Measurement and reliability of the model constructs
| Construct (Dijkstra-Henseler rho) | Item (scale) | Loading | Mean | Std. Dev |
|---|---|---|---|---|
| Risk Management (ρA = 0.944) | Information about risks across business processes is considered | 0.9147 | 5.74 | 1.357 |
| Information and technical assets critical to the organization are identified | 0.8609 | 6.19 | 1.095 | |
| Management controls that provide sufficient protection against threats are defined | 0.9158 | 5.54 | 1.294 | |
| Vulnerabilities in the information systems and related processes are identified regularly | 0.9040 | 5.68 | 1.389 | |
| Organizational Structure (ρA = 0.910) | Information security unit/personnel play important roles in decision-making processes about information security | 0.8869 | 5.69 | 1.473 |
| The operation of the overall information security structure is evaluated and adjusted to adapt to changing conditions | 0.8909 | 5.38 | 1.373 | |
| Information security unit/personnel receive business objectives and needs from relevant unit head | 0.8554 | 5.47 | 1.478 | |
| IS Awareness (ρA = 0.913) | Users are provided with instructions on classifying data in digital operation | 0.9192 | 5.05 | 1.566 |
| Users are provided with instructions on classifying data in manual operation | 0.9253 | 4.98 | 1.633 | |
| Information security awareness briefing is standardized and formalized | 0.7953 | 4.86 | 1.941 | |
| ISA Maturity Level (ρA = 1.000) | Existence of ISA programs. initiatives. applicable tools. and campaigns for improving the skills and abilities of the interested parties (employees. subcontractors. partners. managers. etc.) | 1.0000 | 2.81 | 0.893 |
| Construct (Dijkstra-Henseler rho) | Item (scale) | Loading | Mean | Std. Dev |
|---|---|---|---|---|
| Risk Management (ρA = 0.944) | Information about risks across business processes is considered | 0.9147 | 5.74 | 1.357 |
| Information and technical assets critical to the organization are identified | 0.8609 | 6.19 | 1.095 | |
| Management controls that provide sufficient protection against threats are defined | 0.9158 | 5.54 | 1.294 | |
| Vulnerabilities in the information systems and related processes are identified regularly | 0.9040 | 5.68 | 1.389 | |
| Organizational Structure (ρA = 0.910) | Information security unit/personnel play important roles in decision-making processes about information security | 0.8869 | 5.69 | 1.473 |
| The operation of the overall information security structure is evaluated and adjusted to adapt to changing conditions | 0.8909 | 5.38 | 1.373 | |
| Information security unit/personnel receive business objectives and needs from relevant unit head | 0.8554 | 5.47 | 1.478 | |
| IS Awareness (ρA = 0.913) | Users are provided with instructions on classifying data in digital operation | 0.9192 | 5.05 | 1.566 |
| Users are provided with instructions on classifying data in manual operation | 0.9253 | 4.98 | 1.633 | |
| Information security awareness briefing is standardized and formalized | 0.7953 | 4.86 | 1.941 | |
| ISA Maturity Level (ρA = 1.000) | Existence of ISA programs. initiatives. applicable tools. and campaigns for improving the skills and abilities of the interested parties (employees. subcontractors. partners. managers. etc.) | 1.0000 | 2.81 | 0.893 |
Note(s): Each item was measured on a seven-point scale. where 1 = strongly disagree. and 7 = strongly agree
Source(s): Authors' development
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.