It seems that there is inconsistency between the calls for the creation of ISC and the findings from the previous
researches. For example information security implementation is still does not have full support of OC in terms of getting
sufficient budget from management, only a small technical group of people is involved who participates in information
security implementation, lacking of management support, and information security risk not in the training schedule.
In summary, reference to OC has found its way into research on ISC. Case studies in ISC repeatedly emphasize the
importance and linkage of OC. However, the linkage and importance of OC often with little further elaboration and do
not focus heavily on underlying cultural factors. The obvious conclusion is that careful attention must be paid to OC in
order to embed ISC successfully. The question remains, what type of cultural environment would be more conducive to
influence employees’ behaviour for ISC embedding?