Skip to main content

2019 | OriginalPaper | Buchkapitel

Information Security Policies in Organizations

How Convention Theory Can Serve as a Framework to Inform Information Security Research and HR Practice

verfasst von : Dominik Zellhofer

Erschienen in: Organizing for the Digital World

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The increased use of information technology throughout organizations led to a surge in concern for information security. Information security standards guide information security policy implementation, but the challenge of ensuring compliance is still a major issue, despite extensive information security research. The lack of versatility in theoretical approaches spurred calls for sociological approaches to contribute to the literature, but they were only partly addressed. The proposed framework of convention theory can serve as a fruitful approach by providing a holistic perspective and a strong theoretical foundation. The use of human resource information systems (HRIS) und electronic human resource management (e-HRM) extends the concern for information security to human resource (HR) practices and data privacy is no longer an issue solely for external stakeholders but for employees alike. At the same time, the role of HR practices in contributing to compliance with information security policies seems to be underestimated in existing literature. This paper introduces main concepts of a convention theory-based framework and illustrates implications for information security research and suggests that HR practices can contribute to ensuring information security in organizations.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
3.
Zurück zum Zitat Cost of Data Breach Study: Global Analysis. Ponemon Institute (2016) Cost of Data Breach Study: Global Analysis. Ponemon Institute (2016)
4.
Zurück zum Zitat Stanton, J.M., Stam, K.R., Mastrangelo, P., Jolton, J.: Analysis of end user security behaviors. Comput. Secur. 24, 124–133 (2005)CrossRef Stanton, J.M., Stam, K.R., Mastrangelo, P., Jolton, J.: Analysis of end user security behaviors. Comput. Secur. 24, 124–133 (2005)CrossRef
5.
Zurück zum Zitat Bulgurcu, B., Cavusoglu, H., Benbasat, I.: Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS Q. 34, 523–548 (2010)CrossRef Bulgurcu, B., Cavusoglu, H., Benbasat, I.: Information security policy compliance: an empirical study of rationality-based beliefs and information security awareness. MIS Q. 34, 523–548 (2010)CrossRef
6.
Zurück zum Zitat McFadzean, E., Ezingeard, J.-N., Birchall, D.: Anchoring information security governance research: sociological groundings and future directions. J. Inf. Syst. Secur. 2, 3–48 (2006) McFadzean, E., Ezingeard, J.-N., Birchall, D.: Anchoring information security governance research: sociological groundings and future directions. J. Inf. Syst. Secur. 2, 3–48 (2006)
7.
Zurück zum Zitat Bauer, S., Bernroider, E.W., Chudzikowski, K.: Prevention is better than cure! Designing information security awareness programs to overcome users’ non-compliance with information security policies in banks. Comput. Secur. 68, 145–159 (2017)CrossRef Bauer, S., Bernroider, E.W., Chudzikowski, K.: Prevention is better than cure! Designing information security awareness programs to overcome users’ non-compliance with information security policies in banks. Comput. Secur. 68, 145–159 (2017)CrossRef
8.
Zurück zum Zitat Zafar, H.: Human resource information systems: information security concerns for organizations. Human Resour. Manag. Rev. 23, 105–113 (2013)CrossRef Zafar, H.: Human resource information systems: information security concerns for organizations. Human Resour. Manag. Rev. 23, 105–113 (2013)CrossRef
9.
Zurück zum Zitat Beadles, I., Aston, N., Lowery, C.M., Johns, K.: The impact of human resource information systems: an exploratory study in the public sector. Commun. IIMA 5, 6 (2005) Beadles, I., Aston, N., Lowery, C.M., Johns, K.: The impact of human resource information systems: an exploratory study in the public sector. Commun. IIMA 5, 6 (2005)
10.
Zurück zum Zitat Kovach, K.A., Hughes, A.A., Fagan, P., Maggitti, P.G.: Administrative and strategic advantages of HRIS. Employ. Relat. Today 29, 43–48 (2002)CrossRef Kovach, K.A., Hughes, A.A., Fagan, P., Maggitti, P.G.: Administrative and strategic advantages of HRIS. Employ. Relat. Today 29, 43–48 (2002)CrossRef
11.
Zurück zum Zitat Strohmeier, S.: Research in e-HRM: review and implications. Human Resour. Manag. Rev. 17, 19–37 (2007)CrossRef Strohmeier, S.: Research in e-HRM: review and implications. Human Resour. Manag. Rev. 17, 19–37 (2007)CrossRef
12.
