0% found this document useful (0 votes)
11 views40 pages

Cybersecurity Methodology in Yemeni Banks

Chapter Three outlines the methodology and procedures of a study investigating the impact of cybersecurity requirements on information systems in Yemeni banks. It describes the study's descriptive approach, data collection methods, sample population, and the design and validity of the questionnaire used for data gathering. The chapter also details the statistical methods employed for analysis, ensuring the reliability and validity of the findings.

Uploaded by

primo phone
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views40 pages

Cybersecurity Methodology in Yemeni Banks

Chapter Three outlines the methodology and procedures of a study investigating the impact of cybersecurity requirements on information systems in Yemeni banks. It describes the study's descriptive approach, data collection methods, sample population, and the design and validity of the questionnaire used for data gathering. The chapter also details the statistical methods employed for analysis, ensuring the reliability and validity of the findings.

Uploaded by

primo phone
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter Three:

Methodology and procedures used


in the study
Chapter Three: Methodology and
Study Procedures
After addressing the most important theoretical
concepts related to the two variables of the study and
presenting previous studies on the subject, this chapter
deals with trying to see the real reality of these concepts
by projecting the theoretical side on the applied side by
studying the extent of the application and impact of
cybersecurity requirements on the protection of
information systems in Yemeni banks, so that it deals with
a description of the procedures followed for the purpose of
achieving the objectives of the study, by describing the
methodology, the sources of data and information
collection, its community and sample, and the study tool,
its validity and stability depending on the methods.
Appropriate statistical through the statistical analysis
programs used.

1.3 Study Methodology:

The study adopted the descriptive approach as the


appropriate scientific method that contributes to the study
and analysis of human, social and administrative
phenomena, and describes the phenomenon accurately
and expresses it qualitatively and quantitatively through
analysis, linking and interpretation to reach conclusions on
which the proposed perception is built, which enables
reaching conclusions and generalizations that help
develop the studied reality.
2.3 Sources and methods of collecting study
data:

Data collection was based on primary and


secondary sources as follows:
 Secondary sources: Rely on secondary data
sources represented in books, published research
and scientific theses.
Primary sources: These are the data collected
from the sample members of the employees in
Yemeni banks through the questionnaire
developed for the purposes of this study.
3.3 Study population and sample:

The study population consisted of workers in the


branches of Yemeni banks (governmental, Islamic, and
commercial) in the governorates of Aden and Taiz, which
numbered (23) banks with a total of approximately 5000
employees at various administrative levels according to
the data of human resources departments in the
mentioned banks, where N
the p ( 1− pThampson
×Stephen ) equation
n=
[[
N −1×( d 2the
was adopted in determining ) + of
÷zsize
2
]
p ( the
1− study ]
p ) sample
according to the following formula

N population size = 5000, Z standard score = 1.96, d


error rate = 0.05, P property availability = 0.50
Substituting into the equation to know the size of the

study sample is as follows:

1250
n= =356.82
3.503201791

Using the random sample method to select vocabulary by


(342) employees of Yemeni banks, where the
questionnaire link was distributed across bank groups on
the social networking site WhatsApp, and a response was
obtained from (250) employees, representing an average
of 73% of the target sample, and Table (3-1) shows the
sample size approved for analysis and the KMO and
Bartlett's Test to analyze the adequacy of the approved
sample size as one of the conditions for implementing
factor analysis.

Table: 3-1
The sample size of the study approved in the analysis
MIS NUMBER OF
UNLI RET DISTRI
FINAL SIN QUESTIONNAIR
KELY URN BUTION
G ES
250 0 0 250 342 TOTAL

73% 0% 0% 73% 96% RATIO

KMO and Bartlett's Test


Kaiser-Meyer-Olkin Measure of
0.969
Sampling Adequacy.
Approx.
12560.316 Chi-
Square Bartlett's Test of Sphericity
1378 Df
0.000 Sig.
Source. Preparation of the researcher based on the results of the
analysis. SPSS
Table (3-1) shows that the value of the KMO index for
the degree of homogeneity of the study sample, which
indicates the adequacy and appropriateness of its size for
each of the study variables, is equal to 97%, which is
greater than the acceptable range of the index, which
should not be less than 50%, and the statistical
significance of Bartlett's test indicates the significance of
the factor model at the level of significance (0.05). The
sample items were distributed according to the banks to
which they belong, as in Table (3-2) and Figure (1.3).

Table: 3-2
Distribution of sample items by bank

PERCENTA DUPLICA
GE % TE
4 10 CAC Bank 1
2 4 Bank of Yemen and Kuwait 2
10 25 National Commercial Bank 3
5 13 Commercial Bank 4
11 27 Arab Bank 5
10 24 Central Bank of Yemen 6
1 3 Yemen Bank for Reconstruction 7
and Development
3 8 Hope Bank 8
2 5 Al Amal Islamic Microfinance 9
Bank
22 54 Tadhamon Bank 10
1 3 Alkuraimi Islamic Bank 11
6 14 Comprehensive Bank of Yemen 12
Bahrain
4 11 First Bank of Yemen 13
1 2 Gulf and Yemen Bank 14
19 47 Saba Islamic Bank 15
100% 250 TOTAL
Source. Preparing the researcher based on the data of the human
resources management of banks.

