Table A1

Measurement and reliability of the model constructs

Construct (Dijkstra-Henseler rho)Item (scale)LoadingMeanStd. Dev
Risk Management (ρA = 0.944)Information about risks across business processes is considered0.91475.741.357
Information and technical assets critical to the organization are identified0.86096.191.095
Management controls that provide sufficient protection against threats are defined0.91585.541.294
Vulnerabilities in the information systems and related processes are identified regularly0.90405.681.389
Organizational Structure (ρA = 0.910)Information security unit/personnel play important roles in decision-making processes about information security0.88695.691.473
The operation of the overall information security structure is evaluated and adjusted to adapt to changing conditions0.89095.381.373
Information security unit/personnel receive business objectives and needs from relevant unit head0.85545.471.478
IS Awareness (ρA = 0.913)Users are provided with instructions on classifying data in digital operation0.91925.051.566
Users are provided with instructions on classifying data in manual operation0.92534.981.633
Information security awareness briefing is standardized and formalized0.79534.861.941
ISA Maturity Level (ρA = 1.000)Existence of ISA programs. initiatives. applicable tools. and campaigns for improving the skills and abilities of the interested parties (employees. subcontractors. partners. managers. etc.)1.00002.810.893

Note(s): Each item was measured on a seven-point scale. where 1 = strongly disagree. and 7 = strongly agree

Source(s): Authors' development

or Create an Account

Close subscription notice
Close access options