Choi, S.E., Martins, J.T. and Bernik, I. (2018) Information security: Listening to the perspective of organisational insiders. Journal of Information Science, 44 (6). pp. 752-767. ISSN 0165-5515
Abstract
Aligned with the strategy-as-practice research tradition, this article investigates how organisational insiders understand and perceive their surrounding information security practices, how they interpret them, and how they turn such interpretations into strategic actions. The study takes a qualitative case study approach, and participants are employees at the Research & Development department of a multinational original brand manufacturer. The article makes an important contribution to organisational information security management. It addresses the behaviour of organisational insiders – a group whose role in the prevention, response and mitigation of information security incidents is critical. The article identifies a set of organisational insiders’ perceived components of effective information security practices (organisational mission statement; common understanding of information security; awareness of threats; knowledge of information security incidents, routines and policy; relationships between employees; circulation of stories; role of punishment provisions; and training), based on which more successful information security strategies can be developed.
Metadata
Item Type: | Article |
---|---|
Authors/Creators: |
|
Copyright, Publisher and Additional Information: | © The Author(s) 2018. This is an author produced version of a paper subsequently published in Journal of Information Science. Uploaded in accordance with the publisher's self-archiving policy. Article available under the terms of the CC-BY-NC-ND licence (https://creativecommons.org/licenses/by-nc-nd/4.0/). |
Keywords: | Information security awareness; information security; organisational insiders; strategy as practice |
Dates: |
|
Institution: | The University of Sheffield |
Academic Units: | The University of Sheffield > Faculty of Social Sciences (Sheffield) > Information School (Sheffield) |
Depositing User: | Symplectic Sheffield |
Date Deposited: | 05 Apr 2018 13:20 |
Last Modified: | 20 Apr 2021 13:46 |
Status: | Published |
Publisher: | SAGE Publications |
Refereed: | Yes |
Identification Number: | 10.1177/0165551517748288 |
Open Archives Initiative ID (OAI ID): | oai:eprints.whiterose.ac.uk:129241 |