Shape:(1.3)
Frequency Distribution of Study Sample Items by Bank
Name

300

1 250

200

150
250
100

19 22
50
54 10 11 10
47 6 5
4
11 14 2 3 24 27 13 25 2 4
10 0
1
2 1
3 5 8 1
3 4
‫ال‬
‫ا‬ ‫بن‬ ‫ن‬ ‫ب‬ ‫بن‬ ‫بن‬ ‫ن‬ ‫ب‬ ‫بن‬ ‫ن‬ ‫ب‬ ‫ن‬ ‫ب‬ ‫ال‬ ‫ال‬ ‫ال‬ ‫ال‬ ‫ال‬ ‫ن‬ ‫ب‬ k
‫ج‬ ‫ك‬ ‫كا كا كا كا كا كا ك‬ ‫بن‬ ‫بن‬ ‫بن‬ ‫بن‬ ‫بن‬ ‫ك‬ an
‫كا‬ ‫س‬ ‫ل‬‫ا‬ ‫ل‬ ‫ل‬ ‫ل‬ ‫ل‬ ‫ك‬ ‫ك‬ ‫ك‬ ‫ك‬ ‫ك‬
‫لي‬
‫ا‬ B
‫ي‬
‫ل‬ ‫بأ‬ ‫يم‬ ‫يم‬ ‫تضا كري يم‬ ‫ألم‬ ‫الم ال ي ألم‬ ‫ا‬ ‫ا‬
‫ من أله ل تج ل ع‬AC
‫ا‬
‫ا‬ ‫ن‬ ‫ن‬ ‫ن‬ ‫م‬ ‫م‬ ‫ل‬ ‫ل‬ ‫ن‬ ‫م‬ ‫ر‬ ‫ب‬ ‫ر‬ ‫ا‬ ‫ل‬
‫إل‬ ‫لل‬ C
‫ل بح ألو وال‬
‫ا‬ ‫ا‬ ‫كز‬ ‫وال ي ا ري ي‬
‫س‬ ‫يا‬ ‫ن‬
‫تم‬ ‫ي يل‬ ‫ل‬ ‫ك‬
‫خلي الم‬ ‫ل‬ ‫ر‬ ‫إل‬ ‫و‬ ‫ن‬‫إل‬ ‫ا‬ ‫ت‬ ‫و‬
‫ي‬ ‫س‬ ‫ي‬ ‫لي‬ ‫ج‬ ‫ي‬
‫ي‬ ‫ج‬ ‫ن‬
‫الم‬ ‫لا‬ ‫من شا‬ ‫ار‬ ‫ت‬
‫ال‬ ‫أل‬ ‫ء‬ ‫ي‬ ‫ي‬
‫ش‬ ‫ي‬ ‫وا‬
‫ام‬ ‫ر‬ ‫صغ‬ ‫ع‬ ‫لت‬
‫ل‬ ‫ا‬ ‫م‬
‫س‬
‫إل‬ ‫ير‬
‫الم‬
‫ي‬

‫التكرارات‬ ‫النسبة‬%

Source. Preparing the researcher based on the data of the sample


vocabulary.

4.3 Study Tool:

The questionnaire was chosen as a means of collecting


primary data, which was designed with a survey list of the
opinions of the study sample on the paragraphs of the
study axes and dimensions to study the impact of the
level of availability of cybersecurity requirements in
enhancing the levels of protection of the confidentiality of
information systems in Yemeni banks.

5.3 Questionnaire Design:

In an effort to ensure accuracy and effectiveness, the


questionnaire was prepared according to the closed
question form. This model allows study participants to
choose specific responses to a variety of statements,
designed to cover various aspects of the [Link] axes of
the study were determined after presenting them to the
doctor supervising this study, and then presented to (7)
arbitrators from experts and academics Appendix No. (1),
and after making the required amendments, the
questionnaire was in its final form as in Appendix No. (3),
and its components include two axes, in addition to the
demographic characteristics of the respondents, as
follows:

Part I: Personal data: It is the initial information of the


members of the study sample, including (academic
qualification, specialization, bank name, type of bank, job
title, years of experience specialization, number of
training courses obtained).

Part II: Data related to the study and consists of two


axes:

 The first axis: Independent variables


(cybersecurity requirements) includes 37
paragraphs, and may be represented in four sub-
dimensions: regulatory requirements and contains 10
paragraphs of the questionnaire, technical
requirements contain 9 paragraphs, compliance with
international frameworks and standards contains 10
paragraphs, physical security measures contain 8
paragraphs. Based on previous studies, including:
Al-Sarhan, 2020, Nabila, 2022, Al-Ramadan &
Hasan, 2021.
 The second axis: the dependent variable (protection of

information systems) and contains 16 paragraphs, and the

paragraphs of this variable were adopted based on previous studies

such as: (Alsharabi, 2020

Table: 3-3
Components of the resolution dimensions
NUMBER DIMENSIONS VARIABLES
OF
PARAGRAP
HS
10 Regulatory ) INDEPENDENT
requirements VARIABLE (:
9 Technical CYBERSECURITY
requirements VARIABLES
10 Compliance with
international
frameworks and
standards
8 Physical security
measures
) DEPENDENT
VARIABLE (:
16 PROTECTION OF
INFORMATION
SYSTEMS

53 TOTAL

6.3 Guide to Results Readings for Descriptive


Statistics:
The researcher used the Likert Scale quintuple (Likert
Scale) as a guide to read and interpret the results of the
study for descriptive statistics, which is the scale used in
many administrative studies and others, and the scale
consists of five degrees of approval indicate the highest
(5) to the highest approval, and the lowest (1) to the
lowest approval, and the values are distributed between
2, 3, 4 between approval (disagree, neutral, agree)
respectively , 2022) (Ahmed, M. Kamarruddeen & others.
As shown in Table (3-4).

