An integrative study of information systems security effectiveness

An integrative study of information systems security effectiveness
复制标题

DOI:
10.1016/s0268-4012(02)00105-6
复制
发表时间:
2003-04
期刊:
Int. J. Inf. Manag.
影响因子:
--
通讯作者:
A. Kankanhalli;H. Teo;B. Tan;K. Wei
A. Kankanhalli;H. Teo;B. Tan;K. Wei
中科院分区:
其他
文献类型:
--
作者:
A. Kankanhalli;H. Teo;B. Tan;K. Wei

文献摘要

被引文献

相似文献

随着组织越来越依赖于信息系统(IS)的战略优势和业务,IS安全问题也变得越来越重要。在当今互联的电子商务环境中,安全问题至关重要。管理层必须投资于信息系统安全,以防止可能导致竞争劣势的滥用。利用文献的安全实践和组织因素,本研究开发了一个综合模型,是安全有效性和实证检验模型。这些数据是通过对各经济部门的基础设施服务管理人员进行调查而收集的。与大型组织相比,中小型企业采取的威慑措施较少。研究发现,高层管理支持较强的组织比高层管理支持较弱的组织开展更多的预防工作。金融机构比其他部门的组织采取更多的威慑努力,具有更严厉的威慑严重性。此外,还发现,加大威慑力度和预防措施可提高信息系统的安全效力。这些研究结果进一步的研究和实践的影响进行了讨论。
As organizations become increasingly dependent on information systems (IS) for strategic advantage and operations, the issue of IS security also becomes increasingly important. In the interconnected electronic business environment of today, security concerns are paramount. Management must invest in IS security to prevent abuses that can lead to competitive disadvantage. Using the literature on security practices and organizational factors, this study develops an integrative model of IS security effectiveness and empirically tests the model. The data were collected through a survey of IS managers from various sectors of the economy. Small and medium-sized enterprises were found to engage in fewer deterrent efforts compared to larger organizations. Organizations with stronger top management support were found to engage in more preventive efforts than organizations with weaker support from higher management. Financial organizations were found to undertake more deterrent efforts and have stiffer deterrent severity than organizations in other sectors. Moreover, greater deterrent efforts and preventive measures were found to lead to enhanced IS security effectiveness. Implications of these findings for further research and practice are discussed.