Journal of Cyber Security and Risk Auditing

Journal of Cyber Security and Risk Auditing

ISSN: 3079-5354 (Online)

Publishing model:

: Open access
Scopus Indexed
2025
14.7

CiteScore

Q1
open accessOpen Access

Article

👁️0views

Adaptation and Validation of the KAB Model to Assess the Risk of Internal Information Security Incidents

by 

Amjad Mahfuth Orcid link ;

Salman Yussof Orcid link

PDF logoPDF

Published: 02/08/2026

Abstract

Many studies have revealed that an organization’s insiders pose risks to the security of information assets. Among the key threats to a secure information environment are employees’ actions and behaviors in handling information. Insiders, whether intentional or unintentional, may pose significant risks, despite the substantial investments organizations typically make in security controls and related solutions. Employee behavior in information security cannot be fully addressed through technical and procedural controls alone. An organization’s approach to information security should include employee behavior because the organization’s success or failure effectively depends on what its employees do or fail to do. To develop appropriate security perceptions between employees within an organization, we need to know the security knowledge required to influence employee behavior. To achieve this, the KAB (knowledge, attitude and behavior) model has been adapted and validated to guide the cultivation of a security culture that helps minimize internal security threats in organizations. The literature review indicated a positive relationship between knowledge and behavior. Accordingly, this research aims to investigate the security knowledge required to influence employee behavior and to examine the impact of security knowledge on behavior. This research uses a questionnaire was used to collect the data from the employees. The result of the quantitative analysis revealed that the knowledge of security threat, knowledge of security risk, knowledge of security responsibility and knowledge of legislation, regulation and national culture have significant effect on employee behavior. Furthermore, the result has also shown that these knowledge security construct have significant positive indirect effect on behavior through attitudes. These areas of security knowledge should be incorporated as key topics in organizational security training and awareness programs for employees, in order to foster an effective information security culture within the organization.

Keywords

KAB ModelInsider threatSecurity BehaviorInformation Security CultureSecurity KnowledgeSecurity behaviorOrganization.

