Inductively Deriving an Organisational Information Security Risk Management Agenda by Exploring Process Improvisation
نویسندگان
چکیده
In times of heightened uncertainty and unpredictability it is believed that incrementalist approaches that are not resolute to order and control in information security risk management (ISRM) are necessary. This is because information security incidents that occur in context are noted to differ one from another. Incrementalist approaches to ISRM apply when contextual security risk instances are rare, unique and complex. This paper qualitatively explores and draws viewpoints from information security management on the incrementalist viewpoint of managing information security risk. Attention is given to process improvisation, an explication of combined functionalism and incrementalism which places an emphasis on ways in which practitioners creatively mitigate information security risk. An in-depth case study approach has been used to explore this phenomenon and grounded theory techniques employed to analyse the data. The process of inductive theory building that serves as impetus for an ISRM agenda shows the fit between data and the emerging theory on process improvisation. Findings highlighted in this paper yield rich insights about how an ISRM agenda may incorporate incrementalist and functionalist approaches. Implications for such an agenda to practising information security professionals are also presented.
منابع مشابه
The Case for Improvisation in Information Security Risk Management
Information Security (IS) practitioners face increasingly unanticipated challenges in IS risk management, often pushing them to act extemporaneously. Few studies have been dedicated to examining the role these extemporaneous actions play in mitigating IS risk. Studies have focused on clear guidelines and policies as sound approaches to ISRM (functionalist approaches). When IS risk incidents occ...
متن کاملCollective Improvisation: Complementing Information Security Frameworks with Self-Policing
The approach to information security governance has predominantly followed a functionalist paradigm with emphasis placed on formalized rule structures and policy frameworks. The alternative socio-organisational (reflexive) approach has in the recent past grown in prominence due to the emergent socio-organizational aspect of technologies and processes. This paper challenges the epistemology of t...
متن کاملبهبود رتبه بندی مخاطرات امنیت اطلاعات با استفاده از مدل های تصمیم گیری چند شاخصه
One of the most important capabilities of information security management systems, which must be implemented in all organizations according to their requirements, is information security risk management. The application of information security risk management is so important that it can be named as the heart of information security management systems. Information security risk rating is conside...
متن کاملA Framework for Managing Predictable and Unpredictable Threats: The Duality of Information Security Management
Information systems security is a challenging research area in the context of Information Systems. In fact, it has strong practical implications for the management of IS and, at the same time, it gives very interesting insights into understanding the process of social phenomena when communication information technologies are deployed in organizations. Current standards and best practices for th...
متن کاملExploring the Type of Relationship between Information Security Management and Organizational Culture (Case Study in TAM Iran Khodro Co.)
A culture conducive to information security practice is extremely important for organizations since information has to be critical assets in modern enterprises. Thus for understanding and improving the organizational behavior with regard to information security, enterprises may look into organizational culture and examine how it affects the effectiveness of implementing ISM. This study aims ...
متن کامل