USER PARTICIPATION IN INFORMATION SYSTEMS SECURITY RISK MANAGEMENT

被引:5
作者
Spears, Janine L. [1 ]
Barki, Henri [2 ]
机构
[1] Depaul Univ, Chicago, IL 60604 USA
[2] HEC Montreal, Montreal, PQ H3T 2A7, Canada
关键词
Information security; user participation; security risk management; Sarbanes-Oxley Act; INVOLVEMENT; AWARENESS; IMPACT;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper examines user participation in information systems security risk management and its influence in the context of regulatory compliance via a multi-method study at the organizational level. First, eleven informants across five organizations were interviewed to gain an understanding of the types of activities and security controls in which users participated as part of Sarbanes-Oxley compliance, along with associated outcomes. A research model was developed based on the findings of the qualitative study and extant user participation theories in the systems development literature. Analysis of the data collected in a questionnaire survey of 228 members of ISACA, a professional association specialized in information technology governance, audit, and security, supported the research model. The findings of the two studies converged and indicated that user participation contributed to improved security control performance through greater awareness, greater alignment between IS security risk management and the business environment, and improved control development. While the IS security literature often portrays users as the weak link in security, the current study suggests that users may be an important resource to IS security by providing needed business knowledge that contributes to more effective security measures. User participation is also a means to engage users in protecting sensitive information in their business processes.
引用
收藏
页码:503 / 522
页数:20
相关论文
共 65 条
  • [1] Alberts C.J., 2003, MANAGING INFORM SECU
  • [2] [Anonymous], 2006, P 39 ANN HAW INT C S, DOI DOI 10.1109/HICSS.2006.481
  • [3] [Anonymous], P 11 AM C INF SYST O
  • [4] Aytes K., 2004, Journal of Organizational and End User Computing, V16, P22, DOI 10.4018/joeuc.2004070102
  • [5] RETHINKING THE CONCEPT OF USER INVOLVEMENT
    BARKI, H
    HARTWICK, J
    [J]. MIS QUARTERLY, 1989, 13 (01) : 53 - 63
  • [6] MEASURING USER PARTICIPATION, USER INVOLVEMENT, AND USER ATTITUDE
    BARKI, H
    HARTWICK, J
    [J]. MIS QUARTERLY, 1994, 18 (01) : 59 - 82
  • [7] AN EMPIRICAL-STUDY OF THE IMPACT OF USER INVOLVEMENT ON SYSTEM USAGE AND INFORMATION SATISFACTION
    BAROUDI, JJ
    OLSON, MH
    IVES, B
    [J]. COMMUNICATIONS OF THE ACM, 1986, 29 (03) : 232 - 238
  • [8] Chin WW, 1998, QUANT METH SER, P295
  • [9] User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach
    D'Arcy, John
    Hovav, Anat
    Galletta, Dennis
    [J]. INFORMATION SYSTEMS RESEARCH, 2009, 20 (01) : 79 - 98
  • [10] Response rate and response quality of Internet-based surveys: An experimental study
    Deutskens, E
    De Ruyter, K
    Wetzels, M
    Oosterveld, P
    [J]. MARKETING LETTERS, 2004, 15 (01) : 21 - 36