Perception of risk and the strategic impact of existing IT on information security strategy at board level

被引:44
|
作者
McFadzean, Elspeth [1 ]
Ezingeard, Jean-Noel [1 ]
Birchall, David [1 ]
机构
[1] Henley Management Coll, Ctr Business Digital Econ, Henley On Thames, England
关键词
boards; information control; data security; perception; governance;
D O I
10.1108/14684520710832333
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose - Information security is becoming increasingly more important as organisations are endangered by a variety of threats from both its internal and external environments. Many theorists now advocate that effective security policies should be created at senior management level. This is because executives are able to evaluate the Organisation using a holistic approach as well as having the power to ensure that new systems and procedures are implemented in a timely manner. There is, however, a continuing lack of understanding regarding the strategic importance of managing information security. In addition, there is a gap in the literature on the relationship between directors and information security strategy. This paper attempts to close this gap by exploring how directors perceive their Organisation's security and what factors influence their decisions on the development and implementation of information security strategy. Design/methodology/approach - The research is based 011 constructivist grounded theory. Forty-three interviews were conducted at executive level in 29 organisations. These interviews were then coded and analysed in order to develop new theory on directors' perception of risk and its effect on the development and implementation of information security strategy. Findings - The analysis shows that senior managers' engagement with information security is dependent on two key variables: the strategic importance of information systems to their organisation and their perception of risk. Additionally, this research found that these two variables are affected by both organisational contextual factors and the strategic and operational actions undertaken within the business. Furthermore, the results demonstrated that the two board variables also have an impact on the Organisation's environment as well as its strategic and operational actions. This paper uses the data gathered from the inter-views to develop a model of these factors. In addition, a perception grid is constructed which illustrates the potential concerns that can drive board engagement. Practical implications - The paper illustrates the advantages of using the perception grid to understand and develop current and future information security issues. Originality/value - The paper investigates how organisational directors perceive information security and how this perception influences the development of their information security strategy.
引用
收藏
页码:622 / 660
页数:39
相关论文
共 50 条
  • [41] The impact of risk perception and information acquisition on meteorological adaptive behavior of large grain farmers
    Zhu Lingjuan
    Cai Yingshu
    He Yulong
    Huang Jichao
    Li Huijie
    EMIRATES JOURNAL OF FOOD AND AGRICULTURE, 2023, 35 (03): : 251 - 261
  • [42] INFORMATION DIFFUSION IN THE EVALUATION OF MEDICAL MARIJUANA LAWS' IMPACT ON RISK PERCEPTION AND USE RESPONSE
    Schmidt, Laura A.
    Jacobs, Laurie M.
    Spetz, Joanne
    AMERICAN JOURNAL OF PUBLIC HEALTH, 2016, 106 (12) : E8 - E9
  • [43] The Level of Tuberculosis Knowledge and Risk Perception Among Soldiers with Tuberculosis and Impact of Education on This Process
    Ciftci, Faruk
    Isildak, Yesim Isler
    Torun, Oezguel
    Selvan, Hatice
    Bicak, Mesut
    Kaya, Hatice
    Deniz, Oemer
    Acikel, Cengiz Han
    Hasoglu, Cengiz
    TURKIYE KLINIKLERI TIP BILIMLERI DERGISI, 2010, 30 (01): : 180 - 186
  • [44] Corresponding Security Level with the Risk Factors of Personally Identifiable Information through the Analytic Hierarchy Process
    Lin, Iuon-Chang
    Lin, Yung-Wang
    Wu, Yu-Syuan
    JOURNAL OF COMPUTERS, 2016, 11 (02) : 124 - 131
  • [45] The Impact of a Company's Management Strategy on Its Profitability, Stability, and Growth: A Focus on the Information Security Industry
    Kang, Hyun
    Na, Hyung Jong
    SUSTAINABILITY, 2024, 16 (12)
  • [46] Impact of luck perception on consumer's construal level: the mediating role of psychological security and the moderating role of power
    Jianrong Tao
    Jianbin Zhao
    Hehe Li
    Current Psychology, 2023, 42 : 28470 - 28483
  • [47] The Impact of Historical Performance and Managerial Risk-taking Propensity on the Behavior of Choosing Prospector Strategy and Using Strategic Management Accounting Information in Viet Nam Manufacturer
    Vo, Liem Tan
    Vo, Nhi Van
    Pham, Toan Ngoc
    Hien, Nguyen Ngoc
    SAGE OPEN, 2023, 13 (04):
  • [48] Risk, perception and COVID-19 impact on food security: evidence from Bundelkhand region, India
    Jatav, Surendra Singh
    DISCOVER SUSTAINABILITY, 2024, 5 (01):
  • [49] Impact of luck perception on consumer's construal level: the mediating role of psychological security and the moderating role of power
    Tao, Jianrong
    Zhao, Jianbin
    Li, Hehe
    CURRENT PSYCHOLOGY, 2023, 42 (32) : 28470 - 28483
  • [50] A RISK MANAGEMENT MODEL BASED ON USER PERCEPTION FOR INFORMATION SYSTEMS SECURITY AT UNIVERSIDAD NACIONAL DEL ALTIPLANO PUNO
    Condori Alejo, Henry Ivan
    REVISTA INVESTIGACIONES ALTOANDINAS-JOURNAL OF HIGH ANDEAN RESEARCH, 2013, 15 (01): : 23 - 34