>
          -
          <lpage>412</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref69">
        <mixed-citation>
          24.
          <string-name>
            <surname>Lacey</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Understanding and transforming organizational security culture</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>18</volume>
          ,
          <fpage>4</fpage>
          -
          <lpage>13</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref70">
        <mixed-citation>
          25. Al Natheer,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Chan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>Nelson</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.</surname>
          </string-name>
          :
          <article-title>Understanding and measuring information security culture (</article-title>
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref71">
        <mixed-citation>
          26.
          <string-name>
            <surname>Vroom</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Solms</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <article-title>von: Towards information security behavioural compliance</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>23</volume>
          ,
          <fpage>191</fpage>
          -
          <lpage>198</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref72">
        <mixed-citation>
          27.
          <string-name>
            <surname>Pienta</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pu</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Purvis</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          :
          <article-title>The Impact of Culture on Information Security: Exploring the Tension of Flexibility and Control</article-title>
          .
          <source>In: ICIS</source>
          <year>2017</year>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref73">
        <mixed-citation>
          28.
          <string-name>
            <surname>Menard</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warkentin</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lowry</surname>
            ,
            <given-names>P.B.</given-names>
          </string-name>
          :
          <article-title>The impact of collectivism and psychological ownership on protection motivation: A cross-cultural examination</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>75</volume>
          ,
          <fpage>147</fpage>
          -
          <lpage>166</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref74">
        <mixed-citation>
          29.
          <string-name>
            <surname>Harnesk</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lindström</surname>
          </string-name>
          , J.:
          <article-title>Shaping security behaviour through discipline and agility</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>19</volume>
          ,
          <fpage>262</fpage>
          -
          <lpage>276</lpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref75">
        <mixed-citation>
          30.
          <string-name>
            <given-names>Rocha</given-names>
            <surname>Flores</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            ,
            <surname>Ekstedt</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          :
          <article-title>Shaping intention to resist social engineering through transformational leadership, information security culture and awareness</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>59</volume>
          ,
          <fpage>26</fpage>
          -
          <lpage>44</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref76">
        <mixed-citation>
          31.
          <string-name>
            <surname>Kolkowska</surname>
          </string-name>
          , E.:
          <article-title>Security subcultures in an organization-exploring value conflicts</article-title>
          .
          <source>In: ECIS 2011 Proceedings. 243</source>
          . (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref77">
        <mixed-citation>
          32.
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Greene</surname>
          </string-name>
          , G.:
          <article-title>Security culture and the employment relationship as drivers of employees' security compliance</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>22</volume>
          ,
          <fpage>474</fpage>
          -
          <lpage>489</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref78">
        <mixed-citation>
          33.
          <string-name>
            <surname>Ruighaver</surname>
            ,
            <given-names>A.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maynard</surname>
            ,
            <given-names>S.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chang</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Organisational security culture: Extending the enduser perspective</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>26</volume>
          ,
          <fpage>56</fpage>
          -
          <lpage>62</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref79">
        <mixed-citation>
          34.
          <string-name>
            <surname>AlKalbani</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Deng</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kam</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Organisational Security Culture and Information Security Compliance for E-Government Development: The Moderating Effect of Social Pressure</article-title>
          . In: PACIS, p.
          <volume>65</volume>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref80">
        <mixed-citation>
          35.
          <string-name>
            <surname>M. Karjalainen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Siponen</surname>
            , Petri Puhakainen,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Sarker: One Size Does Not Fit All: Different Cultures Require Different Information Systems Security</surname>
          </string-name>
          <article-title>Interventions</article-title>
          . In: PACIS (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref81">
        <mixed-citation>
          36.
          <string-name>
            <given-names>Rocha</given-names>
            <surname>Flores</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            ,
            <surname>Holm</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            ,
            <surname>Nohlberg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Ekstedt</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          :
          <article-title>Investigating personal determinants of phishing and the effect of national culture</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>23</volume>
          ,
          <fpage>178</fpage>
          -
          <lpage>199</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref82">
        <mixed-citation>
          37.
