Although, many organisations have implemented technical solutions to protect information resources from adverse events, internal security breaches continue to occur. Therefore an approach that emphasises an information security culture within the organisation is required to make security a part of employees' daily work routines. In order to develop a successful information security culture within an organisation, it is a need to understand both technical and non-technical aspects of information security. Thus, this paper aims to investigate and discuss the conceptual and methodological issues pertaining the challenges in information security culture. MAMPU (Malaysian Administrative Modernisation and Management Planning Unit) was chosen as the subject of analysis and to serve as the specific in-depth case study for the investigation. In terms of epistemological approach, the interpretivism paradigm has been adopted as the main strategy in inquiry. For data collection, this researc...