信息安全控制理论:实现信息共享与隐私保护之间的可持续平衡

Information Security Control Theory: Achieving a Sustainable Reconciliation Between Sharing and Protecting the Privacy of Information

Journal of Management Information Systems · 2017
被引 65
FT 50ABS 4

中文导读

针对组织在信息共享与保护之间的两难困境,提出信息安全控制理论,并通过美国西部健康信息交换的纵向案例验证其解释力,为管理者提供平衡策略。

Abstract

Contemporary organizations operate in highly interconnected environments where they are frequently confronted by the challenge of balancing the protection of information resources with the need for sharing information. This tension between the expected benefits and the potential security risks inherent in the information sharing process, exists in many domains, including business, health care, law enforcement, and military—yet it is not well-understood. We propose an information security control theory to explain and manage this tension. We evaluate this theory through a longitudinal case study of the iterative development of the information security policies for a health information exchange in the western United States. Our study shows that the theory offers a good framework through which to understand the information security policy development process, and a way to reconcile the tension between information sharing and information protection. The theory has practical applicability to many business domains.

信息安全信息共享隐私保护信息管理组织管理