          <string-name>
            <surname>Dhillon</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Syed</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pedron</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          :
          <article-title>Interpreting information security culture: An organizational transformation case study</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>56</volume>
          ,
          <fpage>63</fpage>
          -
          <lpage>69</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref83">
        <mixed-citation>
          38.
          <string-name>
            <surname>Harris</surname>
            ,
            <given-names>A.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yates</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Harris</surname>
            ,
            <given-names>J.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Quaresma</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          :
          <article-title>Information System Ethical Attitudes: A Cultural Comparison of the United States, Spain, and Portugal</article-title>
          . In: AMCIS, p.
          <volume>234</volume>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref84">
        <mixed-citation>
          39.
          <string-name>
            <surname>Knapp</surname>
            ,
            <given-names>K.J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marshall</surname>
            ,
            <given-names>T.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kelly</surname>
            <given-names>Rainer</given-names>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Nelson</given-names>
            <surname>Ford</surname>
          </string-name>
          ,
          <string-name>
            <surname>F.</surname>
          </string-name>
          :
          <article-title>Information security: management's effect on culture and policy</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>14</volume>
          ,
          <fpage>24</fpage>
          -
          <lpage>36</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref85">
        <mixed-citation>
          40.
          <string-name>
            <surname>Thomson</surname>
          </string-name>
          , K.-L.,
          <string-name>
            <surname>Solms</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          <article-title>von: Information security obedience: a definition</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>24</volume>
          ,
          <fpage>69</fpage>
          -
          <lpage>75</lpage>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref86">
        <mixed-citation>
          41.
          <string-name>
            <given-names>Rocha</given-names>
            <surname>Flores</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            ,
            <surname>Antonsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            ,
            <surname>Ekstedt</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          :
          <article-title>Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>43</volume>
          ,
          <fpage>90</fpage>
          -
          <lpage>110</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref87">
        <mixed-citation>
          42. van Niekerk,
          <string-name>
            <given-names>J.F.</given-names>
            ,
            <surname>Solms</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>von: Information security culture: A management perspective</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>29</volume>
          ,
          <fpage>476</fpage>
          -
          <lpage>486</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref88">
        <mixed-citation>
          43.
          <string-name>
            <surname>Karlsson</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Åström</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Karlsson</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Information security culture - state-of-the-art review between 2000 and 2013</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>23</volume>
          ,
          <fpage>246</fpage>
          -
          <lpage>285</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref89">
        <mixed-citation>
          44.
          <string-name>
            <surname>Connolly</surname>
            ,
            <given-names>L.Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lang</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wall</surname>
            ,
            <given-names>D.S.</given-names>
          </string-name>
          :
          <article-title>Information Security Behavior: A Cross-Cultural Comparison of Irish and US Employees</article-title>
          .
          <source>Information Systems Management</source>
          <volume>36</volume>
          ,
          <fpage>306</fpage>
          -
          <lpage>322</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref90">
        <mixed-citation>
          45. Tilahun Muluneh Arage, France Bélanger, Tibebe Beshah:
          <article-title>Influence of National Culture on Employees' Compliance with Information Systems Security (ISS) Policies: Towards ISS Culture in Ethiopian Companies</article-title>
          . In: AMCIS (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref91">
        <mixed-citation>
          46.
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martins</surname>
          </string-name>
          , N.:
          <article-title>Improving the information security culture through monitoring and implementation actions illustrated through a case study</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>49</volume>
          ,
          <fpage>162</fpage>
          -
          <lpage>176</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref92">
        <mixed-citation>
          47.
          <string-name>
            <surname>Plachkinova</surname>
          </string-name>
          , Miloslava and Andrés, Steven: Improving Information Security Training:
          <article-title>An Intercultural Perspective</article-title>
          .
          <source>In: PACIS 2015 Proceedings</source>
          <volume>167</volume>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref93">
        <mixed-citation>
          48.
          <string-name>
            <surname>Tsohou</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Karyda</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kokolakis</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiountouzis</surname>
          </string-name>
          , E.:
          <article-title>Formulating information systems risk management strategies through cultural theory</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>14</volume>
          ,
          <fpage>198</fpage>
          -
          <lpage>217</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref94">
        <mixed-citation>
          49.
          <string-name>
            <surname>Yayla</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>ENFORCING INFORMATION SECURITY POLICIES THROUGH CULTURAL BOUNDARIES: A MULTINATIONAL COMPANY APPROACH</article-title>
          . In: ECIS
          <source>2011 Proceedings. 243</source>
          . (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref95">
        <mixed-citation>
          50.
          <string-name>
            <surname>Lim</surname>
            ,
            <given-names>J.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ahmad</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chang</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Maynard</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Embedding Information Security Culture Emerging Concerns and Challenges</article-title>
          .
          <source>In: PACIS 2010 Proceedings. 43</source>
          . (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref96">
        <mixed-citation>
          51.
          <string-name>
            <surname>AlHogail</surname>
          </string-name>
          , A.:
          <article-title>Design and validation of information security culture framework</article-title>
          .
          <source>Computers in Human Behavior</source>
          <volume>49</volume>
          ,
          <fpage>567</fpage>
          -
          <lpage>575</lpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref97">
        <mixed-citation>
          52.
          <string-name>
            <surname>Shaaban</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Conrad</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Democracy, culture and information security: a case study in Zanzibar</article-title>
          .
          <source>Info Mngmnt &amp; Comp Security</source>
          <volume>21</volume>
          ,
          <fpage>191</fpage>
          -
          <lpage>201</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref98">
        <mixed-citation>
          53.
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martins</surname>
          </string-name>
          , N.:
          <article-title>Defining and identifying dominant information security cultures and subcultures</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>70</volume>
          ,
          <fpage>72</fpage>
          -
          <lpage>94</lpage>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref99">
        <mixed-citation>
          54.
          <string-name>
            <surname>Ashenden</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sasse</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>CISOs and organisational culture: Their own worst enemy?</article-title>
          <source>Computers &amp; Security</source>
          <volume>39</volume>
          ,
          <fpage>396</fpage>
          -
          <lpage>405</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref100">
        <mixed-citation>
          55.
          <string-name>
            <surname>Arage</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Belanger</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Beshah</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Influence of National Culture on Employees' Compliance with Information Systems Security (ISS) Policies: Towards ISS Culture in Ethiopian Companies</article-title>
          . In: AMCIS (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref101">
        <mixed-citation>
          56.
          <string-name>
            <surname>Williams</surname>
            ,
            <given-names>P.A.</given-names>
          </string-name>
          :
          <article-title>What Does Security Culture Look Like For Small Organizations? Security Research Institute (SRI)</article-title>
          , Edith Cowan University (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref102">
        <mixed-citation>
          57. van Niekerk,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Solms</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>von: A theory based approach to information security culture change</article-title>
          .
          <source>Information (Japan) 16</source>
          ,
          <fpage>3907</fpage>
          -
          <lpage>3930</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref103">
        <mixed-citation>
          58.
          <string-name>
            <surname>Ngo</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zhou</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warren</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Understanding Transition towards Information Security Culture Change</article-title>
          . In: AISM, pp.
          <fpage>67</fpage>
          -
          <lpage>73</lpage>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref104">
        <mixed-citation>
          59.
          <string-name>
            <surname>Luo</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warkentin</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Johnston</surname>
            ,
            <given-names>A.C.</given-names>
          </string-name>
          :
          <article-title>The impact of national culture on workplace privacy expectations in the context of information security assurance</article-title>
          .
          <source>In: AMCIS</source>
          <year>2009</year>
          , p.
          <volume>521</volume>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref105">
        <mixed-citation>
          60.
          <string-name>
            <surname>Lim</surname>
            ,
            <given-names>J.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chang</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maynard</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ahmad</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Exploring the Relationship between Organizational Culture and Information Security Culture</article-title>
          . Security Research Institute (SRI), Edith Cowan University (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref106">
        <mixed-citation>
          61.
