Applying Action Research in the Adoption of Information Systems Security Policies
نویسندگان
چکیده
Information Systems Security (ISS) is a critical issue for a wide range of organizations. This paper focuses on organizations belonging to a particular sector, namely Local Public Administration, where public and personal information must be protected by those in charge, and where there must be a concern to view security as a priority. There are several measures which can be implemented in order to ensure the effective protection of information assets, among which stands out the adoption of ISS policies. A recent census concluded that among the 308 Town Councils in Portugal, only 38 indicated to have an ISS policy. The conclusion drawn from that study was that the adoption of ISS policies has not become a reality yet. As an attempt to mitigate this fact, an academic-practitioner collaboration effort was established regarding the implementation of ISS policies in three Town Councils. These interventions were conceived as Action Research projects. This article aims to constitute an empirical study on the applicability of the Action Research method in information systems, more specifically through the implementation of an ISS policy in Town Councils where previous attempts to adopt a policy have failed. The research question we intend to answer is to what extent this research method is adequate to reach the proposed goal. The results of the study suggest that Action Research is a promising means for the institutionalization of ISS policies adoption. It can both act as a research method, improving the understanding among researchers about the issues that hinder such adoption, and as a change method, assisting practitioners to overcome barriers that have prevented the implementation of ISS policies.
منابع مشابه
Users as the Biggest Threats to Security of Health Information Systems
There are a lot of researches in the world about attacks on information systems (IS). Although there have been many attempts to classify threats of IS’s especially in Health Information Systems (HIS), it is still necessary for all health organization to identify new threats and their sources which threaten security of health care domain. The main aim of this paper is to present a research agend...
متن کاملAdoption of an information systems security policy in small and medium sized enterprises
Information Systems Security (ISS) is a relevant fact for current organizations. This paper focuses on Small and Medium Sized Enterprises (SMEs). This article aims to constitute an empirical study on the applicability of the Action Research (AR) method in information systems, more specifically by assessing the adoption of an ISS policy in six SMEs, and identifying the critical success factors i...
متن کاملInstitutionalization of Information Systems Security Policies Adoption: Factors and Guidelines
Information systems security policies are pointed out in literature as one of the main controls to be applied by organizations for protecting their information systems. Despite this, it has been observed that, in several sectors of activity, the number of organizations having adopted that control is low. This study aimed to identify the factors which condition the adoption of information system...
متن کاملA Proposed Model for Assessing the Determinants of Enterprise Resource Planning Adoption and Satisfaction
The complex information systems such as enterprise resource planning (ERP) systems are essential for organizations to make them competitive. However, the success of ERP system projects is a difficult process as it involves different types of end user assessment. The main objective of the present study is to find the key determinants that open the door to employee satisfaction and adoption of E...
متن کاملEmpirical Study of Nova Scotia Nurses’ Adoption of Healthcare Information Systems: Implications for Management and Policy-Making
Background This paper used the Theory of Planned Behavior (TPB), which was extended, to investigate nurses’ adoption of healthcare information systems (HIS) in Nova Scotia, Canada. Methods Data was collected from 197 nurses in a survey and data analysis was carried out using the partial least squares (PLS) technique. Results In contrast to findings in prior studies that used TPB to investig...
متن کامل