A framework to prepare an information security awareness and training programme for a provincial government department in the Eastern Cape, South Africa.

dc.contributor.advisorBoucher, Duaneen
dc.contributor.authorPotelwa, Zandileen
dc.date.accessioned2026-08-20T07:23:12Z
dc.date.available2026-08-20T07:23:12Z
dc.date.issued2022-03en
dc.description.abstractProvincial government departments do not have good audit reports on the information security section. The underlying issues are human factors associated with employee interaction with Information and Communication Technology (ICT). The problem to be addressed is how a provincial government needs to focus on employees’ information security awareness so that there is a residual improvement in information security culture to realise unqualified government audits for information security. A case study approach that focused on the provincial government departments in the Eastern Cape Province was used. The primary data was collected using semi-structured interviews containing questions related to information security awareness. Microsoft Teams was used to conduct online semi-structured interviews with 12 provincial government IT staff from two identified provincial departments. The data was analysed using thematic analysis and MS Excel for coding. The findings then were used to determine the outcome of this study which is the framework for preparing an information security awareness programme. The outcome of the study was achieved by condensing the themes that emerged in both the primary and secondary data. The framework was then explained as a way of recommending the importance of preparing information security awareness and training programmes in changing information security behaviour. The derived artefact of this study is an information security awareness framework that can be utilised in a provincial government department to increase the awareness of information security amongst government employees. The contribution of this study is a framework based on the Protection Motivation Theory and the Organisational Culture, to ascertain employees’ actions in relation to information risks and threats; requirements for preparing an information security awareness program for public sector employees and to determine the requirements to be considered when building information security culture in provincial government departments. The proposed framework can then be used to establish an information security culture within the government departments, which will mitigate security risks and threats. The significance of this study as per the constructs of ISA and training show that it can challenge thinking of how ISA can be prepared for not only provincial government but also for state-owned entities or local government.,Thesis (MCom) (Information Systems) -- University of Fort Hare, 2022en
dc.formatcomputeren
dc.formatonline resourceen
dc.formatapplication/pdfen
dc.format1 online resource (158 pages)en
dc.formatpdfen
dc.identifier.citationPotelwa, Zandile. 2022-03en
dc.identifier.othervital:52016en
dc.identifier.otherhttp://hdl.handle.net/10353/22289en
dc.identifier.urihttp://hdl.handle.net/20.500.11837/4993
dc.language.isoEnglishen
dc.publisherUniversity of Fort Hareen
dc.publisherFaculty of Management and Commerceen
dc.rightsUniversity of Fort Hareen
dc.rightsAll Rights Reserveden
dc.rightsOpen Accessen
dc.subjectInformation technology--Security measures.en
dc.subjectEmployees--Training of.en
dc.subjectData encryption (Computer science)en
dc.subjectGrahamstown (South Africa)en
dc.subjectEastern Cape (South Africa)en
dc.subjectSouth Africaen
dc.subjectHistoryen
dc.titleA framework to prepare an information security awareness and training programme for a provincial government department in the Eastern Cape, South Africa.en
dc.typeMaster's thesesen

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
vital_52016+SOURCE1+SOURCE1.0.pdf
Size:
2.24 MB
Format:
Adobe Portable Document Format