Zurück zum Zitat Zafar, H., Clark, J.G.: Current state of information security research in IS. Commun. Assoc. Inf. Syst. 24, 572–596 (2009) Zafar, H., Clark, J.G.: Current state of information security research in IS. Commun. Assoc. Inf. Syst. 24, 572–596 (2009)
13.
Zurück zum Zitat Williams, P.: Information security governance. Inf. Secur. Tech. Rep. 6, 60–70 (2001)CrossRef Williams, P.: Information security governance. Inf. Secur. Tech. Rep. 6, 60–70 (2001)CrossRef
14.
Zurück zum Zitat Simon, H.A.: Models of Man; Social and Rational. Wiley, New York (1957) Simon, H.A.: Models of Man; Social and Rational. Wiley, New York (1957)
15.
Zurück zum Zitat Davis, G., Olson, M.: Management Information Systems: Conceptual Foundations, Methods and Development. McGraw-Hill, New York (1985) Davis, G., Olson, M.: Management Information Systems: Conceptual Foundations, Methods and Development. McGraw-Hill, New York (1985)
16.
Zurück zum Zitat Knapp, K.J., Franklin Morris Jr, R., Marshall, T.E., Byrd, T.A.: Information security policy: an organizational-level process model. Comput. Secur. 28, 493–508 (2009) Knapp, K.J., Franklin Morris Jr, R., Marshall, T.E., Byrd, T.A.: Information security policy: an organizational-level process model. Comput. Secur. 28, 493–508 (2009)
17.
Zurück zum Zitat Siponen, M.: A conceptual foundation for organizational information security awareness. Inf. Manag. Comput. Secur. 8, 31–41 (2000)CrossRef Siponen, M.: A conceptual foundation for organizational information security awareness. Inf. Manag. Comput. Secur. 8, 31–41 (2000)CrossRef
18.
Zurück zum Zitat Warkentin, M., Willison, R.: Behavioral and policy issues in information systems security: the insider threat. Eur. J. Inf. Syst. 18, 101 (2009)CrossRef Warkentin, M., Willison, R.: Behavioral and policy issues in information systems security: the insider threat. Eur. J. Inf. Syst. 18, 101 (2009)CrossRef
19.
Zurück zum Zitat Orlikowski, W.J., Barley, S.R.: Technology and institutions: what can research on information technology and research on organizations learn from each other? MIS Q. 25, 145–165 (2001)CrossRef Orlikowski, W.J., Barley, S.R.: Technology and institutions: what can research on information technology and research on organizations learn from each other? MIS Q. 25, 145–165 (2001)CrossRef
20.
Zurück zum Zitat Siponen, M., Oinas-Kukkonen, H.: A review of information security issues and respective research contributions. SIGMIS Database 38, 60–80 (2007)CrossRef Siponen, M., Oinas-Kukkonen, H.: A review of information security issues and respective research contributions. SIGMIS Database 38, 60–80 (2007)CrossRef
21.
Zurück zum Zitat Dhillon, G., Backhouse, J.: Current directions in IS security research: towards socio-organizational perspectives. Inf. Syst. J. 11, 127–153 (2001)CrossRef Dhillon, G., Backhouse, J.: Current directions in IS security research: towards socio-organizational perspectives. Inf. Syst. J. 11, 127–153 (2001)CrossRef
22.
Zurück zum Zitat Durkheim, E., Solovay, S.A., Mueller, J.H., Catlin, S.G.E.G.: The Rules of Sociological Method, by Emile Durkheim (trans: Solovay, S.A., Mueller, J.H. and Ed: Catlin, G.E.G.). Free Press, New York (1982) Durkheim, E., Solovay, S.A., Mueller, J.H., Catlin, S.G.E.G.: The Rules of Sociological Method, by Emile Durkheim (trans: Solovay, S.A., Mueller, J.H. and Ed: Catlin, G.E.G.). Free Press, New York (1982)
23.
Zurück zum Zitat Wagner, P.: A History and Theory of the Social Sciences. Sage Publications Ltd., London (2001) Wagner, P.: A History and Theory of the Social Sciences. Sage Publications Ltd., London (2001)
24.
Zurück zum Zitat Bourdieu, P., Passeron, J.-C.: Sociology and philosophy in France since 1945: death and resurrection of a philosophy without subject. Soc. Res. 162–212 (1967) Bourdieu, P., Passeron, J.-C.: Sociology and philosophy in France since 1945: death and resurrection of a philosophy without subject. Soc. Res. 162–212 (1967)
25.