Table: 3-4

Guide to reading results (Likert pentameter scale)


Strongly Disagre neutra I Strongl Ferry
disagree e l agree y agree
1 2 3 4 5 Grade
Very low low Mediu High Very Approval
m high score level
0-20% 21-40% 41- 61- 81- Materiality
60% 80% 100%

7.3 Validity and stability of the resolution:

The truthfulness of the questionnaire means the extent


of the truthfulness of its phrases, and their ability to
measure the variables that are designed to be measured,
and to verify the validity of the questionnaire used in the
study, the following procedures were measured:

1.7.3 Virtual honesty (content truthfulness):

The validity of standard tools, such as questionnaires,


depends on the arbitrators' assessment of the validity
and reliability of the tool. In this context, the researcher
assigns a group of arbitrators with experience and
specialization in the field of study, such as information
technology and management, in order to verify the clarity
and accuracy of the wording of the paragraphs in the
questionnaire. In the current study, the questionnaire was
presented to 7 specialists and academics in order to
review it and provide their comments on it, and after the
final amendment and the adoption of the observations of
the arbitrators, the questionnaire was distributed.

2.7.3 Statistical methods used:


After the questionnaire was designed, tested,
modified, circulated to the target sample, and then
collected from the respondents, IBM SPSS V.27 and
SMART. PLS 3 using the following statistical methods:

1- Frequencies and percentages of demographic


variables (personal characteristics) of the study
sample.
2- Arithmetic averages and coefficients of variation of
the paragraphs of the study tool and relative
importance
3- Test the box as any to see if the opinions of the
respondents match what is expected of them.
4- Factor loading, to measure the extent to which
paragraphs are loaded on their dimensions.
5- McDonald's coefficient of stability is ω, the coefficient
of stability of Cronbach (Cronbach Alpha).
6- Reliability coefficients (homogeneity coefficient Rho-
A, Composite Reliability, AVE) to study the reliability
and reliability of the study instrument.
7- Discriminant Validity to measure the extent to which
the dimensions of the study are discriminated
through the paragraphs representing it.
8- Confirmatory factor analysis (load coefficients – KMO
test for sample size adequacy)
9- Analysis of nonparametric variance (Kruskal Wallace
test) to find out the difference between the opinions
of the study sample members towards the study
axes, which are attributed to their different
demographic characteristics.
10-Structural equation models (SEM) to find out the
suitability of the theoretical model (appropriateness
of the study tool), according to the answers of the
study sample members, where among the outputs
of measuring and the impact relationship is the
determination coefficient R2, which is relied upon to
explain the changes in the dependent variable,
which are attributed to changes in the independent
variable, in addition to the relationship size
coefficient and the effect F2, which shows the
strength of the relationship of the effect of the
change caused by the independent variable in the
dependent variable.
3.7.3 Internal consistency:

To measure the internal consistency of the dimensions


of the axes of the study, the correlation coefficient
between the categories (Intraclass Correlation) was used,
which is an indicator that expresses the exact concept of
the stability coefficient because it reflects the differences
in performance, and depends on the analysis of variance
(difference) between the paragraphs of the dimension,
and can be measured using the following relationship:

MS betw −MS with


ICC=
MS betw +(n−1)MS with

Table: 3-5
Internal consistency of the paragraphs of the dimensions
of the study

LOWE NUMBER
POINT
UPPER R OF
ESTIMA STUDY DIMENSIONS
95% CI 95% PARAGRAP
TE
CI HS
REGULATORY
0.956 0.936 0.942 10
REQUIREMENTS
TECHNICAL
0.943 0.918 0.934 9
REQUIREMENTS
COMPLIANCE WITH
INTERNATIONAL
0.96 0.943 0.944 10
FRAMEWORKS AND
STANDARDS
PHYSICAL SECURITY
0.946 0.921 0.925 8
MEASURES
PROTECTING THE
CONFIDENTIALITY
0.972 0.96 0.961 16
OF INFORMATION
SYSTEMS
Figure:2.3
Internal consistency of the paragraphs of the dimensions
of the study
100%
0.972 0.946 0.96 0.943 0.956 90%
0.96 0.943 0.918 0.936
0.961 0.921 80%
0.925 0.944 0.934 0.942
70%
60%
50%
40%
16 10 9 10
8 30%
20%
10%
0%

‫تدابير األمن حماية سرية‬ ‫االمتثال‬ ‫المتطلبات‬ ‫المتطلبات‬


‫نظم‬ ‫المادي‬ ‫لألطر‬ ‫الفنية‬ ‫التنظيمية‬
‫المعلومات‬ ‫والمعايير‬
‫الدولية‬

‫عدد الفقرات‬ Point Estimate


Lower 95% CI Upper

The results in Table (3-5) and Figure (2.3) show that all
coefficients of consistency are very high approaching the
correct one, meaning that the paragraphs within each
dimension are very consistent and close, i.e. there is no
difference in opinions between the paragraphs within
each dimension of the study.