References

  1. S. Skinner, R. Von Solms, … J. van N.-P. C., and undefined 2025, “Cultivating Cybersecurity Awareness Among Seafarers,” Elsevier, Accessed: Oct. 22, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S1877050925020800
  2. Verizon, “2014 Data Breach Investigations Report,” Verizon Business Journal, vol. 2014, no. 1, pp. 1–60, 2014.
  3. P. Bhatt, R. Valecha, H. R.-I. J. of Information, and undefined 2025, “Situational awareness about data breaches and ransomware attacks: A multi-dimensional cyber threat impact framework and content analyses of practitioner-public,” Elsevier, Accessed: Oct. 22, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0268401225000349
  4. V. Marvik and R. Bakir, “Information security culture: An investigation into the impact of a large-scale cyberattack,” University of Agder, 2023.
  5. Symantec, “Internet Security Threat Report,” vol. 23, no. March, 2018.
  6. A. Mahfuth, “A Systematic Literature Review : Information Security Culture,” pp. 1–6, 2017.
  7. N. Alsuqayh, A. Mirza, and A. Alhogail, “A Phishing Website Detection System Based on Hybrid Feature Engineering with SHAP Explainable Artificial Intelligence Technique,” Springer, vol. 15463 LNCS, pp. 3–17, 2025, doi: 10.1007/978-981-96-1483-7_1.
  8. K. Chauhan, “Insider Threats Mitigation: Role of Penetration Testing,” Jul. 2024, Accessed: Oct. 26, 2025. [Online]. Available: https://arxiv.org/pdf/2407.17346
  9. M. Sharulnizam Kamarulzaman, S. Mohamed Shuhidan, K. Abdul Wahid, A. Abdul Wahab, and A. Jalil Toha, “The Current State of Information Security Policies,” istes.org, vol. 14, no. 1, 2024, Accessed: Oct. 27, 2025. [Online]. Available: https://www.istes.org/storage/01JGK7MF50AKKKW35SCK14TVZW.pdf#page=8
  10. A. D. V.- Diversity, undefined AI, and S. for F. Growth, and undefined 2025, “Encouraging Creativity and Innovation in the Cybersecurity Culture of the Organisation for Sustainable Value and Growth,” igi-global.com, Accessed: Oct. 27, 2025. [Online]. Available: https://www.igi-global.com/chapter/encouraging-creativity-and-innovation-in-the-cybersecurity-culture-of-the-organisation-for-sustainable-value-and-growth/369102
  11. A. Mahfuth, S. Yussof, A. A. Baker, and N. Ali, “A systematic literature review: Information security culture,” in International Conference on Research and Innovation in Information Systems, ICRIIS, 2017. doi: 10.1109/ICRIIS.2017.8002442.
  12. H. Zangana, Z. Sallow, M. O.-J. I. Computer, and undefined 2025, “The human factor in cybersecurity: Addressing the risks of insider threats,” researchgate.net, Accessed: Oct. 22, 2025. [Online]. Available: https://www.researchgate.net/profile/Hewa-Zangana/publication/386275073_The_Human_Factor_in_Cybersecurity_Addressing_the_Risks_of_Insider_Threats/links/674b1298f309a268c0193c7c/The-Human-Factor-in-Cybersecurity-Addressing-the-Risks-of-Insider-Threats.pdf
  13. A. Appari and M. E. Johnson, “Information security and privacy in healthcare: current state of research,” International journal of Internet and enterprise management, vol. 6, no. 4, pp. 279–314, 2010.
  14. M. Boujettif and Y. Wang, “Constructivist approach to information security awareness in the Middle East,” in Broadband, Wireless Computing, Communication and Applications (BWCCA), 2010 International Conference on, 2010, pp. 192–199.
  15. A. Mahfuth, “A Systematic Literature Review : Information Security Culture,” pp. 1–6, 2017.
  16. A. Mahfuth, “Security Knowledge Required To Improve Employee Security Behavior in Information Security Culture,” International Journal of Computer Science and Information Security, vol. 20, no. 2, 2022.
  17. R. MOHAMAD RASHID, O. ZAKARIA, and M. NABIL ZULHEMAY, “THE RELATIONSHIP OF INFORMATION SECURITY KNOWLEDGE (ISK) AND HUMAN FACTORS: CHALLENGES AND SOLUTION.,” J. Theor. Appl. Inf. Technol., vol. 57, no. 1, 2013.
  18. T. Ramluckan, B. van N. I. Martins, and others, “A change management perspective to implementing a cyber security culture,” in ECCWS 2020 20th European Conference on Cyber Warfare and Security, 2020, p. 442.
