课题基金 / 基金详情

ITR: Behavioral Information Security: The Politics, Motivation, and Ethics of Information Security in Work Organizations

ITR: Behavioral Information Security: The Politics, Motivation, and Ethics of Information Security in Work Organizations
ITR:行为信息安全:工作组织中信息安全的政治、动机和伦理
批准号:
0312078
负责人:
Jeffrey Stanton
金额:
$15.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2003
资助国家:
美国
项目状态:
已结题
起止时间:
2003-09-01 至 2006-08-31

项目摘要

项目成果

Jeffrey Stanton的其他基金

相似基金

相关文献

中文摘要
翻译
许多信息安全技术解决方案只有在个人和群体有效运作的情况下才能发挥良好作用。本提案通过关注“行为信息安全”来解决这一限制,“行为信息安全”被定义为组织内影响信息系统可用性、保密性和完整性的人类行为的复合体。通过利用社会科学和组织科学的理论,这种方法试图促进对组织中与安全相关的行为的本质和前因的理解。这些研究人员先前的研究表明,相互冲突的组织亚文化、不适当的组织激励、沟通障碍和混乱的行为道德标准都会干扰组织中信息安全的有效实施。拟议的研究将建立在这项已完成和正在进行的工作的基础上,为组织中的行为信息安全制定一个理论框架。该框架将明确解决组织在控制行为方面的利益与个人权利(如自决、言论、隐私)之间的紧张关系。该项目将使用多案例研究方法,观察并记录组织中与安全相关的行为。团队成员将对十到二十个在研究团队区域内有业务的组织的工人、经理和信息技术专业人员进行一系列现场面试和工作观察,这些组织包括小型和大型组织、营利性和非营利组织,可能还有政府组织。该团队将识别和分析特定的社会配置、权力动态、学习机会、行动自由和个人特征,这些因素会影响员工决定如何遵守、抵制或改进规定的信息安全行为。访谈和观察数据的汇编、转录和分析将导致初步理论框架的开发和测试。研究人员将通过会议、学术期刊提交和从业人员简报文章以及通过开发项目网站来传播项目成果。在该项目结束时,他们将汇编一份数据档案,供其他学者使用,其中包括所有抄本的未识别版本。此外,该项目打算与行业媒体就信息安全的行为方法进行合作。该项目有可能提高医院和公用事业等关键基础设施组织的信息安全做法的有效性。由于许多行业的信息安全成本持续上升,它在许多行业也具有潜在的经济效益。然而,与此同时,通过关注工人的关切,结果可能有助于组织避免侵犯或减少个别工人的权利。
英文摘要
Many technical solutions to information security only function well when operationalized effectively by individuals and groups of people. The present proposal addresses this constraint by focusing on "behavioral information security," defined as the complexes of human action within organizations that influence the availability, confidentiality, and integrity of information systems. By harnessing theories from the social and organizational sciences, this approach attempts to advance the understanding of the nature and antecedents of security-related behavior in organizations. Prior research by these investigators has revealed that conflicting organizational subcultures, inappropriate organizational incentives, communication barriers, and disconcerted ethical standards for behavior each and all interfere with the effective enactment of information security in organizations. The proposed research will build on this completed and in-progress work to develop a theoretical framework for behavioral information security in organizations. The framework will explicitly address the tension between organizations' interests in controlling behavior and individuals' rights (e.g., self determination, speech, privacy). The project will observe and document security-related behavior in organizations, using a multiple case study approach. Team members will conduct a series of onsite interviews and job observations with workers, managers, and information technology professionals at ten to twenty organizations with operations in the research team's regional area, including small and large organizations, for profit and non-profit organizations, and possibly a governmental organization. The team will identify and analyze the specific social configurations, power dynamics, learning opportunities, freedom of action, and personal characteristics that influence how workers decide to comply with, resist, or improve upon prescribed information security behavior. Compilation, transcription, and analysis of interview and observational data will lead to the development and testing of a preliminary theoretical framework. Investigators will disseminate project results through conferences, scholarly journal submissions, and brief practitioner articles and through the development of a project website. At the close of the project, they will compile a data archive for use by other scholars that includes de-identified versions of all transcriptions. Additionally, the project intends to work with the trade press on behavioral approaches to information security. This project has the potential to enhance the effectiveness of information security practices in critical infrastructure organizations such as hospitals and utilities. Because the cost of information security continues to rise in many industries, it also has potential economic benefits in many sectors. Simultaneously, however, by attending to the concerns of workers, the results may help organizations to avoid infringing upon or diminishing individual workers' rights.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CI-Facilitators: Information Architects across the STEM Disciplines
  • 批准号:
    0753372
  • 项目类别:
    Standard Grant
  • 资助金额:
    $24.44万
  • 财政年份:
    2008
  • 负责人:
    Jeffrey Stanton
  • 依托单位:
ITWF: Culture Clash! The Adverse Effects of IT Occupational Subculture on Formative Work Experiences of IT Students
  • 批准号:
    0420434
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2004
  • 负责人:
    Jeffrey Stanton
  • 依托单位:
CAREER: Organizations, Technology, and Data about Workers
  • 批准号:
    0196415
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $10.65万
  • 财政年份:
    2001
  • 负责人:
    Jeffrey Stanton
  • 依托单位:
CAREER: Organizations, Technology, and Data about Workers
  • 批准号:
    9984111
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $10.65万
  • 财政年份:
    2000
  • 负责人:
    Jeffrey Stanton
  • 依托单位:
国内基金
海外基金
Behavioral Insights on Cooperation in Social Dilemmas
  • 批准号:
    --
  • 项目类别:
    外国优秀青年学者研究基金项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    LIEN,Jaimie Wei-Hung
  • 依托单位: