Unintentional information security behavior from the Qur’an and hadith’s perspective

As the world becomes more interconnected now than decades ago, information security incidents are more prevalent in organizations. The incidents are more likely caused by insiders and they can happen with or without intentions. Although some security studies state that unintentional security inciden...

Full description

Bibliographic Details
Main Authors: Barzak, Omar Mokhles, Abdul Molok , Nurul Nuha, Talib, Shuhaili, Mahmud, Murni
Format: Conference or Workshop Item
Language:English
English
Published: 2015
Subjects:
Online Access:http://irep.iium.edu.my/47341/
http://irep.iium.edu.my/47341/
http://irep.iium.edu.my/47341/1/Barzak%2C_Abdul_Molok%2C_Talib_%26_Mahmud_2015_-_Unintentional_information_security_behavior.pdf
http://irep.iium.edu.my/47341/4/IMAN2015_Program_v12.pdf
Description
Summary:As the world becomes more interconnected now than decades ago, information security incidents are more prevalent in organizations. The incidents are more likely caused by insiders and they can happen with or without intentions. Although some security studies state that unintentional security incidents could cause more damages to organizational information systems (IS) than intentional security incidents, The research in this area is still limited. This paper focuses on unintentional employees’ behaviors that have impacts on organizational information security, rather than unintentional behaviors in general IT practices. It explores unintentional information security behavior based on the perspective of the Qur’an and Hadith. Moreover, it provides some recommendations based on academic studies and Sharia teachings to overcome unintentional information security behavior. This paper starts with the discussion on information security behavior, human intentions based on the Sharia, and unintentional behavior under Islamic perspective. Finally, the significant of the study relies on the recommendation to reduce unintentional security threats based on information security studies and Sharia teachings by proposing a model to understand unintentional information security behavior and the factors that affect them.