  19. A. AlHogail and A. Mirza, “A proposal of an organizational information security culture framework,” Proceedings of International Conference on Information, Communication Technology and System (ICTS) 2014, no. JANUARY 2015, pp. 243–250, 2014, doi: 10.1109/ICTS.2014.7010591.
  20. O. Huss, “Information Security Culture Guidelines: Based on Best Practices,” 2025, Accessed: Oct. 22, 2025. [Online]. Available: https://www.diva-portal.org/smash/record.jsf?pid=diva2:1965097
  21. D. S. Hermawan, F. Setiadi, and D. Oktaria, “Measurement Level of Information Security Awareness for Employees Using KAB Model with Study Case at XYZ Agency,” in 2022 1st International Conference on Software Engineering and Information Technology (ICoSEIT), 2022, pp. 174–179.
  22. M. Neri, F. Niccolini, and L. Martino, “Organizational cybersecurity readiness in the ICT sector: a quanti-qualitative assessment,” emerald.com, vol. 32, no. 1, pp. 38–52, Jan. 2024, doi: 10.1108/ICS-05-2023-0084/FULL/HTML.
  23. A. Alhogail and A. Mirza, “Information Security Culture: A Definition and a Literature review,” Computer Applications and Information Systems (WCCCAIS), no. January, pp. 1–7, 2014, doi: 10.1109/WCCAIS.2014.6916579.
  24. A. Alhogail, “Design and validation of information security culture framework,” Comput. Human Behav., vol. 49, pp. 567–575, 2015, doi: 10.1016/j.chb.2015.03.054.
  25. J. Onyango, J. Onyango Abingo, D. Musumba, and D. Maina Mbuki, “Factors Influencing Information Security Culture in Organizations Dealing With Economic Crime in Kenya,” Abingo, IJSRM, vol. 12, 2024, doi: 10.18535/ijsrm/v12i12.em12.
  26. A. Al Hogail, “Cultivating and Assessing an Organizational Information Security Culture; an Empirical Study,” International Journal of Security and Its Applications, vol. 9, no. 7, pp. 163–178, 2015.
  27. J. F. Van Niekerk, “Establishing an information security culture in organizations: an outcomes based education approach,” Nelson Mandela Metropolitan University, 2005.
  28. H. A. Kruger and W. D. Kearney, “A prototype for assessing information security awareness,” Comput. Secur., vol. 25, no. 4, pp. 289–296, 2006.
  29. Bilal Khan, “Effectiveness of information security awareness methods based on psychological theories,” African Journal of Business Management, vol. 5, no. 26, pp. 10862–10868, 2011, doi: 10.5897/ajbm11.067.
  30. J. Kaur and N. Mustafa, “Examining the effects of knowledge, attitude and behaviour on information security awareness: A case on SME,” 2013 International Conference on Research and Innovation in Information Systems (ICRIIS), vol. 2013, pp. 286–290, 2013, doi: 10.1109/ICRIIS.2013.6716723.
  31. K. Parsons, A. McCormac, M. Butavicius, M. Pattinson, and C. Jerram, “Determining employee awareness using the Human Aspects of Information Security Questionnaire (HAIS-Q),” Comput. Secur., vol. 42, pp. 165–176, 2014, doi: 10.1016/j.cose.2013.12.003.
  32. S. Mäeses, “Evaluation method for human aspects of information security,” Digi.Lib.Ttu.Ee, pp. 1–56, 2015.
  33. J. Chmura, “Forming the Awareness of Employees in the Field of Information Security,” Journal of Positive Management, vol. 8, no. 1, p. 78, 2017, doi: 10.12775/jpm.2017.006.
  34. A. Gandhi, “Quantitative assessment of information security awareness on informatics students in a university,” ACM International Conference Proceeding Series, pp. 346–350, 2017, doi: 10.1145/3176653.3176728.
  35. M. S. bin Othman Mustafa, M. Nomani Kabir, F. Ernawan, and W. Jing, “An Enhanced Model for Increasing Awareness of Vocational Students Against Phishing Attacks,” 2019 IEEE International Conference on Automatic Control and Intelligent Systems (I2CACIS), no. June, pp. 10–14, 2019, doi: 10.1109/i2cacis.2019.8825070.
  36. B. Aybars, S. E. -, D. ve T. B. D. Medical, and undefined 2025, “Human Factor Risk Modeling in Cybersecurity: A Scoping Review of KAB Frameworks and Data-Driven Approaches,” euroasiajournal.orgB Aybars, S ERDEMEuroasia Matematik, Mühendislik, Doğa ve Tıp Bilimleri Dergisi, 2025•euroasiajournal.org, vol. 12, no. 1, pp. 47–59, 2025, doi: 10.5281/zenodo.15812726.
