International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa SOCIAL AND BEHAVIORAL SCIENCES. Health Care Sciences ORIGINAL RESEARCH An Information Security Assessment Model for Bring Your Own Device in the South African Healthcare Sector Authors’ Contribution: A – Study design; Moeketsi C. B.1 ABCDEFG , Adeyelure T. S.1 ABCDEFG , B – Data collection; Segooa M. A.1 ABCDEFG C – Statistical analysis; 1 D – Data interpretation; Tshwane University of Technology, South Africa E – Manuscript preparation; F – Literature search; Received: 29.06.2024; Accepted: 30.07.2024; Published: 25.12.2024 G – Funds collection Abstract Background and The healthcare sector stands at the forefront of industries embracing personal- Aim of Study: device usage for professional tasks. Permitting to Bring Your Own Device (BYOD) for healthcare professionals presents information security hurdles that pose challenges for decision-makers in the healthcare field, despite the considerable benefits associated with BYOD. The aim of the study: to develop an information-security assessment model for BYOD in the South African healthcare sector to guide healthcare decision-makers. Material and Methods: The main focus of the study was the South African private healthcare sector, Gauteng Province. The target population size of 170 with a sample size of 118 with the feedback responses with additional 10, which were also included in the analysis data statistics that was done for 128 received responses. The instrument used for the closed-ended questionnaire was SPSS 28.0.1.1 and the expert judgement technique for the validation questionnaire. Factors from the diffusion of innovation theory, the electronic protected health information security framework, cybersecurity knowledge, skills, abilities and external variables were adapted to inform the conceptual model. Results: The following factors have the most significant contributions to the development of an information security assessment model for BYOD in the South African healthcare sector: training is the most influential factor with a predictive power of 64.0% (β=0.640) at p=0.001; security threats with 61.3% (β=0.613) significance level p=0.020; conversely, security controls had a predictive power of 50.9% (β=0.509) at p=0.001. Conclusions: This study has developed a contextual information-security assessment model for BYOD within the South African healthcare sector. In practical terms, this model offers guidance to healthcare decision-makers in seamlessly integrating BYOD practices into daily operations; and aids in cautious planning, guided by the insights provided by the security-assessment model for BYOD. Keywords: healthcare, private, information security, bring your own device, South Africa. Copyright: © 2024 Moeketsi C. B., Adeyelure T. S., Segooa M. A. Published by Archives of International Journal of Science Annals DOI: https://doi.org/10.26697/ijsa.2024.2.1 Conflict of interests: The authors declare that there is no conflict of interests Peer review: Double-blind review Source of support: This research did not receive any outside funding or support Information about Moeketsi Catherine Botlwaelo (Corresponding Author) – https://orcid.org/0009- the authors: 0006-4120-7691; cthmoeketsi@gmail.com; Master of Computing, Department of Informatics, Tshwane University of Technology, Pretoria, South Africa. Adeyelure Tope Samuel – https://orcid.org/0000-0002-6138-4285; Doctor of Computing Science and Data Processing, Senior Lecturer, Department of Informatics, Tshwane University of Technology, Pretoria, South Africa. Segooa Mmmatshuene Anna – https://orcid.org/0000-0002-4190-8256; Doctor of Computing, Lecturer, Department of Informatics, Tshwane University of Technology, Pretoria, South Africa. 57 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa Introduction model to assess and mitigate security risks associated Information Communication Technology (ICT) plays a with BYOD adoption. Developing such an information- vital role in facilitating various business solutions, by security assessment model is essential to ensure the offering a wide range of technical and software overall operational efficiency of healthcare providers in application platforms for organizations to enhance their South Africa. To address this research gap, the study operational efficiency. With the continuous evolution of developed an information-security assessment model for technology, organizations are harnessing these Bring Your Own Device in the South African healthcare advancements to stay competitive in the market. This sector. has led to a gradual shift towards digital platforms and The aim of the study. To develop an information-security products for day-to-day operations, transforming assessment model for BYOD in the South African information technology (IT) from a mere service healthcare sector from the perspective of behavioral provider into a strategic asset driving current business science, specifically within the niche of Business operations (Omboga et al., 2021; Pypenko, 2019). Information Systems. Additionally, there