Implementation of an Information Systems Security Policy: Action Research

被引:0
|
作者
Lopes, Isabel [1 ]
Oliveira, Pedro [2 ]
机构
[1] Inst Politecn Braganca, Dept Informat & Comunicacoes, Braganca, Portugal
[2] Inst Politecn Braganca, Dept Construcoes Civis & Planeamento, Braganca, Portugal
关键词
action research; information systems security policies; information security; small and medium sized enterprises;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Information Systems Security (ISS) is a critical issue for a wide range of organizations. This paper focuses on Small and Medium Sized Enterprises (SMEs) as although all organizations have their own requirements as far as information security is concerned, SMEs offer one of the most interesting cases for studying the issue of information security policies in particular, and information security in general. Within the organizational universe, SMEs assume a unique relevance due to their high number, which makes information security efficiency a crucial issue. There are several measures which can be implemented in order to ensure the effective protection of information assets, among which the adoption of ISS policies stands out. A recent survey concluded that among 307 SMEs, only 15 indicated to have an ISS policy. The conclusion drawn from that study was that the adoption of ISS policies has not become a reality yet. As an attempt to mitigate this fact, an academic-practitioner collaboration effort was established regarding the implementation of ISS policies in three SMEs. These interventions were conceived as Action Research (AR) projects. AR, whose application was originally established in academic milieus in the fields of Social and Medical Sciences, started to be successfully explored from 1990 in the field of IS. The nineties witnessed a development in Research, namely in Educational Sciences, IS research and the learning of Organizations (Baskerville 1999). This article aims to constitute an empirical study on the applicability of the AR method in information systems, more specifically through the implementation of an ISS policy in SMEs where previous attempts to adopt a policy have failed. The research question we intend to answer is to what extent this research method is adequate to reach the proposed goal. The results of the study suggest that AR is a promising means for the institutionalization of ISS policies adoption. It can both act as a research method, improving the understanding among researchers about the issues that hinder such adoption, and as a change method, assisting practitioners to overcome barriers that have prevented the implementation of ISS policies in SMEs.
引用
收藏
页码:244 / 252
页数:9
相关论文
共 50 条
  • [21] Information security policy development and implementation: The what, how and who
    Flowerday, Stephen V.
    Tuyikeze, Tite
    [J]. COMPUTERS & SECURITY, 2016, 61 : 169 - 183
  • [22] POLICY AND IMPLEMENTATION ISSUES FOR INFORMATION SECURITY EDUCATION IN DEVELOPING NATIONS
    Francis, Serah
    Marfurt, Konrad
    [J]. ICERI2015: 8TH INTERNATIONAL CONFERENCE OF EDUCATION, RESEARCH AND INNOVATION, 2015, : 728 - 737
  • [23] RESEARCH OF THE INFORMATION SECURITY IMPLEMENTATION LEVEL IN THE UNIVERSITY ENVIRONMENT
    Petrikova, Jirina
    Stevko, Martin
    [J]. IDIMT-2012: ICT SUPPORT FOR COMPLEX SYSTEMS, 2012, 38 : 369 - 371
  • [24] Research and implementation of information security for intelligent distribution network
    Wang Ning
    Wu Yanli
    Liu Guangxing
    Yao Ruizhe
    Zhang Longfei
    [J]. 2019 INTERNATIONAL CONFERENCE ON ENVIRONMENT, RESOURCES AND ENERGY ENGINEERING, 2020, 464
  • [25] A Comprehensive Security Policy Research on Web Information System
    Wang, Fengying
    Li, Caihong
    Zhao, Lei
    Li, Xiumei
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION AND LOGISTICS ( ICAL 2009), VOLS 1-3, 2009, : 1776 - 1780
  • [26] The poverty of action research in information systems
    McKay, J
    Marshall, P
    [J]. SYNERGY MATTERS: WORKING WITH SYSTEMS IN THE 21ST CENTURY, 1999, : 187 - 192
  • [27] Action research in information systems development
    Mansell, G.
    [J]. INFORMATION SYSTEMS JOURNAL, 1991, 1 (01) : 29 - 40
  • [28] Managing information security in healthcare - An action research experience
    Armstrong, H
    [J]. INFORMATION SECURITY FOR GLOBAL INFORMATION INFRASTRUCTURES, 2000, 47 : 19 - 28
  • [29] Applying Action Research in the Formulation of Information Security Policies
    Lopes, Isabel
    Oliveira, Pedro
    [J]. NEW CONTRIBUTIONS IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, PT 1, 2015, 353 : 513 - 522
  • [30] The Strategic Action Field Framework for Policy Implementation Research
    Moulton, Stephanie
    Sandfort, Jodi R.
    [J]. POLICY STUDIES JOURNAL, 2017, 45 (01) : 144 - 169