  37. B. Alkhazi, M. Alshaikh, S. Alkhezi, H. L.-I. access, and undefined 2022, “Assessment of the impact of information security awareness training methods on knowledge, attitude, and behavior,” ieeexplore.ieee.orgB Alkhazi, M Alshaikh, S Alkhezi, H LabbaciIEEE access, 2022•ieeexplore.ieee.org, Accessed: Jan. 27, 2026. [Online]. Available: https://ieeexplore.ieee.org/abstract/document/9991148/
  38. B. H. Nguyen and H. N. Q. Le, “Investigation on information security awareness based on KAB model: the moderating role of age and education level,” emerald.comBH Nguyen, HNQ LeInformation & Computer Security, 2024•emerald.com, vol. 32, no. 5, pp. 598–612, Nov. 2024, doi: 10.1108/ICS-09-2023-0152/FULL/HTML.
  39. D. S. Hermawan, F. Setiadi, and D. Oktaria, “Measurement Level of Information Security Awareness for Employees Using KAB Model with Study Case at XYZ Agency,” in 2022 1st International Conference on Software Engineering and Information Technology (ICoSEIT), 2022, pp. 174–179.
  40. X. Jiang et al., “Oral health-related knowledge, attitudes and behaviors (KAB) of dental students: a systematic review and meta-analysis,” bmcmededuc.biomedcentral.com, vol. 25, no. 1, Dec. 2025, doi: 10.1186/S12909-025-07445-8.
  41. K.-L. Thomson, R. Solms, and L. Louw, “Cultivating an organizational information security culture,” Computer Fraud & Security, vol. 2006, no. 10, pp. 7–11, 2006, doi: http://dx.doi.org/10.1016/S1361-3723(06)70430-4.
  42. A. Mahfuth, “Security Knowledge Required To Improve Employee Security Behavior in Information Security Culture,” International Journal of Computer Science and Information Security, vol. 20, no. 2, 2022.
  43. M. Zwilling, G. Klien, D. Lesjak, Ł. Wiechetek, F. Cetin, and H. N. Basim, “Cyber Security Awareness, Knowledge and Behavior: A Comparative Study,” Journal of Computer Information Systems, vol. 00, no. 00, pp. 1–16, 2020, doi: 10.1080/08874417.2020.1712269.
  44. A. Da Veiga and N. Martins, “Improving the information security culture through monitoring and implementation actions illustrated through a case study,” Comput. Secur., vol. 49, pp. 162–176, 2015.
  45. R. Von Solms and B. Von Solms, “From policies to culture,” Comput. Secur., vol. 23, no. 4, pp. 275–279, 2004.
  46. B. Von Solms, “Information security--the fourth wave,” Comput. Secur., vol. 25, no. 3, pp. 165–168, 2006.
  47. A. Da Veiga and J. H. P. Eloff, “A framework and assessment instrument for information security culture,” Comput. Secur., vol. 29, no. 2, pp. 196–207, 2010, doi: 10.1016/j.cose.2009.09.002.
  48. P. a. Chia, S. B. Maynard, and a. B. Ruighaver, “Understanding Organizational Security Culture,” Pacis, pp. 1–23, 2002.
  49. M. E. Whiteman and H. J. Matort, Principles of Information Security. Cengage Learning, 2014.
  50. J. W. Brady, “Securing health care: Assessing factors that affect HIPAA security compliance in academic medical centers,” in System Sciences (HICSS), 2011 44th Hawaii International Conference on, 2011, pp. 1–10.
  51. M. Siponen, S. Pahnila, and A. Mahmood, “Employees’ adherence to information security policies: an empirical study,” in IFIP International Information Security Conference, 2007, pp. 133–144.
  52. B. McIntosh, “An ethnographic investigation of the assimilation of new organizational members into an information security culture,” Nova Southeastern University, 2011.
  53. A. Al Hogail, “Cultivating and Assessing an Organizational Information Security Culture; an Empirical Study,” International Journal of Security and Its Applications, vol. 9, no. 7, pp. 163–178, 2015, doi: 10.14257/ijsia.2015.9.7.15.
  54. M. Alnatheer and K. Nelson, “Proposed Framework for Understanding Information Security Culture and Practices in the Saudi Context,” Australian Information Security Management Conference, no. December, pp. 6–17, 2009.
  55. L. Connolly and M. Lang, “Information Systems Security: The Role of Cultural Aspects in Organizational Settings,” Information Systems Security, 2013.
  56. M. A. Alnatheer, “A conceptual model to understand information security culture,” International Journal of Social Science and Humanity, vol. 4, no. 2, p. 104, 2014.