is a rising trend of mobility adoption, This research diverges from the traditional pure in which employees utilize their personal devices for computing system approach, focusing instead on both personal and professional tasks. Some understanding the factors that influence information organizations, especially in developing countries, have security in BYOD environments. By examining the implemented permissive policies allowing the use of interactions between the identified factors, the study personal devices for business purposes (Pypenko, & aims to create a contextual model that addresses the Melnyk, 2021; Wani et al., 2021). unique security challenges within the domain of the The utilization of personal devices, such as cellphones, study. This approach underscores the importance of computers, laptops, and tablets in business operations integrating human-centered insights with technical has been proven to boost employee morale, enhance solutions to enhance security measures within the South work performance, and save costs (Mahat & Ali, 2018). African healthcare sector. Employees feel more flexible and comfortable using familiar devices anytime, anywhere. Smart mobile Materials and Methods devices are increasingly prevalent in workplaces as The study employed design science research methods, organizations embrace Bring Your Own Device which aimed to develop artefacts to address research (BYOD) policies (Downer & Bhattacharya, 2022). This problems. This process involves five iterative steps practice positively impacts business processes, (Kuechler & Vaishnavi, 2011). Firstly, there is necessitating strategic planning, user awareness, and awareness of the problem, influenced by preliminary training (Kholoanyane, 2020). BYOD adoption brings investigations that identified the absence of a contextual multiple benefits, including improved performance, information-security assessment model for BYOD in the enhanced business processes, cost-efficiency, and South African healthcare sector. Next, the suggestion of heightened employee morale, leading to increased the artefact as a potential solution is made based on productivity (Coker, 2021). Leveraging personal existing theories. Following that is the development devices enables organizations to realize numerous phase, in which the artefact is created using various advantages, ranging from cost savings to enhanced theories to formulate an assessment-security model for productivity and morale. This approach fosters a more guiding BYOD implementation in the South African agile and connected workforce, particularly crucial in healthcare sector. sectors such as healthcare where rapid access to Validation involves measuring the validity of the information can be lifesaving (Ujakpa et al., 2019). developed artefact through expert judgment. Finally, in In South Africa, the healthcare sector faces challenges the conclusion phase, the results obtained through expert in delivering timely services due to inadequate judgment are presented. A group of selected experts technology support for digital health platforms, mobile validated the developed model, contributing to the health, and smart technology such as BYOD. Such validation process of the artefact. Kuechler and technologies could benefit both the public and private Vaishnavi (2011) commented that the results of an sectors, including medical aid schemes (Ali et al., 2021). artefact or developed model are reflected in the The increasing demand for BYOD as a service conclusion stage of design-science research. underscores its importance in organizational Design science research (DSR) functions as a problem- infrastructure, given its agility, business flexibility, solving paradigm focused on advancing human boosted employee morale, improved productivity, and understanding by creating innovative solutions (vom enhanced employee satisfaction (Abdulkarim & Binord, Brocke et al., 2020). In essence, DSR seeks to enhance 2021). These factors highlight the potential of BYOD to knowledge domains in technology and science by enhance workplace productivity and efficiency. crafting new artefacts that tackle challenges and Despite the acknowledged benefits of BYOD in improve their respective environments. This study enhancing organizational efficiency, there is a critical adhered to the principles of design science research in need for an information-security assessment model line with its overarching objective: the development of specifically tailored for the South African healthcare an information-security assessment model tailored for sector. This sector, already grappling with inadequate BYOD implementation in the South African healthcare technology support, urgently requires a contextualized sector. 