Value-focused assessment of information system security in organizations

被引:162
作者
Dhillon, Gurpreet
Torkzadeh, Gholamreza
机构
[1] Virginia Commonwealth Univ, Sch Business, Dept Informat Syst, Richmond, VA 23284 USA
[2] Univ Nevada, Coll Business, Dept MIS, Las Vegas, NV 89154 USA
关键词
IS security; security values; value-focused thinking; intensive research; qualitative methods;
D O I
10.1111/j.1365-2575.2006.00219.x
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information system (IS) security continues to present a challenge for executives and professionals. A large part of IS security research is technical in nature with limited consideration of people and organizational issues. The study presented in this paper adopts a broader perspective and presents an understanding of IS security in terms of the values of people from an organizational perspective. It uses the value-focused thinking approach to identify 'fundamental' objectives for IS security and 'means' of achieving them in an organization. Data for the study were collected through in-depth interviews with 103 managers about their values in managing IS security. Interview results suggest 86 objectives that are essential in managing IS security. The 86 objectives are organized into 25 clusters of nine fundamental and 16 means categories. These results are validated by a panel of seven IS security experts. The findings suggest that for maintaining IS security in organizations, it is necessary to go beyond technical considerations and adopt organizationally grounded principles and values.
引用
收藏
页码:293 / 314
页数:22
相关论文
共 58 条
[1]  
[Anonymous], ADV QUALITATIVE ORG
[2]  
[Anonymous], IEEE SYST MAN CYB C
[3]  
ARMSTRONG H, 1999, THESIS CURTIN U PERT
[4]  
Backhouse J., 2000, Journal of End User Computing, V12, P33, DOI 10.4018/joeuc.2000040104
[5]   Structures of responsibility and security of information systems [J].
Backhouse, J ;
Dhillon, G .
EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 1996, 5 (01) :2-9
[6]   Electronic trading and work transformation in the London Insurance Market [J].
Barrett, M ;
Walsham, G .
INFORMATION SYSTEMS RESEARCH, 1999, 10 (01) :1-22
[7]   INFORMATION-SYSTEMS SECURITY DESIGN METHODS - IMPLICATIONS FOR INFORMATION-SYSTEMS DEVELOPMENT [J].
BASKERVILLE, R .
COMPUTING SURVEYS, 1993, 25 (04) :375-414
[8]  
Baskerville R., 1991, European Journal of Information Systems, V1, P121, DOI 10.1057/ejis.1991.20
[9]  
Baskerville R, 1989, SYSTEMS DEV HUMAN PR, P241
[10]  
Benbasat I, 2001, INFORM SYST RES, V12, pIII