Exploring organizational culture for information security management

被引:108
|
作者
Chang, Shuchih Ernest [1 ]
Lin, Chin-Shien
机构
[1] Natl Chung Hsing Univ, Inst Elect Commerce, Taichung 40227, Taiwan
[2] Natl Chung Hsing Univ, Dept Business Adm, Taichung 40227, Taiwan
关键词
data security; information systems; organizational culture;
D O I
10.1108/02635570710734316
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Purpose - This paper aims to examine the influence of organization culture on the effectiveness of implementing information security management (ISM). Design/methodology/approach - Based on a literature review, a model of the relationship between organizational culture and ISM was formulated, and both organizational culture characteristics and ISM effectiveness were measured empirically to investigate how various organizational culture traits influenced ISM principles, by administrating questionnaires to respondents in organizations with significant use of information systems. Findings - Four regression models were derived to quantify the impacts of organizational culture traits on the effectiveness of implementing ISM. Whilst the control-oriented organizational culture traits, effectiveness and consistency, have strong effect on the ISM principles of confidentiality, integrity, availability and accountability, the flexibility-oriented organizational culture traits, cooperativeness and innovativeness, are not significantly associated with the ISM principles with one exception that cooperativeness is negatively related to confidentiality. Research limitations/implications; - The sample is limited to the organizational factors in Taiwan. It is suggested to replicate this study in other countries to reconfirm the result before adopting its general implications. Owing to the highly intrusive nature of ISM surveys, a cautious approach with rapport and trust is a key success factor in conducting empirical studies on ISM. Practical implications - A culture conducive to information security practice is extremely important for organizations since the human dimension of information security cannot totally be solved by technical and management measures. For understanding and improving the organization behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. Originality/value - A research model was proposed to study the impacts of organizational factors on ISM, after a broad survey on related researches. The validated model and its corresponding study results can be referenced by enterprise managers and decision makers to make favorable tactics for achieving their goals of ISM - mitigating information security risks.
引用
收藏
页码:438 / 458
页数:21
相关论文
共 50 条
  • [1] Exploring Organizational Culture for Information Security in Healthcare Organizations: A Literature Review
    Page, Bridget Barnes
    [J]. 2017 PORTLAND INTERNATIONAL CONFERENCE ON MANAGEMENT OF ENGINEERING AND TECHNOLOGY (PICMET), 2017,
  • [2] Perceptions of organizational culture and value conflicts in information security management
    Karlsson, Martin
    Denk, Thomas
    Astrom, Joachim
    [J]. INFORMATION AND COMPUTER SECURITY, 2018, 26 (02) : 213 - 229
  • [3] The Influence of Organizational Information Security Culture on Information Security Decision Making
    Parsons, Kathryn Marie
    Young, Elise
    Butavicius, Marcus Antanas
    McCormac, Agata
    Pattinson, Malcolm Robert
    Jerram, Cate
    [J]. JOURNAL OF COGNITIVE ENGINEERING AND DECISION MAKING, 2015, 9 (02) : 117 - 129
  • [4] Impact of Organizational Culture to Information Security Triad
    Sari, Puspita Kencana
    Deniharza, Rully Satriawan
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL SEMINAR AND CONFERENCE ON LEARNING ORGANIZATION (ISCLO-15), 2016, 45
  • [5] The impacts of organizational culture on information security culture: a case study
    Tang, Mincong
    Li, Meng'gang
    Zhang, Tao
    [J]. INFORMATION TECHNOLOGY & MANAGEMENT, 2016, 17 (02): : 179 - 186
  • [6] The impacts of organizational culture on information security culture: a case study
    Mincong Tang
    Meng’gang Li
    Tao Zhang
    [J]. Information Technology and Management, 2016, 17 : 179 - 186
  • [7] Deriving the Relationship between Organizational Culture and Information Security Culture
    Hassan, Noor Hafizah
    Ismail, Zuraini
    [J]. VISION 2020: INNOVATION, DEVELOPMENT SUSTAINABILITY, AND ECONOMIC GROWTH, VOLS 1-3, 2013, : 926 - 932
  • [8] Exploring Organizational Human Resource Information System Security
    Zafar, Humayun
    [J]. AMCIS 2012 PROCEEDINGS, 2012,
  • [9] Organizational Management Role In Information Security Management System
    Qusef, Abdallah
    Arafat, Mais
    Al-Taher, Samar
    [J]. ICFNDS'18: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND DISTRIBUTED SYSTEMS, 2018,
  • [10] New organizational forms for information security management
    Baskerville, R
    [J]. INFORMATION SECURITY IN RESEARCH AND BUSINESS, 1997, : 296 - 307