58 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa In this study, the researcher collaborated with the ICT According to Yin (2014), measuring instrument with directorate, who facilitated the distribution of the values above 0.7 threshold are acceptable and deemed questionnaire to employees and IT subject matter reliable. The overall reliability of the questionnaire with experts in the healthcare sector. Before distributing the 54 items as demonstrated in Table 1 was found to be questionnaire, a permission letter was issued, and the 0.959, which reliability was considered good since it contact person was assured that data collection would be was above the recommended threshold of 0.7, and anonymous, private, and solely for research purposes. A comparing the number of items in the questionnaire. Google Form was created, and a link was sent to the ICT directorate to aid in distributing it to healthcare staff. Results The research adopted a mixed-method approach, The results demonstrated indicated that all hypotheses integrating both quantitative and qualitative analyses. In were supported after data analysis at an acceptable at the line with this methodology, a survey questionnaire was p value with a significant value less than 0.05, which is adopted, gathering data from a total of 128 randomly acceptable; and therefore, the conceptual model was not selected individuals. Expert Judgement was used in this iterated before it was taken to the experts for validation. study, and the validity of the developed artefact was The reliability statistics table demonstrated relationships determined by the experts’ responses to the developed between constructs were supported. model validation questionnaire. The sample size of 128 respondents was considered and The reliability of the measuring instrument was tested therefore, Part one focused on gathering demographic and was reliable based on the output in Table 1. information such as organization, age, gender, profession, race, educational level, and years of service. Table 1 Part two centered on assessing participants’ knowledge Overall Reliability Statistics of the Measuring of computers, information security, and BYOD. Instrument: Reliability Statistics Participant’s demographics are shown in Table 2, which is broken down into the relevant categories. Table 2 Frequencies of Participants’ Demographics 59 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa The outcomes in Table 2 take the individuals’ the total. According to the table, individuals who were operational space into account. Some of participants between the ages of 36 and 45 made up the highest (14.1%) work within the public sector; these are percentage of participants at 46.1%. individuals who have partnered with the private sector. Pearson’s Correlation of the Constructs About 68.8% of participants work within the private Correlation, in a general sense, assesses the connection sector space. Some of responses (8.6%) were received between variables; and quantifies the degree of for both pharmaceutical and clinical services that are association between two variables (Talaat & Gamel, also partnering with the private healthcare sector. More 2023). When two variables change in magnitude, they responses were attained from the private healthcare do so either in the same direction (positive correlation) sector, at about 68.8% responses. or in the opposite direction (negative correlation) in The outcomes in Table 2 take the individuals’ years correlated data. This technique gauges the relationship within the organization into account. Some of between continuous variables that are both dependent participants (7.8%) had 2 years or less of service. About and independent. Additionally, this method can have 18.8% of participants had between 3-5 years of service. both advantages and drawbacks. A negative correlation About 43.8% of the largest group of participants had 6- suggests that, as the value of one variable increases, the 10 years of experience within the organization; and value of the other variable decreases; whereas a positive 29.7 % of participants had 10 years + of service. correlation indicates that as one variable’s value There were 14.8% of participants with increases, the value of the other variable also increases. matric/certificate. Participants with a bachelor’s degree Table 3 indicates factors grouped together with a made up 28.9% of the group, while those with a post- positive and a significantly high correlation with one graduate degree made up 11.7%. Participants with another. Correlation coefficient values, as outlined by “other” numbered 2.3%, while the 42.2% of survey Schober et al. (2018), range from -1 to 1, with -1 respondents with a diploma yielded the highest indicating a perfect negative correlation; and 1 percentage. indicating a perfect positive correlation. Pearson’s Both genders participated in the survey, according to the correlation approach was employed in this study to findings. The percentage of male participants was represent the relationship between the constructs. 