8.3 Stability of the study instrument:

The researcher verified the stability of the study tool


using Cronbach's Alpha equation as well as McDonald's ω
to find out the degree of stability of the scale used and its
validity and the stability indicators of the underlying
variables expressing the dimensions of the study, as in
Table (6.3) and Figure (2.3).
Table: 3-6
Values of the Alfakronbach and Macdonald indicators to
measure the stability of the study instrument
NUMBER OF
CRONBACH' MCDONALD'
PARAGRAPH ESTIMATE
SΑ SΩ
S
0.7 0.7 MINIMUM INDEX
REGULATORY
0.942 0.947 10
REQUIREMENTS
TECHNICAL
0.934 0.939 9
REQUIREMENTS
COMPLIANCE
WITH
0.944 0.952 10 INTERNATIONAL
FRAMEWORKS
AND STANDARDS
PHYSICAL
0.925 0.935 8 SECURITY
MEASURES
CYBERSECURITY
0.978 0.981 37
REQUIREMENTS
PROTECTING THE
CONFIDENTIALIT
0.961 0.966 16 Y OF
INFORMATION
SYSTEMS
THE RESOLUTION
0.986 0.987 53
AS A WHOLE

Figure: 3.3
Values of the Alfakronbach and Macdonald indicators to
measure the stability of the study instrument
‫عدد الفقرات‬ McDonald's ω Cronbach's α
60
99%
40
98%
53 20
96%
97% 37
16 93%
94% 94%
95% 93%
94% 94%
95%
8 10 9 10 0

‫ا‬ ‫مت‬ ‫ت‬ ‫ا‬ ‫ال‬ ‫ال‬


‫ال‬
‫ا‬ ‫حم‬ ‫اب‬
‫د‬
‫الم‬ ‫مت‬ ‫مت‬
‫ست‬ ‫ية‬ ‫طل‬ ‫ير‬ ‫ث‬ ‫ت‬
‫با‬ ‫با‬ ‫ا‬ ‫ا‬ ‫طل‬ ‫طل‬
‫نة‬ ‫ل‬ ‫با‬ ‫با‬
‫سر‬ ‫ا‬ ‫ت‬ ‫م‬ ‫أل‬ ‫ل‬
‫كك‬ ‫ية‬ ‫ألم‬ ‫نا‬
‫أل‬
‫ال‬
‫ت‬ ‫تا‬
‫ل‬ ‫ن‬ ‫ن‬ ‫ل‬ ‫ر‬‫ط‬ ‫ف‬ ‫ن‬ ‫لت‬
‫ظ‬ ‫م‬ ‫وا‬ ‫ن‬
‫ما‬
‫ال‬ ‫اد‬ ‫ية‬ ‫ظ‬
‫ل‬ ‫ي‬‫س‬ ‫ي‬ ‫ع‬ ‫لم‬ ‫ي‬ ‫يم‬
‫مع‬ ‫ب‬ ‫اي‬ ‫ة‬
‫لو‬ ‫ران‬ ‫ير‬
‫م‬ ‫ي‬ ‫ا‬
‫ت‬
‫ا‬ ‫لد‬
‫ي‬ ‫ول‬
‫ة‬

Table (3-6) and Figure (33) The stability indicators of


the latent variables expressing the dimensions and axes of
the study, which in their entirety have exceeded the
minimum limits of the range of each indicator, where it is
noted that the stability coefficient (McDonald's ω) has
exceeded the minimum (0.70) for all dimensions, which
indicates that the scale of the study instrument has
acceptable stability levels for the purpose of scientific
research as well as for the stability coefficient of alpha
Crowe Nabach (Cronbach's α) has exceeded the minimum
(0.70) (،‫برزوق‬ ‫ و‬،‫ وسعيدي‬،‫ دحو‬،‫ مليكة‬،‫شيخي‬،2020)، Which
indicates that the vertebrae of the axes and dimensions
have a high degree of stabilityand Confirms the validity
and validity of the questionnaire to analyze the data on
the questions Education , and more detail later in the
analysis of structural equations.
9.3 Indicators of reliability and validity of the
study tool:

To measure the reliability and validity of the study tool,


the coefficient of homogeneity, confidence and differential
honesty coefficient were tested as shown in Table (7.3).

Table: 3-7
Indicators of reliability and validity of the study tool
AVERA
DEGREE
GE HOMOGE
OF
VARIAN DISCRIMIN NEITY
CONFIDE STUDY
CE ATORY COEFFICI
NCE VARIABLES
EXPLAI HONESTY ENT RHO-
COEFFIC
NED A
IENT CR
AVE
Greater
Greater than Greater Greater INDICATOR
than
0.70 than 0.70 than 0.70 RANGE
0.50
REGULATORY
0.657 0.811 0.950 0.943 REQUIREMENT
S
TECHNICAL
0.656 0.810 0.945 0.936 REQUIREMENT
S
COMPLIANCE
WITH
INTERNATIONA
0.666 0.816 0.952 0.946 L
FRAMEWORKS
AND
STANDARDS
PHYSICAL
0.659 0.812 0.939 0.928 SECURITY
MEASURES
CYBERSECURIT
Y
0.563 -- 0.979 0.979
REQUIREMENT
S
PROTECTING
THE
CONFIDENTIALI
0.629 0.793 0.964 0.962
TY OF
INFORMATION
SYSTEMS
Figure: 4.3
Indicators of reliability and validity of the study tool
100%
90%
63% 56% 66% 67% 66% 66%
80%
0% 70%
79% 81% 82% 81% 81% 60%
98% 50%
96% 94% 95% 95% 95% 40%
30%
20%
98% 10%
96% 93% 95% 94% 94%
0%

