ASIS Foundation has published a new report exploring security culture, its development, and its role in developing resilience.
The report sets out a framework for security culture that encompasses six factors and provides supporting data, academic concepts, and practical examples for each one.
The framework covers six areas:
- Attitudes: do employees care about security?
- Knowledge: do employees know what is expected?
- Behaviour: do employees do what is expected? What do they see others doing?
- Communication: do executives and security leaders communicate security in a relatable and understandable way?
- Compliance: are policies sensible and easy to follow?
- Empowerment: do employees feel able to play their part?
Embedded in the framework is the conception that security culture needs to account for national cultural norms, applicable legal and regulatory requirements, third parties and the extended enterprise, and organizational change and transformation initiatives.






