Information Security Management Practices: Case Studies from India

被引:5
|
作者
Singh, Abhishek Narain [1 ]
Gupta, M. P. [2 ]
机构
[1] Inst Management Technol Nagpur, Nagpur, Maharashtra, India
[2] Indian Inst Technol Delhi, Dept Management Studies, Informat Syst & E Gov, New Delhi, India
关键词
Data security; information security; information security management; case study; SAP-LAP; TECHNOLOGY; GOVERNANCE; FRAMEWORK; SYSTEMS;
D O I
10.1177/0972150917721836
中图分类号
F [经济];
学科分类号
02 ;
摘要
In recent years, information security has gained attention in organizations across diverse businesses and sectors. Primary reasons of this can be the new and innovative ways of information handling (during generation, processing, storage and distribution), and dependence of business processes on new and emerging IT/ICT mediums in organizations to carry out daily business activities. This has made organizations agile in terms of functioning and, at the same time, has posed new challenges. In this direction, the present study aims to explore and examine information security management (ISM) practices of two IT development and services organizations in India. In case study design, the study adopts qualitative research route to understand the current ISM practices of the case organizations. The observations derived from semi-structured interviews are presented using descriptive analysis methodology. Further, SAP-LAP (Situation, Actor, Process-Learning, Action, Performance) method of inquiry is used to analyse the findings from case studies. Results highlight the importance of consistent top management support, organizational information security culture and a proper monitoring system for ISM effectiveness in organizations. Insights derived from the study can be helpful for managers and decision makers in managing organizational information security practices.
引用
收藏
页码:253 / 271
页数:19
相关论文
共 50 条
  • [1] Information Security Management (ISM) practices: Lessons from select cases from India and Germany
    Singh A.N.
    Picot A.
    Kranz J.
    Gupta M.P.
    Ojha A.
    [J]. Global Journal of Flexible Systems Management, 2013, 14 (4) : 225 - 239
  • [2] Triggers of Change in Information Security Management Practices
    Ezingeard, Jean-Noel
    Bowen-Schrire, Monica
    [J]. JOURNAL OF GENERAL MANAGEMENT, 2007, 32 (04) : 53 - 72
  • [3] Challenges and Best Practices in Information Security Management
    McLaughlin, Mark-David
    Gogan, Janis
    [J]. MIS QUARTERLY EXECUTIVE, 2018, 17 (03) : 237 - 262
  • [4] Information Security Culture: Towards an Instrument for Assessing Security Management Practices
    Lim, Loo S.
    Maynard, Sean B.
    Ahmad, Atif
    Chang, Shanton
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2015, 5 (02) : 31 - 52
  • [5] Collaborative risk method for information security management practices: A case context within Turkey
    Ozkan, Sevgi
    Karabacak, Bilge
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2010, 30 (06) : 567 - 572
  • [6] The impact of information security management practices on organisational agility
    Zaini, Muhamad Khairulnizam
    Masrek, Mohamad Noorman
    Sani, Mad Khir Johari Abdullah
    [J]. INFORMATION AND COMPUTER SECURITY, 2020, 28 (05) : 681 - 700
  • [7] Information security management objectives and practices: A parsimonious framework
    Department of Computer Information Systems, University of Central Missouri, Warrensburg, MO, United States
    不详
    不详
    [J]. Inf. Manage. Comput. Secur, 2008, 3 (251-270):
  • [8] ISO 17799: "BEST PRACTICES" IN INFORMATION SECURITY MANAGEMENT?
    Ma, Qingxiong
    Pearson, J. Michael
    [J]. COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2005, 15 : 577 - 591
  • [9] The Impact of Organizational Practices on the Information Security Management Performance
    Alzahrani, Latifa
    Seth, Kavita Panwar
    [J]. INFORMATION, 2021, 12 (10)
  • [10] Information Security Practices in Latin America: The case of Bolivia
    Guzman, Indira R.
    Galvez, Santos M.
    Stanton, Jeffrey M.
    Stam, Kathryn R.
    [J]. AMCIS 2010 PROCEEDINGS, 2010,