Information systems security resilience as a dynamic capability

被引:3
|
作者
Goel, Lakshmi [1 ]
Russell, Dawn [2 ]
Williamson, Steven [3 ]
Zhang, Justin Zuopeng [3 ]
机构
[1] Univ North Florida, Coggin Coll Business, Dept Management, Jacksonville, FL USA
[2] Univ North Florida, Coggin Coll Business, Dept Mkt & Logist, Jacksonville, FL USA
[3] Univ North Florida, Coggin Coll Business, Dept Management, Jacksonville, FL 32224 USA
关键词
Information systems; Security; Resilience; Dynamic capability; RESOURCE-BASED VIEW; SCALE DEVELOPMENT; DISRUPTION; FRAMEWORK; IMPACT; FIRMS;
D O I
10.1108/JEIM-07-2022-0228
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
PurposeWhile the idea of the resilience of information systems security exists, there is a lack of research that conceptualizes, defines and specifies a way to measure it as a dynamic capability. Drawing on relevant cybersecurity and dynamic capabilities literature, this study aims to define Information Systems Security Resilience (ISSR) as a "dynamic capability of a firm to respond to, and recover from, a security attack" and test it as a new construct.Design/methodology/approachThe authors employ a methodology including multiple phases to develop and test this construct of ISSR. The authors first interview senior managers from various organizations to establish the face validity of the construct; then develop and analyze a pilot survey for internal validity and reliability; and finally, design and deploy a field survey to test and externally validate the construct.FindingsThe authors conceptualize and define the construct of ISSR as a dynamic capability, develop a scale for its measurement and test it in a pilot and field survey. The construct is valid, and the measurement tool works. It demonstrates that resilience is something that is done, rather than had. As a capability, organizations need to track and measure ISSR, which is what this tool provides the ability to do.Originality/valueThis research contributes to the information systems and cybersecurity literature and offers valuable insights for organizations to manage their security effectively.
引用
收藏
页码:906 / 924
页数:19
相关论文
共 50 条
  • [1] Resilience to Leaking - Dynamic Systems Modeling of Information Security
    Hamacher, Kay
    [J]. PLOS ONE, 2012, 7 (12):
  • [2] HARMONISED RESILIENCE, SECURITY AND MOBILITY CAPABILITY FOR IP
    Atkinson, Randall
    Bhatti, Saleem
    Hailes, Stephen
    [J]. 2008 IEEE MILITARY COMMUNICATIONS CONFERENCE: MILCOM 2008, VOLS 1-7, 2008, : 1907 - 1914
  • [3] A Verified Capability-Based Model for Information Flow Security With Dynamic Policies
    Sun, Jianwen
    Long, Xiang
    Zhao, Yongwang
    [J]. IEEE ACCESS, 2018, 6 : 16395 - 16407
  • [4] A Capability Approach to Managing Organisational Information Security
    Carcary, Marian
    Doherty, Eileen
    Conway, Gerry
    [J]. PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 97 - 105
  • [5] RESILIENCE OF FOOD SUPPLY CHAINS - A DYNAMIC CAPABILITY APPROACH
    Jambor, Zsofia
    Nagy, Judit
    [J]. EKONOMSKA MISAO I PRAKSA-ECONOMIC THOUGHT AND PRACTICE, 2022, 31 (02): : 473 - 486
  • [6] Information systems security in the information systems curriculum
    Eastman, C
    Farkas, C
    [J]. INFORMATION TECHNOLOGY AND ORGANIZATIONS: TRENDS, ISSUES, CHALLENGES AND SOLUTIONS, VOLS 1 AND 2, 2003, : 117 - 118
  • [7] Security Constraints in Modeling of Access Control Rules for Dynamic Information Systems
    Poniszewska-Maranda, Aneta
    [J]. SOFSEM 2014: THEORY AND PRACTICE OF COMPUTER SCIENCE, 2014, 8327 : 466 - 477
  • [8] Security of information in IT systems
    Kaliczynska, M
    [J]. Photonics Applications in Astronomy, Communications, Industry, and High-Energy Physics Experiments III, 2005, 5775 : 571 - 576
  • [9] Power Systems Dynamic Security Assessment Using Fisher Information Metric
    Shenoy, Navin
    Ramakumar, R.
    [J]. 2016 IEEE POWER AND ENERGY SOCIETY GENERAL MEETING (PESGM), 2016,
  • [10] A dynamic model for evaluating the effectiveness of security for information technology products and systems
    Anishchenko, VV
    Venzel, EF
    Tomina, GD
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 1999, 33 (02) : 35 - 42