          <string-name>
            <surname>Johnsen</surname>
            ,
            <given-names>S.O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hansen</surname>
            ,
            <given-names>C.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nordby</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dahl</surname>
            ,
            <given-names>M.B.</given-names>
          </string-name>
          :
          <article-title>Measurement and Improvement of Information Security Culture</article-title>
          .
          <source>Measurement and Control</source>
          <volume>39</volume>
          ,
          <fpage>52</fpage>
          -
          <lpage>56</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref107">
        <mixed-citation>
          62.
          <string-name>
            <surname>Ghernouti-Hélie</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tashi</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Simms</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>A Multi-stage Methodology for Ensuring Appropriate Security Culture and Governance</article-title>
          . In: 2010 International Conference on Availability,
          <source>Reliability and Security</source>
          , pp.
          <fpage>353</fpage>
          -
          <lpage>360</lpage>
          . IEEE (
          <year>2010</year>
          - 2010)
        </mixed-citation>
      </ref>
      <ref id="ref108">
        <mixed-citation>
          63.
          <string-name>
            <surname>Dojkovski</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lichtenstein</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warren</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Developing information security culture in small and medium size enterprises: Australian case studies</article-title>
          .
          <source>In: ECIW2008-7th European Conference on Information Warfare and Security: ECIW2008</source>
          . Reading: Academic Conferences Limited, pp.
          <fpage>55</fpage>
          -
          <lpage>66</lpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref109">
        <mixed-citation>
          64.
          <string-name>
            <surname>Corriss</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Information security governance</article-title>
          . In: Bishop, M. (ed.)
          <source>Proceedings of the 2010 Workshop on Governance of Technology, Information and Policies - GTIP '10</source>
          , pp.
          <fpage>35</fpage>
          -
          <lpage>41</lpage>
          . ACM Press, New York, New York, USA (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref110">
        <mixed-citation>
          65.
          <string-name>
            <surname>Connolly</surname>
          </string-name>
          , Lena and Lang, Michael: Information Systems Security:
          <article-title>The Role of Cultural Aspects in Organizational Settings</article-title>
          .
          <source>In: WISP 2012 Proceedings. 30</source>
          . (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref111">
        <mixed-citation>
          66.
          <string-name>
            <given-names>Lena</given-names>
            <surname>Connolly</surname>
          </string-name>
          ,
          <string-name>
            <surname>M.</surname>
          </string-name>
          <article-title>Lang: Investigation of cultural aspects within information systems security research</article-title>
          .
          <source>2012 International Conference for Internet Technology and Secured Transactions</source>
          ,
          <fpage>105</fpage>
          -
          <lpage>111</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref112">
        <mixed-citation>
          67.
          <string-name>
            <surname>Alfawaz</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nelson</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mohannak</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Information security culture: a behaviour compliance conceptual framework</article-title>
          .
          <source>In: Information Security 2010: AISC'10 Proceedings of the Eighth Australasian Conference on Information Security [Conferences in Research and Practice in Information Technology</source>
          , Volume
          <volume>105</volume>
          ], pp.
          <fpage>51</fpage>
          -
          <lpage>60</lpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref113">
        <mixed-citation>
          68.
          <string-name>
            <surname>Karjalainen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Siponen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Puhakainen</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sarker</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Universal and Culture-dependent Employee Compliance of Information Systems Security Procedures</article-title>
          .
          <source>Journal of Global Information Technology Management</source>
          <volume>23</volume>
          ,
          <fpage>5</fpage>
          -
          <lpage>24</lpage>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref114">
        <mixed-citation>
          69.
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>An approach to information security culture change combining ADKAR and the ISCA questionnaire to aid transition to the desired culture</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>26</volume>
          ,
          <fpage>584</fpage>
          -
          <lpage>612</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref115">
        <mixed-citation>
          70.
          <string-name>
            <surname>Tang</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          'g., Zhang, T.:
          <article-title>The impacts of organizational culture on information security culture: a case study</article-title>
          .
          <source>Inf Technol Manag</source>
          <volume>17</volume>
          ,
          <fpage>179</fpage>
          -
          <lpage>186</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref116">
        <mixed-citation>
          71.
