Cameron-Freeman Örgüt Kültürü Türleri Ekseninde Örgüt Kültürü ve Bilgi Güvenliği Algısı İlişkisi: Devlet Üniversitelerinde Bir Uygulama

Bu çalışmada, Cameron-Freeman örgüt kültürü türleri ekseninde Türkiye'deki devlet üniversitelerinin genel kültürel profilinin tanımlanması, bilgi güvenliği prensipleri temelinde akademik personelin bilgi güvenliği algısının ortaya konması ve korelasyon analizi ile örgüt kültürü türleri ve bilgi güvenliği algısı ilişkisinin incelenmesi amaçlanmıştır. Araştırmada, Türkiye'deki 106 devlet üniversitesinin 3.023 akademik personelinden anket yöntemi ile veri toplanmıştır. Anketin Cameron ve Freeman örgüt kültür türlerine ilişkin soruları, Cameron ve Quinn (2006) tarafından geliştirilen Örgütsel Kültür Değerlendirme Aracı dikkate alınarak hazırlanmıştır. Anketin bilgi güvenliği algısına ilişkin sorularının hazırlanmasında da, Chang ve Lin (2007) tarafından geliştirilen ölçekten yararlanılmıştır. Veri analizinde IBM SPSS 21 paket programı kullanılmıştır. Elde edilen bulgulara göre, hiyerarşinin Türkiye'deki devlet üniversitelerinin genel kültürel profilinde baskın olduğu ve erişilebilirlik algısı düzeyinin diğer bilgi güvenliği prensipleri algılarına göre yüksek çıktığı sonucuna ulaşılmıştır. Ayrıca örgüt kültürü türleri ile akademik personelin bilgi güvenliği algısı arasında istatistiksel olarak anlamlı ve orta düzeyde pozitif ilişki gözlemlenmiştir.

The Relationship between Organizational Culture and the Perception of Information Security on the Axis of Cameron-Freeman Organizational Culture Types: An Application in Government Universities

In this study, defining the overall cultural profile of the government universities in Turkey on the axis of Cameron-Freeman organizational culture types, presenting the academicians' perception of information security based on the principles of information security and investigating the relationship between the organizational culture types and the perception of information security by correlation analysis were aimed. In research, data were gathered from 3.023 academicians of 106 government universities in Turkey via survey method. Questions about the Cameron and Freeman organizational culture types were prepared using the Organizational Culture Assessment Instrument developed by Cameron and Quinn (2006). In preparing the questions about the perception of information security, the scale developed by Chang and Lin (2007) was used. In data analysis, SPSS 21 package program was used. According to the findings, in overall cultural profile of the government universities in Turkey it was concluded that hierarchy was dominant culture and the perception level of availability was greater than other principles' perception of information security. Moreover, in between the organizational culture types and the academicians' perception of information security, statistically significant, positive and moderate level relationship was observed.

