[2026-06-27T17:15:54-04:00] vufind.DEBUG: VuFindSearch\Backend\Solr\Connector: Query fl=%2A&wt=json&json.nl=arrarr&q=id%3A%22ir-20.500.14135-1011%22&qt=morelikethis&rows=5 [2026-06-27T17:15:54-04:00] vufind.DEBUG: VuFindSearch\Backend\Solr\Connector: => GET http://localhost:8983/solr/biblio/select?fl=%2A&wt=json&json.nl=arrarr&q=id%3A%22ir-20.500.14135-1011%22&qt=morelikethis&rows=5 [2026-06-27T17:15:54-04:00] vufind.DEBUG: VuFindSearch\Backend\Solr\Connector: <= 200 OK {"time":0.004614830017089844} [2026-06-27T17:15:54-04:00] vufind.DEBUG: Deserialized SOLR response {"qtime":1}

Construção da escala do nível da cultura organizacional de segurança da informação

The present study’s goal was to build a measurement scale of the level of information security in an institution’s organizational culture. Therefore, based on a broad bibliographical review, the study conceptualized the organizational culture of information security, which was our object of evaluati...

Full description

Saved in:
Bibliographic Details
Main Author: Araujo, Pedro Henrique de Moura
Other Authors: Andrade, Dalton Francisco de
Format: Tese
Language:Portuguese
Published: Universidade Federal de Santa Catarina 2024
Subjects:
Online Access:https://hdl.handle.net/20.500.14135/1011
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:The present study’s goal was to build a measurement scale of the level of information security in an institution’s organizational culture. Therefore, based on a broad bibliographical review, the study conceptualized the organizational culture of information security, which was our object of evaluation. Then, the study defined the latent trait – Organizational Culture of Information Security, establishing that the attributes that characterize the latent trait are: the nine principles of the Organization for Economic Cooperation and Development – OECD; and the information security controls of the ABNT NBR ISO / IEC 27002’s standard. In order to build the scale, we developed an evaluation instrument, a questionnaire, and applied it to federal public organizations. After the analysis and validation of the instrument, based on Item Response Theory -IRT, we obtained a set of 55 items that structure the scale. The study yielded the following results: a proposal of a concept of organizational culture applied to information security; and the development of a standardized and interpreted scale of evaluation of the organizational culture level of information security, defined in five levels: 0 - Chaos, 1 - Elementary, 2 - In Progress 3 - Advanced and 4 - Optimized. The scale developed based on IRT allows us to evaluate all types of organizations, enables comparing organizations in a supply chain, and provides the necessary information for self-knowledge of the organization, helping managers to optimize investments in information security and in managerial decision-making.