Zurück zum Zitat Weber, M.: Wirtschaft und Gesellschaft: Grundriss der verstehenden Soziologie. Mohr, Tübingen (1922) Weber, M.: Wirtschaft und Gesellschaft: Grundriss der verstehenden Soziologie. Mohr, Tübingen (1922)
26.
Zurück zum Zitat Diaz-Bone, R.: Die “Economie des conventions”: Grundlagen und Entwicklungen der neuen französischen Wirtschaftssoziologie. Springer VS, Wiesbaden (2015)CrossRef Diaz-Bone, R.: Die “Economie des conventions”: Grundlagen und Entwicklungen der neuen französischen Wirtschaftssoziologie. Springer VS, Wiesbaden (2015)CrossRef
27.
Zurück zum Zitat Hirschheim, R., Klein, H.K.: Four paradigms of information systems development. Commun. ACM 32, 1199–1216 (1989)CrossRef Hirschheim, R., Klein, H.K.: Four paradigms of information systems development. Commun. ACM 32, 1199–1216 (1989)CrossRef
28.
Zurück zum Zitat Boltanski, L., Thévenot, L.: On Justification: Economies of Worth. Princeton University Press, Princeton (2006) Boltanski, L., Thévenot, L.: On Justification: Economies of Worth. Princeton University Press, Princeton (2006)
29.
Zurück zum Zitat Patriotta, G., Gond, J.-P., Schultz, F.: Maintaining legitimacy: controversies, orders of worth, and public justifications. J. Manag. Stud. 48, 1804–1836 (2011)CrossRef Patriotta, G., Gond, J.-P., Schultz, F.: Maintaining legitimacy: controversies, orders of worth, and public justifications. J. Manag. Stud. 48, 1804–1836 (2011)CrossRef
30.
Zurück zum Zitat Thévenot, L.: Organized complexity: conventions of coordination and the composition of economic arrangements. Eur. J. Soc. Theory 4, 405–425 (2001)CrossRef Thévenot, L.: Organized complexity: conventions of coordination and the composition of economic arrangements. Eur. J. Soc. Theory 4, 405–425 (2001)CrossRef
31.
Zurück zum Zitat Thévenot, L., Moody, M., Lafaye, C.: Forms of valuing nature: arguments and modes of justification in French and American environmental disputes. In: Rethinking Comparative Cultural Sociology: Repertoires of Evaluation in France and the United States, pp. 229–272 (2000) Thévenot, L., Moody, M., Lafaye, C.: Forms of valuing nature: arguments and modes of justification in French and American environmental disputes. In: Rethinking Comparative Cultural Sociology: Repertoires of Evaluation in France and the United States, pp. 229–272 (2000)
32.
Zurück zum Zitat Thévenot, L.: Postscript to the special issue: governing life by standards a view from engagements. Social Stud. Sci. 39, 793–813 (2009) Thévenot, L.: Postscript to the special issue: governing life by standards a view from engagements. Social Stud. Sci. 39, 793–813 (2009)
33.
Zurück zum Zitat Thévenot, L.: Rules and implements: investment in forms. Soc. Sci. Inf. 23, 1–45 (1984)CrossRef Thévenot, L.: Rules and implements: investment in forms. Soc. Sci. Inf. 23, 1–45 (1984)CrossRef
34.
Zurück zum Zitat Thévenot, L.: The plurality of cognitive formats and engagements moving between the familiar and the public. Eur. J. Soc. Theory 10, 409–423 (2007)CrossRef Thévenot, L.: The plurality of cognitive formats and engagements moving between the familiar and the public. Eur. J. Soc. Theory 10, 409–423 (2007)CrossRef
35.
Zurück zum Zitat Thévenot, L.: Conventions of co-ordination and the framing of uncertainty. In: Intersubjectivity in Economics: Agents and Structures, pp. 181–197. Routledge, London (2002) Thévenot, L.: Conventions of co-ordination and the framing of uncertainty. In: Intersubjectivity in Economics: Agents and Structures, pp. 181–197. Routledge, London (2002)
36.
Zurück zum Zitat Thévenot, L.: Die Person in ihrem vielfachen Engagiertsein. Trivium. Revue franco-allemande de sciences humaines et sociales—Deutsch-französische Zeitschrift für Geistes-und Sozialwissenschaften (2010) Thévenot, L.: Die Person in ihrem vielfachen Engagiertsein. Trivium. Revue franco-allemande de sciences humaines et sociales—Deutsch-französische Zeitschrift für Geistes-und Sozialwissenschaften (2010)
37.
