超越技术措施:以价值聚焦思维评估改善信息安全政策合规的战略驱动因素

Beyond technical measures: a value-focused thinking appraisal of strategic drivers in improving information security policy compliance

European Journal of Information Systems · 2021
被引 28
ABS 4

中文导读

采用基于价值的方法,识别出30个目标,揭示风险缓解、人员、技术和组织因素对改善发展中国家员工信息安全政策合规的关键作用,为管理者设计和实施安全策略提供指导。

Abstract

The evolving sophistication of threats and the impact of security breaches have caused managers to continually grapple with strategies to reduce these risks. One common security control is the adoption of information security policies (ISPs) geared at improving employees’ compliance behaviour. However, there is mounting empirical evidence that shows that ISP compliance is a challenging undertaking with less than satisfactory outcomes. Further, little attention is placed on developing economies in the study of this phenomenon. This research adopts a values-based methodology to determine fundamental and means objectives in maximising employees’ compliance with ISPs in a developing economy context. The research identifies 30 objectives and demonstrates that risk mitigation, people, technical and organisational factors are essential to improving compliance. The results contribute objectives, contextualised to the people for whom the results are relevant, thus promoting deeper understanding. The research offers utility to managers in the design and implementation of InfoSec strategies and policies. The findings can also inform investment decisions regarding compliance tools, methods and technologies. Recognising that security (information and cyber) threats are a global dilemma, we contend that investigating forms of security risks and potential solutions can mitigate the social and economic costs of security incidents.

信息安全政策合规战略管理新兴经济体