50.8%, while the percentage of female participants was According to Xiong et al. (2020), if p is greater than 0.01 45.3% and ‘other’ made up 3.9% of participants. The but less than or equal to 0.05, a strong assumption about highest number of responses was from male participants the null hypothesis must be made. If p is less than or at 50.8%. equal to 0.01, it indicates a very strong assumption about Participants who were under 25 years made up 6.3% of the null hypothesis. The correlation between the the total. Some 31.3% of participants were between the constructs utilized in this study is depicted in Table 3, ages of 26 and 35; 46.1% were between the ages of 36 which illustrates the relationship between the constructs and 45; and 13.3% were between the ages of 46 and 55. employed in this study. Participants who were 55 and above made up 3.1% of Table 3 Pearson’s Correlation of the Constructs Note. ISA – information-security abilities factors; SECT – security-threats factors; POL – policy factors; SECC – security-controls factors; COMP – compatibility factors; COMPL – complexity factors; TRN – training factors; SECM – information security assessment model for BYOD; ** Correlation is significant at the 0.01 level (2-tailed); * Correlation is significant at the 0.05 level (2-tailed). 60 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa The table shows that information-security abilities (ISA) 0.498 (2-tailed), with security threats of 0.583 (2-tailed), factors have a significant relationship of 0.655 (2-tailed) with policy of 0.606 (2-tailed), with security controls of with security threats, with a significant relationship at 0.675 (2-tailed), with compatibility of 0.490 (2-tailed) the 0.01 level. and with complexity of 0.459 (2-tailed) and all at the Policy factors have a significant relationship of 0.465 (2- 0.01 level. tailed), with ISA factors; and security threats with a Furthermore, there is high value concerning the significant relationship of 0.691 (2-tailed) both at the correlation of security controls and policy of 0.705 (2- 0.01 level. tailed) that is at the 0.01 level. Furthermore, the security control factor has a significant For this reason, an information-security assessment relationship with ISA of 0.420 (2-tailed), a significant model for BYOD can be integrated into day-to-day relationship with security threats of 0.655 (2-tailed), and operations of the healthcare sector. policy factor with a significant relationship of 0.648 (2- The variables show a positive significant relationship at tailed) both at the 0.01 level. a 2-tailed which is supported by Pearson correlation at a Meanwhile, the compatibility factor has a significant R value of 96.9% prediction and a p value less than 0.05. relationship with the ISA factors of 0.324 (2-tailed), with security threats of 0.527 (2-tailed), with the policy Regression Analysis factor of .705 (2-tailed), and a significant relationship In addition to descriptive analysis, a regression analysis with security controls of 0.625 (2-tailed) and all at the was performed to assess the predictive capability of the 0.01 level. overall model and the individual contributions of each Moreover, the complexity factor has a significant independent variable to this prediction. relationship with ISA factors of 0.358 (2-tailed), with The analysis revealed a robust predictive power for the security threats of .558 (2-tailed), with policy of 0.556 model at 94.0% (R2=0.940). (2-tailed), with security control of 0.631 (2-tailed), and The specific contributions of each independent variable lastly a significant relationship with compatibility of to this prediction are detailed in the results presented in 0.704 and all at the 0.01 level. Table 4. Furthermore, the training factor has a significant relationship with information-security ability factors of Table 4 Regression Coefficients* Note. *Dependent variable: SECM – information security assessment model for BYOD; ISA – information-security abilities factors; SECT – security-threats factors; POL – policy factors; SECC – security-controls factors; COMP – compatibility factors; COMPL – complexity factors; TRN – training factors. The results presented in Table 4 reveal significant Ahamed et al. (2023), a Variance Inflation Factor (VIF) contributions of various factors to the development of an exceeding 10 indicates problematic multicollinearity. information security assessment model for BYOD in the However, Table 3 indicates that all VIF values were South African healthcare sector. below 5, indicating an absence of multicollinearity. Training emerged as the most influential factor, with a predictive power of 64.0% (β=0.640) at p=0.001, Testing of the Hypotheses followed by security threats at 61.3% (β=0.613) Based on the regression and correlational analysis, the significance level p=0.020. set hypotheses were tested; and the results are presented Conversely, security controls exhibited a predictive in Table 5. power of 50.9% (β=0.509) at p=0.001. According to 61 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa Table 5 Testing of the Hypotheses Based on these findings, a conceptual model for an South African Healthcare Sector was developed, as information security assessment model for BYOD in the illustrated in Figure 1. Figure 1 An Information Security Assessment Model for Bring Your Own Device in the South African Healthcare Sector Model Validation