Detert's model on organisational culture
Applying an organisational culture model to Security Culture.
Detert and his colleagues developed a framework of eight overarching, descriptive culture dimensions through an extensive evaluation of the literature on organisational culture. They illustrated their framework in their paper by linking it to a set of values and beliefs that represent the cultural backbone of successful Total Quality Management (TQM) adoption. Detert's eight dimensions of organizational culture are briefly identified below. We adapted this model to help us explore the concept of security culture.
In the use of this model to investigate security cultures in organisations, lots of specific aspects of a security culture, such as attitudes, norms, shared expectations and many more, will not fit nicely within a single dimension of this framework. While it became obvious that the concept of a security culture is too complex to be covered by a single framework or model, the broad nature of this model from organisational culture has ensured that our research identified several important aspects of security culture that we would not have found otherwise. The comprehensive nature of this model has also influenced the extension of our security culture research in new areas such as security governance, the main topic of this web site. Finally, it also gave us a new insight in the need for improved risk assessment methodologies and better management frameworks that can cope with the growing complexity of Information Security.