Triggers of Change in Information Security Management Practices

被引:8
|
作者
Ezingeard, Jean-Noel [1 ]
Bowen-Schrire, Monica [2 ]
机构
[1] Kingston Univ, Kingston Business Sch, Surrey, England
[2] EnergiTek, Segeltorp, Sweden
关键词
D O I
10.1177/030630700703200404
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
Continuous improvements in information security are important in order to ensure that an organisation is adequately protected. Industry codes of practice, international standards and sometimes regulatory and legislative frameworks recommend that reviews should take place at least once a year, and that these reviews should involve various levels in the organisation, including senior management and the board. However, there is evidence that these reviews do not happen as often as recommended. Here, we investigate the kinds of triggers, that can cause an organisation to review its information security policy and policy implementation. We also examine which actors are involved in the information security change process and what form such change takes. The research is based on 26 structured interviews carried out in Sweden and the UK. The results show that awareness of risk amongst directors and senior managers influences how often information security reviews take place and the outcome of these reviews. Apart from reviews, change in information security management (ISM) practice is often triggered by internal or external events.
引用
收藏
页码:53 / 72
页数:20
相关论文
共 50 条
  • [1] Challenges and Best Practices in Information Security Management
    McLaughlin, Mark-David
    Gogan, Janis
    [J]. MIS QUARTERLY EXECUTIVE, 2018, 17 (03) : 237 - 262
  • [2] Information Security Culture: Towards an Instrument for Assessing Security Management Practices
    Lim, Loo S.
    Maynard, Sean B.
    Ahmad, Atif
    Chang, Shanton
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2015, 5 (02) : 31 - 52
  • [3] The impact of information security management practices on organisational agility
    Zaini, Muhamad Khairulnizam
    Masrek, Mohamad Noorman
    Sani, Mad Khir Johari Abdullah
    [J]. INFORMATION AND COMPUTER SECURITY, 2020, 28 (05) : 681 - 700
  • [4] Information security management objectives and practices: A parsimonious framework
    Department of Computer Information Systems, University of Central Missouri, Warrensburg, MO, United States
    不详
    不详
    [J]. Inf. Manage. Comput. Secur., 2008, 3 (251-270):
  • [5] ISO 17799: "BEST PRACTICES" IN INFORMATION SECURITY MANAGEMENT?
    Ma, Qingxiong
    Pearson, J. Michael
    [J]. COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2005, 15 : 577 - 591
  • [6] The Impact of Organizational Practices on the Information Security Management Performance
    Alzahrani, Latifa
    Seth, Kavita Panwar
    [J]. INFORMATION, 2021, 12 (10)
  • [7] Information Security Management Practices: Case Studies from India
    Singh, Abhishek Narain
    Gupta, M. P.
    [J]. GLOBAL BUSINESS REVIEW, 2019, 20 (01) : 253 - 271
  • [8] Conceptualizing the Relationships between Information Security Management Practices and Organizational Agility
    Zaini, Muhamad Khairulnizam
    Masrek, Mohamad Noorman
    [J]. 2013 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER SCIENCE APPLICATIONS AND TECHNOLOGIES (ACSAT), 2014, : 269 - 273
  • [9] Investigation of Information Security Management Practices in Indian Pubic Sector Banks
    Diwakar, Hemalatha
    Naik, Atul
    [J]. 8TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY WORKSHOPS: CIT WORKSHOPS 2008, PROCEEDINGS, 2008, : 276 - +
  • [10] Organizational practices as antecedents of the information security management performance An empirical investigation
    Perez-Gonzalez, Daniel
    Trigueros Preciado, Sara
    Solana-Gonzalez, Pedro
    [J]. INFORMATION TECHNOLOGY & PEOPLE, 2019, 32 (05) : 1262 - 1275