___

  • British Standard, (1999). BS 7799-1: Information Security Management-Part1: Code of Practice for Information Security Management, British Standards Institution, United Kingdom.
  • Büyüköztürk, Ş., (2015). Sosyal Bilimler İçin Veri Analizi El Kitabı, Pegem Akademi, Ankara.
  • Cameron, K. S., Freeman, S. J., (1991). "Cultural Congruence, Strength and Type: Relationships to Effectiveness", Research in Organizational Change and Development, Vol. 5, 23-58.
  • Cameron, K. S., Quinn, R. E., (2006). Diagnosing and Changing Organizational Culture, Jossey-Bass, San Francisco.
  • Canbek, G., Sağıroğlu, Ş., (2006). "Bilgi, Bilgi Güvenliği ve Süreçleri Üzerine Bir İnceleme", Politeknik Dergisi, Cilt. 9, Sayı. 3, 165-174.
  • Chang, S. E., Lin, C. S., (2007). "Exploring Organizational Culture for Information Security Management", Industrial Management & Data Systems, Vol. 107, No. 3, 438-458.
  • Denison, D. R., (1996). "What is the Difference Between Organizational Culture and Organizational Climate? A Native's Point of View on a Decade of Paradigm Wars", Academy of Management Review, Vol. 21, No. 3, 619-654.
  • Deshpande, R., Webster, F. E., (1989). "Organizational Culture and Marketing: Definig the Research Agenda", The Journal of Marketing, Vol. 53, No. 1, 3-15.
  • Field, A., (2009). Discovering Statistics Using Spss, SAGE Publications, London.
  • Fussel, R. S., (2005). "Protecting Information Security Availability via Self-Adapting Intelligent Agents", IEEE Conference Publications, 2005 IEEE Military Communications Conference, Vol. 5, 2977-2982.
  • Harris, S., (2013). All-In-One CISSP Exam Guide, Mc Graw Hill, United States.
  • Hauke, J., Kossowski, T., (2011). "Comparison of Values of Pearson's and Spearman's Correlation Coefficients on the Same Sets of Data", Quaestiones Geographicae, Vol. 30, No. 2, 87-93.
  • Jones, D., (2004). "Confidentiality and Security of Information", Anaesthesia and Intensive Care Medicine, Vol. 5, No. 12, 404-406.
  • Kanday, R., (2012). "A Survey on Cloud Computing Security", IEEE Conference Publications, 2012 International Conference on Computing Sciences, 302-311.
  • Knapp, K. J., Ford, F. N., (2006). "Information Security: Management's Effect on Culture and Policy", Information Management & Computer Security, Vol. 14, No. 1, 24-36.
  • Lim, J. S., Chang, S., Maynard, S. Ahmad, A., (2009). "Exploring the Relationship between Organizational Culture and Information Security Culture", 7th Australian Information Security Management Conference, 88-97.
  • Meijer, A., (2001). "Accountability in an Information Age: Opportunities and Risks for Records Management", Archival Science, Vol. 1, No. 4, 361-372.
  • Onwubiko, C., Lenaghan, A. P., (2007). "Managing Security Threats and Vulnerabilities for Small to Medium Enterprises", IEEE Conference Publications, 2007 IEEE Intelligence and Security Informatics, 244-249.
  • Quinn, R. E., Rohrbaugh, J., (1981). "A Competing Values Approach to Organizational Effectiveness", Public Productivity Review, Vol. 5, No. 2, 122-140.
  • Quinn, R. E., Rohrbaugh, J., (1983). "A Spatial Model of Effectiveness Criteria: Towards a Competing Values Approach to Organizational Analysis", Management Science, Vol. 29, No. 3, 363-377.
  • Quinn, R. E., Spreitzer, G. M., (1991). "The Psychometrics of the Competing Values Culture Instrument and an Analysis of the Impact of Organizational Culture on Quality of Life", Research in Organizational Change and Development, Vol. 5, 115-142.
  • Rainer, R. K., Marshall, T. E., Knapp, K. J. Montgomery, G. H., (2007). "Do Information Security Professionals and Business Managers View Information Security Issues Differently?", Information Systems Security, Vol. 16, 100-108.
  • Ryan, S. D., Bordoloi, B., (1997). "Evaluating Security Threats in Mainframe and Client/Server Environments", Information & Management, Vol. 32, 137-146.
  • Schein, E. H., (1984). "Coming to a New Awareness of Organizational Culture", Sloan Management Review, Vol. 25, No. 2, 3-16.
  • Schwartz, H., Davis, S. M., (1981). "Matching Corporate Culture and Business Strategy", Organizational Dynamics, Vol. 10, 30-48.
  • Solms, B. V., Solms, R. V., (2004). "The 10 Deadly Sins of Information Security Management", Computer & Security, Vol. 23, No. 5, 371-376.
  • Türk Standardı, (2006). TS ISO/IEC 27001 Bilgi Teknolojisi-Güvenlik Teknikleri-Bilgi Güvenliği Yönetim Sistemleri-Gereksinimler, Türk Standartları Enstitüsü, Ankara.
  • Türkiye Bilişim Derneği, (2006). Bilişim Sistemleri Güvenliği El Kitabı Sürüm 1.0, Türkiye Bilişim Derneği Yayınları, Ankara.
  • Veiga, A. D., Eloff, J. H. P., (2007). "An Information Security Governance Framework", Information Systems Management, Vol. 24, No. 4, 361-372.
  • Vroom, C., Solms, R. V., (2004). "Towards Information Security Behavioural Compliance", Computer & Security, Vol. 23, No. 3, 191-198.
  • Woodhouse, S., (2007). "Information Security: End User Behavior and Corporate Culture", IEEE Conference Publications, 7th IEEE International Conference on Computer and Information Technology, 767-774.
  • YÖK (Yükseköğretim Kurulu) Web, URL Adresi: http://yok.gov.tr/web/guest/universitelerimiz, Son Erişim: 21 Nisan 2016.
İşletme Araştırmaları Dergisi-Cover
  • ISSN: 1309-0712
  • Yayın Aralığı: Yılda 4 Sayı
  • Başlangıç: 2009
  • Yayıncı: Melih Topaloğlu