The Weakest Link Human Behaviour and the Corruption of Information Security Management in Organisations - an Analytical Framework

被引:0
|
作者
Holmberg, Robert [1 ]
Sundstrom, Mikael [2 ]
机构
[1] Lund Univ, Dept Psychol, SE-22100 Lund, Sweden
[2] Lund Univ, Dept Polit Sci, SE-22100 Lund, Sweden
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper we introduce the norm-injection analysis framework, a construct which can be employed to aid analysis of processes that affect information security management (ISM) in organisations. The underpinnings of this framework draw on and evolve - theories about how apparently mundane organisational processes, particularly managerial demands on employees, may in some instances lead to undesired, perhaps calamitous, consequences. Because the mechanisms between input (demand) and the adverse consequences work by gradually accruing and multiplying Subtle communication "problemettes" into major problems, they are almost undetectable to the untrained eye. Breaches of ISM protocol may appear wholly mysterious to the crash investigators brought in to analyse, post-event, what went wrong. The norm-injection analysis framework is intended to shed light on these below-the-radar processes, and to supplement the tool set an organisation analyst has at his disposal when preparing or evaluating strategic ISM measures.
引用
收藏
页码:94 / +
页数:2
相关论文
共 50 条
  • [21] Analytical Visualization Techniques for Security Information and Event Management
    Novikova, Evgenia
    Kotenko, Igor
    [J]. PROCEEDINGS OF THE 2013 21ST EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED, AND NETWORK-BASED PROCESSING, 2013, : 519 - 525
  • [22] A Framework of Information Security Integrated with Human Factors
    Al-Darwish, Ahmed, I
    Choe, Pilsung
    [J]. HCI FOR CYBERSECURITY, PRIVACY AND TRUST, 2019, 11594 : 217 - 229
  • [23] Collective information security behaviour: a technology-driven framework
    Snyman, Dirk P.
    Kruger, Hennie
    [J]. INFORMATION AND COMPUTER SECURITY, 2021, 29 (04) : 589 - 603
  • [24] Development of the Information Security Management System Standard for Public Sector Organisations in Estonia
    Seeba, Mari
    Matulevicius, Raimudas
    Toom, Ilmar
    [J]. 24TH INTERNATIONAL CONFERENCE ON BUSINESS INFORMATION SYSTEMS (BIS): ENTERPRISE KNOWLEDGE AND DATA SPACES, 2021, : 355 - 366
  • [25] Developing a theory-based information security management framework for human service organizations
    Mubarak, Sameera
    [J]. JOURNAL OF INFORMATION COMMUNICATION & ETHICS IN SOCIETY, 2016, 14 (03): : 254 - 271
  • [26] Information Security Management Framework for Web Applications Development
    Soares, Cleberton Carvalho
    da Silva, Paulo Caetano
    Soares, Natanael Dantas
    [J]. JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2018, 13 (03): : 98 - 108
  • [27] Information security management: A hierarchical framework for various approaches
    Eloff, MM
    von Solms, SH
    [J]. COMPUTERS & SECURITY, 2000, 19 (03) : 243 - 256
  • [28] An integrated system for information security management with the unified framework
    Yang, Tsung-Han
    Ku, Cheng-Yuan
    Liu, Man-Nung
    [J]. JOURNAL OF RISK RESEARCH, 2016, 19 (01) : 21 - 41
  • [29] A proposed security management framework for the global information community
    Coyle, J
    Demerest, J
    McAllister, R
    [J]. SIXTH IEEE WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 1997, : 220 - 227
  • [30] An audit framework to support information system security management
    Pereira, Teresa
    Santos, Henrique M. Dinis
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2010, 3 (03) : 265 - 277