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Comparing the information security culture of employees who had read the information security policy and those who had not</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>24</volume>
          ,
          <fpage>139</fpage>
          -
          <lpage>151</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref117">
        <mixed-citation>
          72.
          <string-name>
            <surname>Nel</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Drevin</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Key elements of an information security culture in organisations</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>27</volume>
          ,
          <fpage>146</fpage>
          -
          <lpage>164</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref118">
        <mixed-citation>
          73.
          <string-name>
            <surname>Cram</surname>
            ,
            <given-names>W.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Proudfoot</surname>
            ,
            <given-names>J.G.</given-names>
          </string-name>
          :
          <article-title>Seeing the Forest and the Trees: A Meta-Analysis of the Antecedents to Information Security Policy Compliance</article-title>
          .
          <source>MISQ 43</source>
          ,
          <fpage>525</fpage>
          -
          <lpage>554</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref119">
        <mixed-citation>
          74.
          <string-name>
            <surname>Lin</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kunnathur</surname>
            ,
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>The Cultural Foundation of Information Security Behavior</article-title>
          .
          <source>Journal of Database Management</source>
          <volume>31</volume>
          ,
          <fpage>21</fpage>
          -
          <lpage>41</lpage>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref120">
        <mixed-citation>
          75.
          <string-name>
            <surname>Vance</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Siponen</surname>
            ,
            <given-names>M.T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Straub</surname>
            ,
            <given-names>D.W.:</given-names>
          </string-name>
          <article-title>Effects of sanctions, moral beliefs, and neutralization on information security policy violations across cultures</article-title>
          .
          <source>Information &amp; Management</source>
          <volume>57</volume>
          ,
          <issue>103212</issue>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref121">
        <mixed-citation>
          76.
          <string-name>
            <surname>Hina</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dominic</surname>
          </string-name>
          , P.D.D.:
          <article-title>Information security policies' compliance: a perspective for higher education institutions</article-title>
          .
          <source>Journal of Computer Information Systems</source>
          <volume>60</volume>
          ,
          <fpage>201</fpage>
          -
          <lpage>211</lpage>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref122">
        <mixed-citation>
          77.
          <string-name>
            <surname>da Veiga</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Astakhova</surname>
            ,
            <given-names>L.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Botha</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Herselman</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Defining organisational information security culture-Perspectives from academia and industry</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>92</volume>
          ,
          <issue>101713</issue>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref123">
        <mixed-citation>
          78. Wiley,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>McCormac</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Calic</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          :
          <article-title>More than the individual: Examining the relationship between culture and Information Security Awareness</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>88</volume>
          ,
          <issue>101640</issue>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref124">
        <mixed-citation>
          79.
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zahedi</surname>
            ,
            <given-names>F.M.:</given-names>
          </string-name>
          <article-title>Individuals' Internet Security Perceptions and Behaviors: Polycontextual Contrasts Between the United States and China</article-title>
          .
          <source>MISQ 40</source>
          ,
          <fpage>205</fpage>
          -
          <lpage>222</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref125">
        <mixed-citation>
          80.
          <string-name>
            <surname>Arage</surname>
            ,
            <given-names>T.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Belanger</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , and
          <string-name>
            <surname>Tesema</surname>
          </string-name>
          ,
          <source>T.B.: Investigating the Moderating Impact of National Culture in Information Systems Security Policy Violation: The Case of Italy and Ethiopia"</source>
          (
          <year>2016</year>
          ).
          <source>In: MCIS 2016 Proceedings. 56</source>
          . (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref126">
        <mixed-citation>
          81.
          <string-name>
            <surname>Kam</surname>
          </string-name>
          , H.-J.,
          <string-name>
            <surname>Katerattanakul</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hong</surname>
          </string-name>
          , S.-G.:
          <article-title>A Tale of Two Cities: Information Security Policy Compliance of the Banking Industry in the United States</article-title>
          and South Korea. University of Münster, Münster, Germany (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref127">
        <mixed-citation>
          82.