  57. S. Dojkovski, S. Lichtenstein, and M. J. Warren, “Fostering Information Security Culture in Small and Medium Size Enterprises: An Interpretive Study in Australia.,” in ECIS, 2007, pp. 1560–1571.
  58. P. Ifinedo, “The effects of national culture on the assessment of information security threats and controls in financial services industry,” International Journal of Electronic Business Management, vol. 12, no. 2, p. 75, 2014.
  59. E. Sherif, S. Furnell, and N. Clarke, “An identification of variables influencing the establishment of information security culture,” in International Conference on Human Aspects of Information Security, Privacy, and Trust, 2015, pp. 436–448.
  60. J. F. Van Niekerk and R. Von Solms, “Information security culture: A management perspective,” Comput. Secur., vol. 29, no. 4, pp. 476–486, 2010, doi: 10.1016/j.cose.2009.10.005.
  61. J. H. P. Eloff and M. M. Eloff, “Information security architecture,” Computer Fraud & Security, vol. 2005, no. 11, pp. 10–16, 2005.
  62. A. Da Veiga, N. Martins, and J. H. P. Eloff, “Information security culture – validation of an assessment instrument,” South African Business Review, vol. 11, no. 1, pp. 147–166, 2007.
  63. C. Paulsen and T. Coulson, “Beyond Awareness: Using Business Intelligence to Create a Culture of Information Security.,” Communications of the IIMA, vol. 11, no. 3, 2011.
  64. G. Dhillon and J. Backhouse, “Technical opinion: Information system security management in the new millennium,” Commun. ACM, vol. 43, no. 7, pp. 125–128, 2000, doi: 10.1145/341852.341877.
  65. N. S. Safa, M. Sookhak, R. Von Solms, S. Furnell, N. A. Ghani, and T. Herawan, “Information security conscious care behaviour formation in organizations,” Comput. Secur., vol. 53, 2015, doi: 10.1016/j.cose.2015.05.012.
  66. A. Da Veiga and J. H. P. Eloff, “A framework and assessment instrument for information security culture,” Comput. Secur., vol. 29, no. 2, pp. 196–207, 2009.
  67. OECD, “OECD; 2005,” in The promotion of a culture of security for information systems and networks in OECD countries (OECD), 2005.
  68. C. Vroom and R. Von Solms, “Towards information security behavioural compliance,” Comput. Secur., vol. 23, no. 3, pp. 191–198, 2004.
  69. K. M. Parsons, E. Young, M. A. Butavicius, A. McCormac, M. R. Pattinson, and C. Jerram, “The influence of organizational information security culture on information security decision making,” J. Cogn. Eng. Decis. Mak., vol. 9, no. 2, pp. 117–129, 2015, doi: 10.1177/1555343415575152.
  70. S. M. Furnell, N. Clarke, R. von Solms, H. Kruger, L. Drevin, and T. Steyn, “A vocabulary test to assess information security awareness,” Information Management & Computer Security, vol. 18, no. 5, pp. 316–327, 2010.
  71. A. Da Veiga and A. Da Veiga, “Comparing the information security culture of employees who had read the information security policy and those who had not: Illustrated through an empirical study,” Information & Computer Security, vol. 24, no. 2, pp. 139–151, 2016.
  72. A. Nasir, R. A. Arshah, M. R. A. Hamid, and S. Fahmy, “An analysis on the dimensions of information security culture concept: A review,” Journal of Information Security and Applications, vol. 44, pp. 12–22, 2019, doi: 10.1016/j.jisa.2018.11.003.
  73. A. Da Veiga, “Cultivating and Assessing Information Security Culture,” University ot Pretoria., 2008.
  74. R. M. Rashid, O. Zakaria, and N. Zulhemay, “Australian Journal of Basic and Applied Sciences Determining critical success factors ( CSF ) of information security knowledge ( ISK ) towards organisations ’ information security effectiveness,” vol. 8, no. 23, pp. 336–344, 2014.
  75. M. Whitman and H. Mattord, Management of information security. Nelson Education, 2013.
  76. M. Al-Awadi and K. Renaud, “Success factors in information security implementation in organizations,” in IADIS International Conference e-Society, 2007.
  77. A. McIlwraith, Information security and employee behaviour: how to reduce risk through employee education, training and awareness. Taylor and Francis, 2021. doi: 10.4324/9780429281785/INFORMATION-SECURITY-EMPLOYEE-BEHAVIOUR-ANGUS-MCILWRAITH.
