Examining the Relationship between Information Security Effectiveness and Information Security Threats

  • Mohamad Noorman Masrek Universiti Teknologi MARA Selangor
  • Tri Soesantari Universitas Airlangga
  • Asad Khan University of Peshawar
  • Aang Kisnu Dermawan Universitas Islam Madura
Keywords: information security, security policy, information threats, structural equation modelling, survey, Malaysia


Information is the most critical asset of any organizations and business. It is considered as the lifeblood of the organization or business. Because of its importance, information needs to be protected and safeguarded from any forms of threats and this is termed as information security. Information security policy and procedure has been regarded as one of the most important controls and measures for information security. A well-developed information security policy and procedure will ensure that information is kept safe form any harms and threats. The aim of this study is to examine the relationship between information security policy effectiveness and information security threats. 292 federal government agencies were surveyed in terms of their and information security practices and the threats that they had experienced. Based on the collected, an analysis using partial least square structural equation modeling (PLS-SEM) was performed and the results showed that there is a significant relationship between information security policy effectiveness and information security threats. The finding provides empirical evidence on the importance of developing an effective information security policy and procedure.