‫حماية‬ ‫متطلبات‬ ‫تدابير‬ ‫المتطلبات المتطلبات االمتثال‬


‫سرية نظم‬ ‫األمن‬ ‫األمن‬ ‫لألطر‬ ‫الفنية‬ ‫التنظيمية‬
‫السيبراني المعلومات‬ ‫المادي‬ ‫والمعايير‬
‫الدولية‬

‫ معامل التجانس‬Rho-A ‫ درجة معامل الثقة‬CR


‫الصدق التميزي‬ ‫ متوسط التباين المفسر‬AVE

Table (3-7) and Figure (4.3) shows the values of each of


the coefficient of homogeneity, confidence coefficient,
discriminatory honesty coefficient, average interpreted
variance and the range of acceptance for each indicator,
as it shows that all the values of the indicators mentioned
within the range of acceptance specified for all dimensions
and axes of the study, which means that the dimensions
explain most of the variance of its paragraphs and that all
factors (dimensions) have represented the measured
variables (paragraphs) constituent to a high degree, and
therefore the study tool is characterized by high levels of
structural honesty and levels of homogeneity of its
structural components and the possibility of Distinguishing
among them through paragraphs that represent each
dimension for the purposes of scientific research.
Chapter Four:

Analyze data and discuss results


Chapter Four: Data Analysis and Discussion of
Results

This chapter deals with a presentation of data analysis


and hypothesis testing, where it provides a detailed
description of the demographic variables related to the
respondents in the study sample, an analysis of their
answers to the paragraphs of the study tool, a description
of the variables of the study model and its sub-
dimensions, as well as the results of testing the
hypotheses reached by the study, as well as discussing
and commenting on them and presenting conclusions and
recommendations.

1.4 Presentation and analysis of demographic data


of the study sample:

This part presents the results of the analysis of the


demographic data of the study sample members , as
follows:
1.1.4 Qualification variable:
The academic qualification variable deals with the
frequency and percentages of academic qualifications
obtained by the sample members as shown in Table (4-
1) and Figure (1.4).
Table: 4-1
Characteristics of the sample members according to the
variable of academic qualification
Percentage Iteration Qualification
%
2 6 High school or less
6 16 diploma

74 186 Bachelor

15 38 Master

2 4 Doctor

Total
100 250

Figure: 1.4
Characteristics of the study sample according to the
variable of academic qualification

94 100
90
80
70

54 60
50
37 38 37 40
30
22 22
15 15 20
9 6 10
2
0
‫أخرى‬ ‫محاسبة‬ ‫إدارة‬ ‫مالية‬ ‫تكنولوجيا‬ ‫شبكات‬
‫أعمال‬ ‫ومصرفية‬ ‫معلومات‬

‫التكرار‬ ‫النسبة المئوية‬%

Table (4-1) and Figure (1.4) show the frequency


distribution and percentage of the demographic
characteristics of the study sample, and the majority of
respondents came from holding a bachelor's degree by
approximately 74%, while holders of a master's degree
came in second place by about 15%, followed by diploma
holders by about 6%, and the remaining percentage was
distributed among high school 2% and holders PhD
approximately 2%.
The results show that the Yemeni banking sector attracts
individuals with a good level of education, which may
facilitate the process of training and enhancing their
cybersecurity skills. The presence of a good percentage of
master's holders demonstrates the availability of an
advanced and dependable knowledge base to understand
and implement complex cybersecurity requirements.

2.1.4 Variable Specialization:


This part deals with the characteristics of the study
sample according to the specialization variable as shown
in Table (4-2) and Figure (2.4) below as follows::
Table: 4-2
Characteristics of the study sample according to the
specialization variable

Percentage % Iteration Specialization


2 6 Networks

9 22 Information
Technology
15 37 Finance & Banking

22 54 Business
Administration
38 94 accounting

15 37 Other

100% 250 Total

Figure: 2.4
Characteristics of the study sample according to the
specialization variable
94
100
90
80
70
54
60
50 37 38 37
40
22 22
30 15 15
20 6 9
2
10
0
‫شبكات‬ ‫تكنولوجيا‬ ‫مالية‬ ‫إدارة‬ ‫محاسبة‬ ‫أخرى‬
‫معلومات‬ ‫ومصرفية‬ ‫أعمال‬
‫التكرار‬

Table (4-2) and Figure (2.4) show that the majority of


respondents hold accounting specialization by 38%,
business administration majoring came in second place
by 22%, while finance and banking majoring came third
with 15%, information technology 9%, networks 2%, and
other disciplines not classified 15%.

These results are attributed to the nature of the work


carried out by banks, where most of the jobs are focused
on accounting specialization as they are commensurate
with the tasks assigned to them, followed by business
administration specialization to match the requirements of
work in the banking sector.

