Abstract
In recent years, many organizations are concerned with the importance of information security. However, information security measures are not necessarily taken effectively. In this paper, we analyse cause why information security measures in organization are not taken effectively, by focusing on an asymmetry of information in information security risks.