They indicated that the model is highly appropriate for The validation of the proposed information-security improving business productivity, guiding decision- assessment model for BYOD in the South African makers, and enhancing security measures within the healthcare sector was conducted with seven experts who healthcare sector. The feedback from the experts provided comprehensive feedback. The reviewers, highlighted that the model effectively addresses the possessing diverse qualifications and extensive necessary constructs and requires no modifications, experience in information security, unanimously agreed confirming its adequacy and applicability. From the on the model's relevance, suitability, and significance. feedback obtained from the seven experts’ review, the 62 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa model is considered relevant, suitable, and significant, Policy Factors and it will serve as a guide for decision-makers in It was predicted that H3-Policy Factors will have a assessing information security for BYOD in the South positive influence on the information-security African healthcare sector. The developed artifact was not assessment model for BYOD integration into the South modified as all the constructs were supported. African healthcare sector. This hypothesis was validated, impacting the development of the information-security Discussion assessment model for BYOD integration. Farid et al. The results of this study, all 7 variables were all (2023) define an information-security policy as a widely supported and found to be significant to be integrated into recognized foundational framework for organizational the day-to-day healthcare operations. information security, serving a pivotal role in Information-Security Abilities Factors communicating both acceptable and unacceptable actions It was predicted that H1-Information-Security Abilities concerning the organization’s assets to employees. Factors will have a significant influence on the Consequently, this hypothesis bolsters the information- information-security assessment model for BYOD security assessment model for BYOD integration. integration into the South African healthcare sector. The Security-Controls Factors findings of this study, depicted in Figure 1, supported the It was predicted that H4-Security-Controls Factors will hypothesis. Information-security abilities emerged as have a significant influence in the information-security influential and significant factors in developing an assessment model for BYOD integration into the South information-security assessment model for BYOD African healthcare sector. The hypothesis received integration. Dash and Ansari (2022) underscored the support based on the findings presented in Figure 1 of this necessity of considering extensive competencies such as study. Access control measures are indispensable for skills, experience, and knowledge, along with their safeguarding the information and assets of the healthcare interrelationships, to craft a practical security model. sector against both internal and external threats, thereby Within the healthcare sector, information-security reducing vulnerability to physical and cyberattacks abilities for BYOD signify the depth of skills and (Ayedh et al., 2023). Alshurideh et al. (2023) aver that knowledge relevant to the information-security domain. security measures within computer systems include These assessment models are typically constructed and various techniques such as speech analysis, firewalls, and upheld by experts within the security domain. digital signatures, aimed at protecting software, devices, As noted by Chowdhury and Gkioulos (2023), the and data contained within the system. However, the escalating demand within modern enterprises for security of BYOD technology faces contemporary proficient security professionals has spurred the challenges, including inadequate security controls on proliferation of various programmes and initiatives devices commonly used by healthcare professionals, aimed at imparting security skills and knowledge. concerns regarding device locking and authentication; Despite increased awareness among enterprise staff and issues related to the security of mobile-device regarding security threats, the incidence of successful applications (Wani et al., 2020). Consequently, the attacks against companies has shown little to no decline validated hypothesis indicates that the security-controls over the years. factor significantly influences the integration of an Security-Threats Factors information-security assessment model for BYOD into It was predicted that H2-Security-Threats Factors will the South African healthcare sector. Furthermore, this have a significant influence on the information-security influence can be augmented by implementing robust assessment model for BYOD integration into the South access-control mechanisms for personal devices to African healthcare sector. This hypothesis predicted a safeguard confidential patient information in the positive correlation between the security threats