3.1.4 Job Title Variable:


This part deals with the characteristics of the study
sample according to the variable of job title as shown in
Table (4-3) and uncertaintyfor (3.4) below as follows:
Table: 4-3
Characteristics of the study sample according to the job
title variable
Percentage % Iteration Job Title
4 11 Senior Management

7 17 Director of
Administration
5 13 Deputy Director of
Administration
29 72 Head of Department

55 137 employee

100% 250 Total

Figure: 3.4
Characteristics of the study sample according to the job
title variable

137
140

120

100
72
80
55
60

40 29
17 13
11 7 5
20 4
0
‫االدارة‬ ‫نائب مدير مدير إدارة‬ ‫رئيس‬ ‫موظف‬
‫العليا‬ ‫إدارة‬ ‫قسم‬
‫التكرار‬
‫النسبة المئوية‬%

Table (4-3) and Figure (3.4) show that the majority of the
sample members are employees with 55% of the total
sample size, while heads of departments represented 29%
and the remaining percentage was distributed among
deputy directors, managers and senior management.

These results reflect the concentration of the largest


number of staff at lower levels of administrative functions
(operational management), who constitute the mainstay in
accomplishing many day-to-day tasks, while the number
of posts has shrunk up the administrative pyramid to
senior management.

4.1.4 Years of Experience Variable:


This part deals with the characteristics of the study
sample according to the variable of years of experience
as shown in Table (4-4) and Figure (4.4) below as follows::
Table: 4-4
Characteristics of the study sample according to the
variable of years of experience

Percentage % Iteration Years of Experience


41 102 5 to 10 years

34 84 From 10 to 20 years
old
26 64 More than 20 years

100% 250 Total

Figure: 4.4

Characteristics of the study sample according to the experience variable


120
102
100
84
80
64
60
41
34
40 26

20

0
‫ إلى‬5 ‫ إلى من‬10 ‫ من‬20 ‫أكثر من‬
10‫سنوات‬ ‫سنة‬20 ‫سنة‬
‫التكرار‬
‫النسبة المئوية‬%

Table (4-4) and Figure (4.4) show that the highest


percentage of those with experience between 5 to less
than 10 years at approximately 34%, followed by those
with experience from 10 years to 20 years at 34%,
followed by those with experience above 20 years at
26%.

These results reflect banks' awareness of the importance


of providing medium expertise capable of dealing with
modern technology and their ability to learn and adapt to
new and advanced security systems.

5.1.4 Bank Type Variable:


This part deals with the characteristics of the study
sample according to the variable of the type of bank as
shown in Table (4-5) and Figure (5.4) below as follows::
Table: 4-5
Characteristics of the study sample according to the bank
type variable
Percentage % Iteration Bank Type
15 37 governmental

38 94 Commercial

48 119 Islamic

100% 250 Total

Figure: 5.4

Characteristics of the study sample according to the bank


type variable
119
120
94
100

80
48
60
37 38
40
15
20

0
‫حكومي‬ ‫تجاري‬ ‫إسالمي‬
‫التكرار‬

Table (4-5) and Figure (5.4) show that the members of


the study sample are distributed according to the type of
bank in which they work into Islamic banks by 48%,
commercial banks by 38% and government banks by
about 15%.

This indicates that Islamic banks accounted for 48% of the


respondents under study, while commercial banks came
second with 38%.

6.1.4 Bank Name Variable:


This part deals with the characteristics of the study
sample according to the variable of the name of the bank
as shown in Table (4-6) and the figure (6.4) below as
follows:
Table: 4-6
Characteristics of the study sample according to the bank
name variable

Percentage % Iteration Bank Name


4 10 Credit Bank (CAC
Bank)
2 4 Commercial Bank of
Yemen
10 25 National Commercial
Bank
5 13 Commercial Bank

11 27 Arab Bank

10 24 Central Bank of Yemen

1 3 Yemen Bank for


Reconstruction and
Development
3 8 Hope Bank

2 5 Al Amal Islamic
Microfinance Bank
22 54 Tadhamon Bank

1 3 Alkuraimi Islamic Bank

6 14 Comprehensive Bank
of Yemen Bahrain
4 11 First Bank of Yemen

1 2 Gulf and Yemen Bank

19 47 Saba Islamic Bank

100% 250 Total

Figure: 6.4
Characteristics of the study sample according to the bank
name variable

60 54
‫التكرار‬
‫النسبة المئوية‬% 47
50

40

27
30 25 24
22
19
20 14
10 10 13 11 10 11
8
10 5 5 6
4 4 3 3 3 4
2 1 2 1 21
0

Table (4-6) and Figure (6.4) show that Tadhamon


Bank accounts for the majority of the surveyed sample
with 22% of the total sample, Saba Bank comes in second
place with 19%, while Arab Bank accounted for 11% and
came third, while the rest of the sample members were
distributed among the rest of the banks under study in
different proportions.