  78. M. Zwilling, G. Klien, D. Lesjak, Ł. Wiechetek, F. Cetin, and H. N. Basim, “Cyber Security Awareness, Knowledge and Behavior: A Comparative Study,” Journal of Computer Information Systems, vol. 00, no. 00, pp. 1–16, 2020, doi: 10.1080/08874417.2020.1712269.
  79. A. Alyami, D. Sammon, K. Neville, and C. Mahony, “Critical success factors for Security Education, Training and Awareness (SETA) programme effectiveness: an empirical comparison of practitioner perspectives,” emerald.com, vol. 32, no. 1, pp. 53–73, Jan. 2024, doi: 10.1108/ICS-08-2022-0133/FULL/HTML.
  80. B. J. Oates, Researching information systems and computing. Sage, 2006.
  81. A. Pinsonneault and K. Kraemer, “Survey research methodology in management information systems: an assessment,” Journal of management information systems, vol. 10, no. 2, pp. 75–105, 1993.
  82. O. Zakaria, “Investigating information security culture in a public sector organisation : challenges Malaysian a case,” no. June, pp. 1–200, 2007.
  83. A. Bryman and E. Bell, Business research methods. Oxford University Press, USA, 2015.
  84. A. Al Hogail, “Cultivating and Assessing an Organizational Information Security Culture; an Empirical Study,” International Journal of Security and Its Applications, vol. 9, no. 7, pp. 163–178, 2015, doi: 10.14257/ijsia.2015.9.7.15.
  85. O. Zakaria, “Understanding Challenges of Information Security Culture: A Methodological Issue.,” in In the 2nd Australian Information Security Management Conference, Securing the Future., Perth, Australia, 2004, pp. 83–93.
  86. J. F. Van Niekerk and R. Von Solms, “Information security culture: A management perspective,” Comput. Secur., vol. 29, no. 4, pp. 476–486, 2010, doi: 10.1016/j.cose.2009.10.005.
  87. N. Sohrabi Safa, R. Von Solms, and S. Furnell, “Information security policy compliance model in organizations,” Comput. Secur., vol. 56, pp. 1–13, 2016, doi: 10.1016/j.cose.2015.10.006.
  88. H. A. Kruger and W. D. Kearney, “Consensus ranking--An ICT security awareness case study,” Comput. Secur., vol. 27, no. 7, pp. 254–259, 2008.
  89. S. Al-umaran, “Culture Dimensions of Information Systems Security in Saudi Arabia National Health Services: A thesis submitted in partial fulfilment of the requirements for the degree of Doctor of Philosophy,” no. February, pp. 167–171, 2015, [Online]. Available: https://www.dora.dmu.ac.uk/bitstream/handle/2086/11393/Thesis-1-June 2015-Final-v2.pdf?sequence=1&isAllowed=y
  90. M. Pattinson, K. Parsons, M. Butavicius, A. McCormac, and D. Calic, “Assessing information security attitudes: a comparison of two studies,” Information and Computer Security, vol. 24, no. 2, pp. 228–240, 2016, doi: 10.1108/ICS-01-2016-0009.
  91. H. Liang and Y. Xue, “Understanding security behaviors in personal computer usage: A threat avoidance perspective,” J. Assoc. Inf. Syst., vol. 11, no. 7, p. 394, 2010.
  92. M. Leonard, S. Graham, and D. Bonacum, “The human factor: the critical importance of effective teamwork and communication in providing safe care,” Qual. Saf. Health Care, vol. 13, no. suppl 1, pp. i85--i90, 2004.
  93. J. Hepler, “A good thing isn’t always a good thing: Dispositional attitudes predict non-normative judgments,” Pers. Individ. Dif., vol. 75, pp. 59–63, 2015.
  94. N. S. Safa and R. Von Solms, “An information security knowledge sharing model in organizations,” Comput. Human Behav., vol. 57, pp. 442–451, 2016, doi: 10.1016/j.chb.2015.12.037.
  95. A. Mahfuth, S. Yussof, A. A. Bakar, B. Ali, and W. Abdallah, “A Conceptual Model for Exploring the Factors Influencing Information Security Culture,” vol. 11, no. 5, 2017.
  96. M. Wilson and J. Hash, “Building an information technology security awareness and training program,” NIST Special publication, vol. 800, p. 50, 2003.
  97. R. A. Amr, A. M. Al-Smadi, and R. T. Akasheh, “Diabetes knowledge and behaviour: a cross-sectional study of Jordanian adults,” Springer, vol. 68, no. 2, pp. 320–330, Feb. 2025, doi: 10.1007/S00125-024-06304-3.