factor healthcare sector. and the integration of the information-security Compatibility Factors assessment model for BYOD in this study. The It was predicted that H5-Compatibility Factors will have questionnaire was designed to evaluate the organization’s a significant influence in the information-security readiness regarding mitigation plans for information- assessment model for BYOD integration into the South security breaches and employee awareness. African healthcare sector. The hypothesis was validated Vulnerabilities in hardware, software, and networks, as per Figure 1 in the study. This indicates that employees along with tactics such as phishing scams and social- and experts in the healthcare sector indeed perceive their engineering techniques, are frequently exploited by daily activities to impact the information-security attackers. These threats often propagate through channels assessment model for BYOD. Neves and Mello (2018) such as drive-by downloads, malicious email posit that security models compatible with a company’s attachments, and deceptive applications (Aslan et al., technologies and infrastructure should remain under the 2023). The hypothesis confirmed that the security factor company’s control; and devices with unfixable significantly influences the integration of an information- vulnerabilities should be prohibited. Additionally, security assessment model for BYOD into the South according to Liao et al. (2021), the compatibility African healthcare sector. Furthermore, this influence perspective is predominantly utilized and particularly can be strengthened through preventive measures such as relevant for understanding users’ technology usage established protocols, training programmes, tailored behaviour. Four compatibility principles compatibility policies, and mitigation strategies. with established work practices, chosen work style, prior 63 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa experience, and value are linked to IT innovation within conclusion, all seven supported constructs contribute to the enterprise context. The compatibility factor an information-security assessment model for BYOD demonstrates a substantial influence on the integration of integration, indicating its potential success in the South the information-security assessment model for BYOD African healthcare sector. Decision-makers can into the South African healthcare sector. effectively integrate this model into their day-to-day Complexity Factors operations and services, bolstering overall security It was predicted that H6-Complexity Factors will measures. Furthermore, future studies should also significantly influence the information-security explore the financial aspects of BYOD. This study only assessment model for BYOD integration into the South focused on identifying factors that influence the African healthcare sector. Complexity refers to how development of the artefact, excluding the financial difficult it is to comprehend or utilize a particular system aspects. The developed model can be the baseline for or technology, which impacts perceptions of innovation. additional factors to be incorporated into the type of Almaiah et al. (2022) suggest that when technology is research to be undertaken. less complex and characterized as simple, it is perceived as highly sophisticated and advantageous, especially if it Conclusions includes new technologies and inventive features. The Adopting new technology platforms presents significant complexity of the developed model needed validation by challenges for daily business operations, but it is essential a group of experts to ensure its integration into the for maintaining competitiveness. Successful integration healthcare sector’s daily operations and services would of new systems requires ongoing support, monitoring, not be overly complex. The validation process involved and maintenance. This study developed an information- experts, who positively responded to the model. Testing security assessment model for BYOD in the South and validation of newly designed models are crucial, as African healthcare sector, with a focus on equipping stated by Hao et al. (2021), necessitating thorough stakeholders with the necessary knowledge for the secure examination by a group of individuals or a pilot group use of personal devices. The research involved 128 before deployment across the organization. Complex respondents and 7 experts, all data collected was valid systems, as highlighted by Freund et al. (2021), offer and used for analysis. The study followed the design significant opportunities for innovation within existing science research process to identify key factors, and and potential fields of application. Strategic complexity develop, and validate the model. The validity of the management frameworks or models for system model within the research domain was confirmed by the deployment encapsulate the complexity of IT systems. A experts. However, the study proposed further survey questionnaire was developed to gather investigation into the financial implications of