The majority of respondents in Al Tadamon and Saba


Bank, representing 101 employees out of a total of 250
employees for 15 banks, attributed them to the retention
of a larger number of their employees, while most banks
tend to reduce their functions as a result of the reflection
of the economic conditions of the country on their banking
activities, while Islamic banks remain less affected due to
the nature of their activities.
7.1.4 Variable number of cycles:
This part deals with the characteristics of the study
sample according to the variable number of cycles as
shown in Table (4-7) and Figure (7.4) below as follows::
Table: 4-7
Characteristics of the study sample according to the
variable of the number of cycles

Percentage % Iteration Number of cycles


19 47 Session

17 42 Two courses

23 58 Three and more

41 103 Nothing

100% 250 Total

Figure: 7.4
Characteristics of the study sample according to the
variable of the number of cycles

120
103
100

80
58
60 47
42 41
40 23
19 17
20

0
‫ث‬
‫دو دو‬ ‫ال‬ ‫أل‬
‫رتا ره‬ ‫ث‬ ‫ش‬
‫ن‬ ‫ف‬ ‫يء‬ ‫التكرار‬
‫ث‬ ‫أك‬
‫ر‬

Table (4-7) and Figure (7.4) show that 41% of


respondents did not receive any training courses in the
field of cybersecurity, while 23% received more than two
courses, 19% only one course and17% two courses. The
high percentage of individuals who have not received
training courses indicates that there is a large gap in
training and qualification that must be filled to ensure
raising awareness and efficiency in the field of
cybersecurity.
2.4 Descriptive analysis of the results according
to the components of the questionnaire:

This part deals with the descriptive analysis of the


results of the study variables, represented by the
independent variable: cybersecurity requirements, and the
dependent variable: protection of information systems,
and the weighted arithmetic mean was used with the
frequencies of scale scores, relative importance, and
standard deviations, to find out the degree of agreement
of the sample members with the study variables.

1.2.4 Results of Dimension Analysis of the


Independent Variable (Cybersecurity
Requirements)
This section includes the results of the analysis of the
dimensions of the independent variable: cybersecurity
requirements, namely (regulatory requirements, technical
requirements, compliance with international frameworks
and standards, physical security measures), as follows:
[Link] The results of the analysis of the paragraphs of the first
dimension (regulatory requirements):

This part deals with the arithmetic averages, the coefficient of


variation, relative importance, the significance of good conformity, and
the degrees of agreement of the respondents' answers to the level of
availability of regulatory requirements for cybersecurity in protecting
information systems in Yemeni banks, Table (4-8) illustrates this.
Table: 4-8
Results of the analysis of regulatory requirements
paragraphs
Loadi Moral Coeffic
Weigh
ng good ient of Materi Paragra
ted Icon
facto confor variati ality ph
mean
r mity on
0.811 0.000 23 % 81 % 4.03 The Bank Remote
regularly Size:
updates
its
cybersec
urity
policies in
accordan
ce with
regulatio
ns set by
internatio
nal
bodies
and
organizati
ons.
0.842 0.000 27 % 80 % 3.98 The bank Movie
has a Accesso
dedicated ries
team
responsib
le for
ensuring
complian
ce with
cybersec
urity
regulatio
ns.
0.801 0.000 32 % 73 % 3.64 The Bank Classic
regularly Camera
trains
employee
s on
regulator
y
requirem
ents in
the field
of
cybersec
urity.
0.781 0.000 31 % 74 % 3.68 The Classic
external Camera
audit
team
conducts
internal
audits to
assess
the
Bank's
complian
ce with
cybersec
urity
regulatio
ns.
0.822 0.000 27 % 78 % 3.92 The Bank Classic
shall take Camera
a clear
incident
response
plan as
required
by the
regulatio
ns.
0.864 0.000 27 % 75 % 3.75 The Bank x6
complies
with
mandator
y
reporting
requirem
ents for
cybersec
urity
incidents.
0.773 0.000 30 % 72 % 3.59 The Bank x7
attends
industry
forums
and
workshop
s related
to
cybersec
urity
regulatio
ns
internally
and
externally
.
0.847 0.000 30 % 77 % 3.86 The Bank Remote
takes control
strict and
determin
ed action
to
address
non-
complian
ce with
regulator
y
requirem
ents.
0.836 0.000 25 % 76 % 3.82 The Bank Wireless
cooperate Phones
s with
regulator
y
authoritie
s in
addressin
g
cybersec
urity
issues.
0.859 0.000 28 % 76 % 3.78 The bank Wireless
adopts Accesso
regulator ries
y
complian
ce an
important
aspect of
its
cybersec
urity
strategy.
Regulatory
23 % 76 % 3.81
requirements
Table (4-8) shows the description of the response to
the individuals of the study sample according to the level
of approval scale based on the arithmetic average
weighted by the frequencies of the scale's scores and its
relative importance relative to the highest degree in it,
which shows the degree of approval of the average of the
regulatory requirements dimension as one of the
dimensions of cybersecurity requirements with an
arithmetic average of (3.81), relative importance (76%),
and a coefficient of difference (23%).

Based on the order of paragraphs in order of relative


importance, paragraph (x2) states: "The Bank has a
dedicated team responsible for ensuring compliance with
cybersecurity regulations." with relative importance
(80%) and a coefficient of variation (27%) came in first
place and came paragraph (x7), which states: "The Bank
attends industry forums and workshops related to
cybersecurity regulations internally and externally." In the
last place with relative importance (72%) and a coefficient
of variation (30%) The statistical significance of the square
test as any for good conformity indicates the significance
of the respondents' opinions according to the frequency of
the approval levels on all paragraphs representing the
regulatory requirements at the level of significance 0.01,
and the loading coefficients after the regulatory
requirements on the paragraphs that measure it and
represent it indicate a high degree of consistency (greater
than 0.40) for the response levels of respondents
according to the scale of the study tool on all dimensions
paragraphs.

