In an organisational context, knowledge is often
embedded not only in the documents or repositories
but also in the organisational process, practices,
routines and norms [6]. In the organisation,
information and knowledge become recognised as
information assets and also organisational assets [2,
7]. Therefore it is important to protect these
organisational assets from being exposed because
nowadays, internal security incidents have
increasingly become a serious problem in the
organisation. As a result, information security
needs to be implemented and managed within the
organisation to ensure the information is secure. In
order to improve the organisation’s performance
and effectiveness, knowledge management should
be practised because it involves the ideas and
experience of employees, customers and suppliers
[8].Furthermore,knowledge management
encourages knowledge to be created, shared, learnt,
enhanced, and organised, for the benefits of the
organisation [9]. Therefore, the integration of information security and knowledge management is
important in the organisation where all elements on
information security and knowledge management
are consolidated in order to protect the
organisation’s asset and at the same time increase
organisational performance. This is where the term
of information security knowledge is introduced.
The term information security knowledge will be
defined later.