BYOD, information about the complexity of integrating a which may influence security measures. developed artefact into existing processes. Training Factors Acknowledgments It was predicted that H7-Training Factors will positively The authors wish to acknowledge all those that influence the information-security assessment model for participated in this study. Thank you so much for support. BYOD integration into the South African healthcare sector. The hypothesis found support in the study’s Ethical Approval findings, as illustrated in Figure 1. Beltempo et al. (2022) The study obtained ethical clearance from the institution stressed ongoing research aimed at improving security Ethics Committee (Ref. No. FCRE/ICT/2022/08/002(1). training across the healthcare sector for all employees. This study gave precedence to the training factor, Funding Source evaluating the number of healthcare-sector employees This research did not receive any outside funding or undergoing information-security and BYOD training. support. The survey questionnaire specifically targeted the information-security-awareness training posture among References healthcare-sector employees. Alahmari et al. (2023) Abdulkarim, S., & Binord, F. (2021). The psychological underscored the critical role of effective security training effects of Bring Your Own Device (BYOD). as the primary defence against security breaches. These OIRT Journal of Information Technology, 1(2), researchers advocated for the IT department to prioritize 6–9. https://doi.org/10.53944/ojit-2103 delivering information-security awareness training, with Ahamed, M. I., Biswa, A., & Phukon, M. (2023). A study regular updates on security risks and fraudulent methods, on multicollinearity diagnostics and a few linear ensuring that employees maintain vigilance and prevent estimators. Advances and Applications in unauthorized access to organizational information Statistics, 89(1), 29–54. systems, whether using personal or organizational https://doi.org/10.17654/0972361723050 devices. Alahmari, S., Renaud, K., & Omoronyia, I. (2023). The supported hypothesis highlights the importance of Moving beyond cyber security awareness and the training factors, which may sometimes be training to engendering security knowledge overlooked, but nevertheless significantly enhances sharing. Information Systems and e-Business employees’ vigilance when using personal and Management, 21(1), 123–158. organizational devices for work-related tasks. In https://doi.org/10.1007/s10257-022-00575-2 64 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa Ali, R. F., Ali, S. E. A., Rehman, M., & Sohail, A. (2021). academic libraries: A systematic review (2010- Information security behavior and information 2022). Journal of Information Science. security policy compliance: A systematic https://doi.org/10.1177/01655515231160026 literature review for identifying the Freund, L., Al-Majeed, S., & Millard, A. (2021). transformation process from noncompliance to Towards the definition of a strategic complexity compliance. Applied Sciences, 11(8), Article management framework for complex industrial 3383. https://doi.org/10.3390/app11083383 systems. Proceeding of the 16th International Almaiah, M. A, Alfaisal, R., Salloum, S. A., Hajjej, F., Conference of System of Systems Engineering, Shishakly, R., Lutfi, A., Alrawad, M., Al pp. 210–215. IEEE. Mulhem, A., Alkhdour, T., & Al-Maroof, R. S. https://doi.org/10.1109/SOSE52739.2021.9497491 (2022). Measuring institutions’ adoption of Hao, X., Xiao, Y., Wu, Y., Zhang, Q., & Atkin, G. E. artificial intelligence applications in online (2021). Low complexity suboptimal constellation learning environments: Integrating the innovation design for multi-user multiple access. Proceeding diffusion theory with technology adoption rate. of the 2020 IEEE International Conference on Electronics, 11(20), Article 3291. Electro Information Technology, pp. 259–264. https://doi.org/10.3390/electronics11203291 IEEE. Alshurideh, H. M., Alquqa, E., Alzoubi, H., Kurdi, B., & https://doi.org/10.1109/EIT48999.2020.9208302 Hamadne, S. (2023). The effect of information Kholoanyane, M. E. (2020). Security awareness and security on e-supply chain in the UAE logistics training policy guidelines to minimize the risks of and distribution industry. Uncertain Supply Chain BYOD in a South African SME [Thesis, Northwest Management, 11(1), 145–152. University]. http://hdl.handle.net/10394/36906 https://doi.org/10.5267/j.uscm.2022.11.001 Kuechler, B., & Vaishnavi, V. (2011). On theory Aslan, Ö., Aktug, S. S., Ozkan-Okay, M., Yilmaz, A. A., development in design science research: anatomy & Akin, E. (2023). A comprehensive review of of a research project. European Journal of cyber security vulnerabilities, threats, attacks, and Information Systems, 17(5), 489–504. solutions. Electronics, 12(6), Article 1333. https://doi.org/10.1057/ejis.2008.40 https://doi.org/10.3390/electronics12061333 Liao, X., Wu, D., Zhang, Q., & Han, G. (2021). How to Ayedh, M. A. T., Wahab, A. W. A., & Idris, M. Y. I. improve users’ loyalty to smart