为什么安全与隐私研究处于信息系统人造物的核心:提出一项大胆的研究议程

Why security and privacy research lies at the centre of the information systems (IS) artefact: proposing a bold research agenda

European Journal of Information Systems · 2017
被引 176 · 同刊同年前 6%
ABS 4

中文导读

本文指出安全与隐私研究的不足,建议重新定义信息系统人造物,并针对理论、方法等弱点提出改进,最后指出在线平台、物联网和大数据三个有前景的研究方向。

Abstract

In this essay, we outline some important concerns in the hope of improving the effectiveness of security and privacy research. We discuss the need to re-examine our understanding of information technology and information system (IS) artefacts and to expand the range of the latter to include those artificial phenomena that are crucial to information security and privacy research. We then briefly discuss some prevalent limitations in theory, methodology, and contributions that generally weaken security/privacy studies and jeopardise their chances of publication in a top IS journal. More importantly, we suggest remedies for these weaknesses, identifying specific improvements that can be made and offering a couple of illustrations of such improvements. In particular, we address the notion of loose re-contextualisation, using deterrence theory research as an example. We also provide an illustration of how the focus on intentions may have resulted in an underuse of powerful theories in security and privacy research, because such theories explain more than just intentions. We then outline three promising opportunities for IS research that should be particularly compelling to security and privacy researchers: online platforms, the Internet of things, and big data. All of these carry innate information security and privacy risks and vulnerabilities that can be addressed only by researching each link of the systems chain, that is, technologies–policies–processes–people–society–economy–legislature. We conclude by suggesting several specific opportunities for new research in these areas.

信息安全信息隐私信息系统隐私设计大数据