Information Security Inside Organizations - A Positive Model and Some Normative Arguments Based on New Institutional Economics

Information Security Inside Organizations - A Positive Model and Some Normative Arguments Based on New Institutional Economics
复制标题

组织内部的信息安全——基于新制度经济学的实证模型和一些规范论证

DOI:
--
复制
发表时间:
2009
期刊:
影响因子:
--
通讯作者:
Frank Pallas
Frank Pallas
中科院分区:
--
文献类型:
--
作者:
Frank Pallas

文献摘要

被引文献

相似文献

这项工作发展了一个抽象的,理论基础上的组织内部信息安全的理解。为此目的,从信息安全领域的既定知识的基础上,两个不同的维度:历史维度区分三个“时代”的信息安全,并将它们与当前的计算范式的变化。“安全三角”确定和描述了实现组织内部信息安全的三种不同的“元措施”,并强调了更高级别监管框架的存在。此外,这项工作是基于新制度经济学领域的原则。特别是,信息不对称,交易成本和委托代理关系的概念,以及它们的相关性,建立个人之间的合作。合作反过来被建模为包括两个部分的协调和动机的问题。然后,这些理论基础被合并到组织内部信息安全的经济启发的积极模型中。该模型为过去发生的信息安全实践的变化提供了抽象的和有理论基础的解释。除了这种解释性的使用,积极的模式也适用于前瞻性的方式。当前的技术发展可能会导致越来越多的“交织”计算结构,从而导致另一种流行的计算范式的变化。将模型应用于变化的givens表明,现在建立的做法,如行为指南或那些通常与术语“安全文化”相关的手段将证明是低效的,因此在未来是不够的。因此,各组织将不得不使用替代办法或修改现有办法,以便在变化了的情况下实现信息安全。过去曾提出过各种可能性。其中一些是在经济启发的基础上进行评估的,积极的模式。这一分析导致有充分根据的建议,在什么条件下应适用的方法。此外,对经济的理解还有助于制定迄今尚未想到的新办法。作为最后一个方面,更高层次的监管框架的未来作用是照亮。它表明,这一框架将不得不通过即将到来的变化,以保护组织被迫应用非常低效的做法,仅为合规的原因。总的来说,在这项工作中开发的积极模式提供了解释什么可以观察到在该领域的组织内部信息安全,允许有充分的理由预测什么可以预期的未来,并导致规范的论点,必要的改变既定的方法和做法。因此,它可能在许多方面对未来的研究有价值。
This work develops an abstract, theory-founded understanding of organization-internal infor­mation security. For this purpose, established knowledge from the field of information security is restructured on the basis of two different dimensions: The historical dimension distinguishes three "eras" of information security and relates them to concurrent changes of prevailing computing paradigms. The "security triangle" identifies and characterizes three different "meta-measures" for realizing information security inside organizations and highlights the existence of a higher-level regulatory framework. Additionally, the work is based on principles from the field of New Institutional Economics. In particular, the concepts of information asymmetries, transaction costs and principal-agent relations are explicated as well as their relevance to the establishment of cooperation among individuals. Cooperation is in turn modeled as consisting of the two partial problems of coordination and motivation. These theoretical foundations are then merged into an economically inspired positive model of information security inside organizations. The model provides abstract and theory-founded explanations for the changes of prevailing information security practices that happened in the past. Besides this explanatory use, the positive model is also applied in a prospective manner. Current technological developments will presumably lead to increasingly "interwoven" compu­ting structures and thus to another change of the prevailing computing paradigm. The application of the model to the changed givens suggests that now-established practices like behavioral guidelines or those means usually associated with the term "security culture" will prove inefficient and thus inadequate in the future. Organizations will therefore have to use alternative approaches or to modify existing ones for realizing information security under the changed circumstances. Various possibilities for doing so have been suggested in the past. Some of these are evaluated on the basis of the economically inspired, positive model. This analysis leads to well-founded suggestions which of the approaches should be applied under what conditions. Furthermore, the economic understanding also supports the development of new approaches that have so far not been thought of. As a final aspect, the future role of the higher-level regulatory framework is illuminated. It is shown that this framework will have to be adopted to the upcoming changes in order to protect organizations from being forced to apply highly inefficient practices for compliance reasons alone. Overall, the positive model developed in this work provides explanations for what can be observed in the field of organization-internal information security, allows for well-founded predictions about what can be expected for the future and leads to normative arguments regarding necessary changes of established approaches and practices. It might therefore prove valuable for future research in a multitude of ways.