Zurück zum Zitat Thévenot, L.: Institutions and agency: differentiating regimes of engagement. In: Conference on Economy and Society Thévenot, L.: Institutions and agency: differentiating regimes of engagement. In: Conference on Economy and Society
38.
Zurück zum Zitat Thévenot, L.: Pragmatic regimes governing the engagement with the world. In: Knorr-Cetina, K., Schatzki, T., von Savigny, E. (eds.) The Practice Turn in Contemporary Theory, pp. 56–73. Routledge, London (2001) Thévenot, L.: Pragmatic regimes governing the engagement with the world. In: Knorr-Cetina, K., Schatzki, T., von Savigny, E. (eds.) The Practice Turn in Contemporary Theory, pp. 56–73. Routledge, London (2001)
39.
Zurück zum Zitat Diaz-Bone, R.: The methodological standpoint of the “économie des conventions”. Hist. Soc. Res./Historische Sozialforschung 43–63 (2011) Diaz-Bone, R.: The methodological standpoint of the “économie des conventions”. Hist. Soc. Res./Historische Sozialforschung 43–63 (2011)
40.
Zurück zum Zitat Richards, M., Zellweger, T., Gond, J.P.: Maintaining moral legitimacy through worlds and words: an explanation of firms’ investment in sustainability certification. J. Manag. Stud. 54, 676–710 (2017)CrossRef Richards, M., Zellweger, T., Gond, J.P.: Maintaining moral legitimacy through worlds and words: an explanation of firms’ investment in sustainability certification. J. Manag. Stud. 54, 676–710 (2017)CrossRef
41.
Zurück zum Zitat Latour, B.: Reassembling the Social: An Introduction to Actor-Network-Theory. Oxford University Press, Oxford (2005) Latour, B.: Reassembling the Social: An Introduction to Actor-Network-Theory. Oxford University Press, Oxford (2005)
42.
Zurück zum Zitat Orlikowski, W.J., Scott, S.V.: Sociomateriality: challenging the separation of technology, work and organization. Acad. Manag. Ann. 2, 433–474 (2008)CrossRef Orlikowski, W.J., Scott, S.V.: Sociomateriality: challenging the separation of technology, work and organization. Acad. Manag. Ann. 2, 433–474 (2008)CrossRef
43.
Zurück zum Zitat Soomro, Z.A., Shah, M.H., Ahmed, J.: Information security management needs more holistic approach: a literature review. Int. J. Inf. Manag. 36, 215–225 (2016)CrossRef Soomro, Z.A., Shah, M.H., Ahmed, J.: Information security management needs more holistic approach: a literature review. Int. J. Inf. Manag. 36, 215–225 (2016)CrossRef
44.
Zurück zum Zitat Schlienger, T., Teufel, S.: Information Security Culture. In: Ghonaimy, M.A., El-Hadidi, M.T., Aslan, H.K. (eds.) Security in the Information Society: Visions and Perspectives, pp. 191–201. Springer, US, Boston, MA (2002)CrossRef Schlienger, T., Teufel, S.: Information Security Culture. In: Ghonaimy, M.A., El-Hadidi, M.T., Aslan, H.K. (eds.) Security in the Information Society: Visions and Perspectives, pp. 191–201. Springer, US, Boston, MA (2002)CrossRef
45.
Zurück zum Zitat Meyer, J.W., Rowan, B.: Institutionalized organizations: formal structure as myth and ceremony. Am. J. Sociol. 83, 340–363 (1977)CrossRef Meyer, J.W., Rowan, B.: Institutionalized organizations: formal structure as myth and ceremony. Am. J. Sociol. 83, 340–363 (1977)CrossRef
46.
Zurück zum Zitat Jagd, S.: Pragmatic sociology and competing orders of worth in organizations. Eur. J. Soc. Theory 14, 343–359 (2011)CrossRef Jagd, S.: Pragmatic sociology and competing orders of worth in organizations. Eur. J. Soc. Theory 14, 343–359 (2011)CrossRef
47.
Zurück zum Zitat Knoll, L. (ed.): Organisationen und Konventionen. Die Soziologie der Konventionen in der Organisationsforschung. Springer VS, Wiesbaden (2015) Knoll, L. (ed.): Organisationen und Konventionen. Die Soziologie der Konventionen in der Organisationsforschung. Springer VS, Wiesbaden (2015)
Metadaten
Titel
Information Security Policies in Organizations
verfasst von
Dominik Zellhofer
Copyright-Jahr
2019
DOI
https://doi.org/10.1007/978-3-319-90503-7_5