  98. A. Alhogail and A. Mirza, “Information Security Culture: A Definition and a Literature review,” Computer Applications and Information Systems (WCCCAIS), no. January, pp. 1–7, 2014, doi: 10.1109/WCCAIS.2014.6916579.
  99. I. Veseli, “Measuring the Effectiveness of Information Security Awareness Program,” Information Security, 2011.
  100. G. A. Churchill, “Title Basic Marketing Research.,” The Dryden Press, no. Fort Worth, 2001.
  101. J. F. Hair, W. C. Black, B. J. Babin, R. E. Anderson, R. L. Tatham, and others, Multivariate data analysis, vol. 5, no. 3. Prentice hall Upper Saddle River, NJ, 2006.
  102. C. Fornell and D. F. Larcker, “Evaluating structural equation models with unobservable variables and measurement error,” Journal of marketing research, pp. 39–50, 1981.
  103. R. B. Kline, Principles and practice of structural equation modeling. Guilford publications, 2005.
  104. J. F. Hair Jr, G. T. M. Hult, C. Ringle, and M. Sarstedt, A primer on partial least squares structural equation modeling (PLS-SEM). Sage Publications, 2016.
  105. J. E. Mathieu and S. R. Taylor, “Clarifying conditions and decision points for mediational type inferences in organizational behavior,” J. Organ. Behav., vol. 27, no. 8, pp. 1031–1056, 2006.
  106. M. S. Garver and J. T. Mentzer, “Logistics research methods: employing structural equation modeling to test for construct validity,” Journal of business logistics, vol. 20, no. 1, p. 33, 1999.
  107. H. A. Kruger and W. D. Kearney, “A prototype for assessing information security awareness,” Comput. Secur., vol. 25, no. 4, pp. 289–296, 2006.
  108. V. Marvik and R. Bakir, “Information security culture: An investigation into the impact of a large-scale cyberattack,” University of Agder, 2023.
  109. T. Kizildeniz, F. B.-K. F. B. Dergisi, and undefined 2024, “Evaluating climate change knowledge, attitudes, and behaviors (kab) in agricultural sciences and technologies education,” dergipark.org.tr, vol. 14, no. 2, pp. 619–633, 2024, doi: 10.31466/kfbd.1400642.
  110. I. Topa and M. Karyda, “Identifying Factors that Influence Employees’ Security Behavior for Enhancing ISP Compliance,” in International Conference on Trust and Privacy in Digital Business, 2015, pp. 169–179.
  111. R. MOHAMAD RASHID, O. ZAKARIA, and M. NABIL ZULHEMAY, “THE RELATIONSHIP OF INFORMATION SECURITY KNOWLEDGE (ISK) AND HUMAN FACTORS: CHALLENGES AND SOLUTION.,” J. Theor. Appl. Inf. Technol., vol. 57, no. 1, 2013.
  112. B. Von Solms, “Information security--the fourth wave,” Comput. Secur., vol. 25, no. 3, pp. 165–168, 2006.
  113. P. Singh, Y. F. Chan, and G. K. Sidhu, A comprehensive guide to writing a research proposal. Venton, 2006.
  114. J. Kaur and N. Mustafa, “Examining the effects of knowledge, attitude and behaviour on information security awareness: A case on SME,” 2013 International Conference on Research and Innovation in Information Systems (ICRIIS), vol. 2013, pp. 286–290, 2013, doi: 10.1109/ICRIIS.2013.6716723.
  115. M. S. bin Othman Mustafa, M. N. Kabir, F. Ernawan, and W. Jing, “An enhanced model for increasing awareness of vocational students against phishing attacks,” in 2019 IEEE international conference on automatic control and intelligent systems (I2CACIS), 2019, pp. 10–14.
  116. M. S. bin Othman Mustafa, M. Nomani Kabir, F. Ernawan, and W. Jing, “An Enhanced Model for Increasing Awareness of Vocational Students Against Phishing Attacks,” 2019 IEEE International Conference on Automatic Control and Intelligent Systems (I2CACIS), no. June, pp. 10–14, 2019, doi: 10.1109/i2cacis.2019.8825070.
  117. A. Almoawi and R. Mahmood, “Applying the OTE model in determining the e-commerce adoption on SMEs in Saudi Arabia,” Asian Journal of Business and Management Sciences, vol. 1, no. 7, pp. 12–24, 2011.
  118. O. Barzak, N. N. A. Molok, S. Talib, and M. Mahmud, “Information security behavior among employees from the Islamic perspective,” Proceedings - 6th International Conference on Information and Communication Technology for the Muslim World, ICT4M 2016, pp. 211–215, 2017, doi: 10.1109/ICT4M.2016.46.
SCImago Journal & Country Rank