By analyzing the data related to the regulatory


requirements of the banks under study, it can be noted
that the reference paragraph (2x) states that the banks
targeted in the study owe a periodic commitment to renew
cybersecurity policies in accordance with the standards
and requirements issued by international bodies and
organizations. The weighted estimate for the said
paragraph has been set at 4.03, which confirms the banks'
continued commitment to the standards Global
regulatory. In the same vein, reference paragraph x7
shows a weighted rating value of 3.59, indicating a gap in
directing the surveyed banks towards active participation
in industry forums and workshops related to cybersecurity.
In addition, a deficiency was identified in the x3 reference
paragraph where it was assigned a weighted rating value
of 3.64, demonstrating the urgent need to develop
employee training efforts in line with regulatory
requirements.

In this context, the results show that banks take


cybersecurity seriously, but there is a need to increase
efforts in some areas of training and participation in
industry forums to achieve a higher level of compliance
and response to cyber threats.
[Link] The results of the analysis of the paragraphs of the
second dimension (technical requirements):

This part deals with weighted averages, relative importance,


coefficients of difference, and the significance of good conformity to the
responses of the respondents to the level of availability of technical
requirements for cybersecurity in protecting information systems in
Yemeni banks, Table (4-9) illustrates this.
Table: 4-9
Results of paragraph analysis after technical requirements
Loadi Moral Coeffici Materi Weigh Paragraph Ico
ng good ent of ality ted n
facto confor variatio mean
r mity n
0.810 0.000 20 % 86 % 4.32 The bank C1
uses the
latest
antivirus
and
antivirus
software on
all systems.
0.818 0.000 23% % 81 % 4.04 The bank C2
relies on
strong
encryption
technologie
s such as
SSL/TLS
(Secure
Sockets
Layer/Trans
port Layer
Security)
0.865 0.000 26 % 79 % 3.97 The bank C3
has the
next
generation
of firewalls
to protect
its
information
systems
from
external
threats.
0.837 0.000 24 % 80 % 3.99 The Bank C4
relies on
advanced
intrusion
detection
and
prevention
technologie
s, such as
intrusion
detection
systems
(IDS).
0.832 0.000 22 % 82 % 4.10 The Bank C5
conducts
regular
security
updates
and
patches to
software
and
hardware
component
s.
0.835 0.000 25 % 81 % 4.05 The Bank C6
establishes
procedures
for secure
access to
its
information
systems.
0.864 0.000 26 % 78 % 3.91 The bank c7
regularly
conducts
vulnerabilit
y
assessment
s and
penetration
testing on
its
information
systems.
0.797 0.000 25 % 83 % 4.13 The bank C8
has secure
and fast
measures
in place to
automatical
ly back up
important
data and
designs at
any
moment.
0.697 0.000 23 % 79 % 3.94 The bank c9
uses virtual
networks
such as
VLANs
(Virtual
Local Area
Networks)
19 % 81 % 4.05 Technical
requirements
Table (4-9) shows the description of the response to
the study sample members according to the approval
level scale based on the weighted arithmetic average of
the frequencies of the scale's scores and its relative
importance relative to the highest degree in it, which
shows a high degree of approval for the dimension of
technical requirements as one of the dimensions of
cybersecurity requirements with an arithmetic average of
(4.05), relative importance (81%) and a coefficient of
difference (19%).

Based on the order of paragraphs according to relative


importance, paragraph (c1) states: "The Bank uses the
latest antivirus and anti-virus programs on all
[Link] relative importance (86%) and a coefficient
of variation (27%) came in first place and paragraph (c7)
states: "The Bank shall establish procedures for secure
access to its information systems." in the last place with
relative importance (78%) and a coefficient of variation
(26%) The statistical significance of the square test as any
for good conformity indicates the significance of the
respondents' opinions according to the frequencies of the
approval levels on all paragraphs representing the
technical requirements at the level of significance 0.01,
and the loading coefficients after the technical
requirements on the paragraphs that measure it and
represent it indicate a high degree of consistency (greater
than 0.40) for the response levels of respondents
according to the scale of the study tool on all paragraphs
of the dimension.

It is clear from reference paragraph (c8) that there is


a commitment on the part of banks to have secure and
reliable measures for automatic backup of data and
master designs, and this is confirmed by the weighted
estimate value of (4.13). This expresses banks'
unwavering commitment to ensuring business continuity
and safeguarding essential information. On the other
hand, reference paragraph (c9) which received a
weighted estimate of 3.94 – indicates that the use of
VLANs may need to be enhanced and developed to ensure
higher network security.

On the other hand, a deficiency has been identified in


the reference paragraph (C7), which was assigned a
weighted estimate value of (3.91), which shows the need
to increase the efforts of banks in conducting vulnerability
assessments, penetration tests and security gap
assessments, the difference can be seen between the
reference paragraphs (C8) ( 4.13) and (C9) (3.94) This
The difference highlights the relative distinction of
automatic backup technologies when compared to VPNs,
which indicates the need to evaluate and develop security
strategies related to network technology in Yemeni banks.
[Link] Results of the analysis of the paragraphs of the third
dimension (compliance with international frameworks
and standards):

This part deals with weighted averages, relative importance, coefficients


of variation, and the significance of good conformity to the respondents'
answers to the level of compliance with international
frameworks and standards for cybersecurity in protecting
information systems in Yemeni banks, Table (4-10)
illustrates that

You might also like