Back to Search Start Over

Value-focused assessment of information system security in organizations.

Authors :
Dhillon, Gurpreet
Torkzadeh, Gholamreza
Source :
Information Systems Journal; Jul2006, Vol. 16 Issue 3, p293-314, 22p, 1 Diagram, 2 Charts
Publication Year :
2006

Abstract

Information system (IS) security continues to present a challenge for executives and professionals. A large part of IS security research is technical in nature with limited consideration of people and organizational issues. The study presented in this paper adopts a broader perspective and presents an understanding of IS security in terms of the values of people from an organizational perspective. It uses the value-focused thinking approach to identify ‘fundamental’ objectives for IS security and ‘means’ of achieving them in an organization. Data for the study were collected through in-depth interviews with 103 managers about their values in managing IS security. Interview results suggest 86 objectives that are essential in managing IS security. The 86 objectives are organized into 25 clusters of nine fundamental and 16 means categories. These results are validated by a panel of seven IS security experts. The findings suggest that for maintaining IS security in organizations, it is necessary to go beyond technical considerations and adopt organizationally grounded principles and values. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
13501917
Volume :
16
Issue :
3
Database :
Complementary Index
Journal :
Information Systems Journal
Publication Type :
Academic Journal
Accession number :
20967289
Full Text :
https://doi.org/10.1111/j.1365-2575.2006.00219.x