Information systems security policy implementation in practice: from best practices to situated practices

被引:33
|
作者
Niemimaa, Elina [1 ]
Niemimaa, Marko [2 ]
机构
[1] Tampere Univ Technol, Dept Informat Management & Logist, Korkeakoulunkatu 10, Tampere 33720, Finland
[2] Univ Turku, Turku Ctr Comp Sci Informat Syst Sci, Turku, Finland
关键词
IS security; IS security policy; practice theory; ethnography; PRACTICE PERSPECTIVE; TECHNOLOGY; MANAGEMENT; STANDARDS; TRANSLATION; FIELD; POWER; INSTITUTIONS; RATIONALITY; GOVERNANCE;
D O I
10.1057/s41303-016-0025-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Organizations face institutional pressure to adopt information systems security (ISS) best practices to manage risks to their information assets. The literature shows that best practices should be contextualized, that is, translated from universal and general prescriptions into organizational documents and practices. Yet, little is known about how organizations actually make the translation from the best practices into situated practices. In this ethnographic study, we draw on practice theory and related concepts of canonical and non-canonical practices to analyze the process of translation. We explore how an IT service provider translated the ISS best practice of information classification into an ISS policy and into situated practices. We identify three translation mechanisms: (1) translating global to local, (2) disrupting and reconstructing local non-canonical practices, and (3) reconstructing and enacting local canonical practices. We find that while the translation was inhibited by incongruent practices, insufficient understanding of employees' work, and the ISS managers' lack of engagement in organizational practices, allowing situated practices to shape the ISS policy and actively engaging employees in the reconstruction of situated practices contributed positively to the translation. Contributions and implications for research and practice are discussed and conclusions are drawn.
引用
收藏
页码:1 / 20
页数:20
相关论文
共 50 条
  • [21] Advanced Security Policy Implementation for Information Systems
    Yusufovna, Sattarova Feruza
    [J]. INTERNATIONAL SYMPOSIUM ON UBIQUITOUS MULTIMEDIA COMPUTING, PROCEEDINGS, 2008, : 244 - 247
  • [22] Industry Responses to the European Directive on Security of Network and Information Systems (NIS): Understanding policy implementation practices across critical infrastructures
    Michalec, Ola
    van der Linden, Dirk
    Milyaeva, Sveta
    Rashid, Awais
    [J]. PROCEEDINGS OF THE SIXTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY (SOUPS 2020), 2020, : 301 - 317
  • [23] Privacy and Security: Best Practices for Global Security
    Millar, Sheila A.
    [J]. JOURNAL OF INTERNATIONAL TRADE LAW AND POLICY, 2006, 5 (01) : 36 - +
  • [24] Collaborative Online International Learning (COIL) for Information Systems Education: Best Practices and Implementation Strategies
    Zolbanin, Hamed M.
    Gosalia, Sangita S.
    [J]. COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2024, 54 : 773 - 791
  • [26] School wellness team best practices to promote wellness policy implementation
    Profili, Erika
    Rubio, Diana S.
    Lane, Hannah G.
    Jaspers, Lea H.
    Lopes, Megan S.
    Black, Maureen M.
    Hager, Erin R.
    [J]. PREVENTIVE MEDICINE, 2017, 101 : 34 - 37
  • [27] ERP systems implementation: Best practices in Canadian government organizations
    Kumar, V
    Maheshwari, B
    Kumar, U
    [J]. GOVERNMENT INFORMATION QUARTERLY, 2002, 19 (02) : 147 - 172
  • [28] Best practices in information literacy
    Hunt, F
    Birks, J
    [J]. PORTAL-LIBRARIES AND THE ACADEMY, 2004, 4 (01) : 27 - 39
  • [29] From repositories of best practices to networks of best practices
    Fragidis, G.
    Tarabanis, K.
    [J]. 2006 IEEE INTERNATIONAL CONFERENCE ON MANAGEMENT OF INNOVATION AND TECHNOLOGY, VOLS 1 AND 2, PROCEEDINGS, 2006, : 370 - +
  • [30] Evidence-Informed Knowledge to Practice: Implementation of Stroke Best Practices
    Richardson, D.
    Fortin, J.
    Avinoam, G.
    Skrabka, K.
    Willems, J.
    Sharp, S.
    Linkewich, B.
    [J]. STROKE, 2013, 44 (12) : E203 - E203