          <string-name>
            <surname>Hwee-Joo</surname>
            <given-names>Kam</given-names>
          </string-name>
          , Pairin Katerattanakul, Soongoo Hong:
          <article-title>The Three Musketeers: Impacts of National Culture, Organizational Norms and Institutional Environment on Information Security Policy Compliance</article-title>
          .
          <source>In: WISP</source>
          <year>2014</year>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref128">
        <mixed-citation>
          83.
          <string-name>
            <given-names>K.</given-names>
            <surname>Alshare</surname>
          </string-name>
          ,
          <string-name>
            <surname>P.</surname>
          </string-name>
          <article-title>Lane: A Conceptual Model for Explaining Violations of the Information Security Policy (ISP): A Cross Cultural Perspective</article-title>
          . In: AMCIS (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref129">
        <mixed-citation>
          84.
          <string-name>
            <surname>Lapke</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <source>Power Relationships in Information Systems Security Policy Formulation and Implementation</source>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref130">
        <mixed-citation>
          85.
          <string-name>
            <surname>M. Warkentin</surname>
          </string-name>
          , Nirmalee Malimage, Kalana Malimage:
          <article-title>Impact of Protection Motivation and Deterrence on IS Security Policy Compliance: A Multi-Cultural View</article-title>
          .
          <source>In: WISP</source>
          <year>2012</year>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref131">
        <mixed-citation>
          86.
          <string-name>
            <given-names>T.</given-names>
            <surname>Dols</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          <article-title>Silvius: Exploring the Influence of National Cultures on Non-Compliance Behavior</article-title>
          .
          <source>Communications of the IIMA 10</source>
          ,
          <issue>2</issue>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref132">
        <mixed-citation>
          87.
          <string-name>
            <surname>Hovav</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>D'Arcy</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>A Cross-Cultural Analysis of Security Countermeasure Effectiveness</article-title>
          .
          <source>In: WISP</source>
          <year>2007</year>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref133">
        <mixed-citation>
          88.
          <string-name>
            <surname>Martins</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Elofe</surname>
          </string-name>
          , J.:
          <article-title>Information security culture</article-title>
          .
          <source>In: Security in the information society</source>
          , pp.
          <fpage>203</fpage>
          -
          <lpage>214</lpage>
          . Springer (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref134">
        <mixed-citation>
          89.
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dinev</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hart</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cooke</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Managing Employee Compliance with Information Security Policies: The Critical Role of Top Management and Organizational Culture*</article-title>
          .
          <source>Decision Sciences</source>
          <volume>43</volume>
          ,
          <fpage>615</fpage>
          -
          <lpage>660</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref135">
        <mixed-citation>
          90.
          <string-name>
            <surname>Wetzels</surname>
          </string-name>
          , Odekerken-Schröder, van Oppen:
          <article-title>Using PLS Path Modeling for Assessing Hierarchical Construct Models: Guidelines and Empirical Illustration</article-title>
          .
          <source>MIS Quarterly</source>
          <volume>33</volume>
          ,
          <issue>177</issue>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref136">
        <mixed-citation>
          91.
          <string-name>
            <given-names>Yuryna</given-names>
            <surname>Connolly</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            ,
            <surname>Lang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            ,
            <surname>Gathegi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Tygar</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.J.:</surname>
          </string-name>
          <article-title>Organisational culture, procedural countermeasures, and employee security behaviour</article-title>
          .
          <source>Info and Computer Security</source>
          <volume>25</volume>
          ,
          <fpage>118</fpage>
          -
          <lpage>136</lpage>
          (
          <year>2017</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref137">
        <mixed-citation>
          92.
          <string-name>
            <surname>Cockcroft</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rekker</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>The relationship between culture and information privacy policy</article-title>
          .
          <source>Electron Markets</source>
          <volume>26</volume>
          ,
          <fpage>55</fpage>
          -
          <lpage>72</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref138">
        <mixed-citation>
          93.
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>C.C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Medlin</surname>
            ,
            <given-names>B.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shaw</surname>
            ,
            <given-names>R.S.:</given-names>
          </string-name>
          <article-title>A cross-cultural investigation of situational information security awareness programs</article-title>
          . Info Mngmnt &amp; Comp
          <string-name>
            <surname>Security</surname>
          </string-name>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref139">
        <mixed-citation>
          94.