health devices? (2023). Systematic literature review on security The perspective of compatibility. Sustainability, access control policies and techniques based on 13(19), Article 10722. privacy requirements in a BYOD environment: https://doi.org/10.3390/su131910722 State of the art and future directions. Applied Mahat, N. B., & Ali, N. B. (2018). Empowering Sciences, 13(14), Article 8048. employees through BYOD: Benefits and https://doi.org/10.3390/app13148048 challenges in Malaysian public sector. Beltempo, E., Karvonen, J., & Rajamaki, J. (2022). International Journal of Engineering & ECHO CyberSkills Framework as a Cyber-Skills Technology, 7(4.35), 643–649. Education and Training Tool in Health and https://doi.org/10.14419/ijet.v7i4.35.23077 Medical Tourism. Proceedings of the 21st Neves, U. M., & de Mello, F. L. (2018). BYOD with European Conference on Cyber Warfare and security. ENIGMA – Journal of Information Security, 21(1), 434–437. Security and Cryptography, 5(1), 40–47. https://doi.org/10.34190/eccws.21.1.274 https://doi.org/10.17648/jisc.v5i1.70 Chowdhury, N., & Gkioulos, V. (2023). A personalized Omboga, S. O., Mukisa, M. T., & Cyprian, R. M. (2021). learning theory-based cyber-security training A bring your own device risk assessment model exercise. International Journal of Information International Journal of Security, 12(2), 15–34. Security, 22, 1531–1546. https://www.cscjournals.org/manuscript/Journals https://doi.org/10.1007/s10207-023-00704-z /IJS/Volume12/Issue2/IJS-158.pdf Coker, T. E. (2021). What human factors are associated Pypenko, I. S. (2019). Digital product: The essence of the with the adoption of BYOD in an organization? concept and scopes. International Journal of [Preprint]. https://doi.org/10.31234/osf.io/ey4qm Education and Science, 2(4), 56. Dash, B., & Ansari, M. F. (2022). An effective https://doi.org/10.26697/ijes.2019.4.41 cybersecurity awareness training model: First Pypenko, I. S., & Melnyk, Yu. B. (2021). Principles of defense of an organisational security strategy. digitalisation of the state economy. International International Research Journal of Engineering Journal of Education and Science, 4(1), 42–50. and Technology (IRJET), 9(4), 1–6. https://doi.org/10.26697/ijes.2021.1.5 https://www.irjet.net/archives/V9/i4/IRJET- Schober, P., Boer, C., & Schwarte, L. A. (2018). V9I401.pdf Correlation coefficients: Appropriate use and Downer, K., & Bhattacharya, M. (2022). BYOD security: interpretation. Anesthesia & Analgesia, 126(5), A study of human dimensions. Informatics, 9(1), 1763–1768. Article 16. https://doi.org/10.3390/informatics9010016 https://doi.org/10.1213/ANE.0000000000002864 Farid, G., Warraich, N. F., & Iftikhar, S. (2023). Digital Talaat, F. M., & Gamel, S. A. (2023). Predicting the information security management policy in impact of no. of authors on no. of citations of 65 International Journal of Science Annals, Vol. 7, No. 2, 2024 рrint ISSN: 2617-2682; online ISSN: 2707-3637; DOI:10.26697/ijsa research publications based on neural networks. Australian hospitals – A national survey. In Journal of Ambient Intelligence and Humanized M. Merolli, Ch. Bain, & L. K. Schaper (Eds.), Computing, 14, 8499–8508. Studies in Health Technology and Informatics, https://doi.org/10.1007/s12652-022-03882-1 Vol. 276: Healthier Lives, Digitally Enabled Ujakpa, M. M., Heukelman, D., Mutasa, L., & (pp. 1–6). https://doi.org/10.3233/SHTI210002 Rodríguez-Puente, R. (2019). Perceived use of Xionga, O. L, Nasric, F., Leanna, M. W. Luic, L. M. W, mobile devices at the workplace and its perceived Gillc, H., Phanc, L., Chen-Lic, D., Iacobuccic, M., effect on performance. Proceeding of the 2019 Ho, R., Majeedc, A., & McIntyre, R. S. (2020). Global Trends in Management, IT and Impact of COVID-19 pandemic on mental health Governance in an e-World (pp. 195–198). in the general population: A systematic review. Vom Broke, J., Hevner, A., & Maedche, A. (2020). Journal of Affective Disorders, 277, 55–64. Introduction to design science research. In vom https://doi.org/10.1016/j.jad.2020.08.001 Brocke, J., Hevner, A., Maedche, A. (Eds.), Yin, R. K. (2014). Case study research design and Design Science Research. Cases. Progress in IS methods (5th ed.). SAGE. (pp. 1–13). Springer. https://doi.org/10.1007/978- https://search.worldcat.org/title/Case-study- 3-030-46781-4_1 research-:-design-and-methods/oclc/835951262 Wani, T. A., Mendoza, A., Smolenaers, F., & Gray, K. (2021). Bring-Your-Own-Device usage trends in Cite this article as: Moeketsi, C. B., Adeyelure, T. S., & Segooa, M. A. (2024). An information security assessment model for bring your own device in the South African healthcare sector. International Journal of Science Annals, 7(2), 57–66. https://doi.org/10.26697/ijsa.2024.2.1 The electronic version of this article is complete. It can be found online in the IJSA Archive https://ijsa.culturehealth.org/en/arhiv This is an Open Access article distributed under the terms of the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited (http://creativecommons.org/licenses/by/4.0/deed.en). 66