          <string-name>
            <surname>Ali</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brooks</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>A situated cultural approach for cross‐cultural studies in IS</article-title>
          .
          <source>Journal of Enterprise Information Management</source>
          <volume>22</volume>
          ,
          <fpage>548</fpage>
          -
          <lpage>563</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref140">
        <mixed-citation>
          95.
          <string-name>
            <surname>Thomson</surname>
          </string-name>
          , K.-L.,
          <string-name>
            <surname>Solms</surname>
            , R. von, Louw,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>Cultivating an organizational information security culture</article-title>
          .
          <source>Computer Fraud &amp; Security</source>
          <year>2006</year>
          ,
          <fpage>7</fpage>
          -
          <lpage>11</lpage>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref141">
        <mixed-citation>
          96.
          <string-name>
            <surname>Ruighaver</surname>
            ,
            <given-names>A.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maynard</surname>
            ,
            <given-names>S.B.</given-names>
          </string-name>
          :
          <article-title>Organizational Security Culture: More Than Just an End-User Phenomenon</article-title>
          . In:
          <string-name>
            <surname>Fischer-Hübner</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rannenberg</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yngström</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lindskog</surname>
          </string-name>
          , S. (eds.) Security and Privacy in Dynamic Environments, pp.
          <fpage>425</fpage>
          -
          <lpage>430</lpage>
          . Springer US, Boston, MA (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref142">
        <mixed-citation>
          97.
          <string-name>
            <surname>Crossler</surname>
            ,
            <given-names>R.E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Johnston</surname>
            ,
            <given-names>A.C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lowry</surname>
            ,
            <given-names>P.B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hu</surname>
            ,
            <given-names>Q.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warkentin</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Baskerville</surname>
          </string-name>
          , R.:
          <article-title>Future directions for behavioral information security research</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>32</volume>
          ,
          <fpage>90</fpage>
          -
          <lpage>101</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref143">
        <mixed-citation>
          98.
          <string-name>
            <surname>Zakaria</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          :
          <article-title>Understanding Challenges of Information Security Culture: A Methodological Issue</article-title>
          . In: AISM, pp.
          <fpage>83</fpage>
          -
          <lpage>93</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref144">
        <mixed-citation>
          99.
          <string-name>
            <surname>Solms</surname>
            , R. von, Solms,
            <given-names>B.</given-names>
          </string-name>
          <article-title>von: From policies to culture</article-title>
          .
          <source>Computers &amp; Security</source>
          <volume>23</volume>
          ,
          <fpage>275</fpage>
          -
          <lpage>279</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref145">
        <mixed-citation>
          100.
          <string-name>
            <surname>Schlienger</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Teufel</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Information security culture-from analysis to change</article-title>
          .
          <source>South African Computer Journal</source>
          <year>2003</year>
          ,
          <fpage>46</fpage>
          -
          <lpage>52</lpage>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref146">
        <mixed-citation>
          101.
          <string-name>
            <surname>Ramachandran</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rao</surname>
            ,
            <given-names>S.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goles</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Information Security Cultures of Four Professions: A Comparative Study</article-title>
          .
          <source>In: Proceedings of the 41st Annual Hawaii International Conference on System Sciences (HICSS</source>
          <year>2008</year>
          ), p.
          <fpage>454</fpage>
          .
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2008</year>
          - 2008)
        </mixed-citation>
      </ref>
      <ref id="ref147">
        <mixed-citation>
          102.
          <string-name>
            <surname>Okere</surname>
            , I., van Niekerk,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Carroll</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Assessing information security culture: A critical analysis of current approaches</article-title>
          .
          <source>In: 2012 Information Security for South Africa</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref148">
        <mixed-citation>
          103.
          <string-name>
            <surname>Martins</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Eloff</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          :
          <article-title>Assessing Information Security Culture</article-title>
          . In: ISSA, pp.
          <fpage>1</fpage>
          -
          <lpage>14</lpage>
          (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>