...
首页> 外文期刊>Computers & Security >Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture
【24h】

Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture

机译:组织中的信息安全知识共享:调查行为信息安全治理和国家文化的影响

获取原文
获取原文并翻译 | 示例
           

摘要

This paper presents an empirical investigation on what behavioral information security governance factors drives the establishment of information security knowledge sharing in organizations. Data was collected from organizations located in different geographic regions of the world, and the amount of data collected from two countries - namely, USA and Sweden - allowed us to investigate if the effect of behavioral information security governance factors on the establishment of security knowledge sharing differs based on national culture. The study followed a mixed methods research design, wherein qualitative data was collected to both establish the study's research model and develop a survey instrument that was distributed to 578 information security executives. The results suggest that processes to coordinate implemented security knowledge sharing mechanisms have a major direct influence on the establishment of security knowledge sharing in organizations; the effect of organizational structure (e.g., centralized security function to develop and deploy uniform firm-wide policies, and use of steering committees to facilitate information security planning) is slightly weaker, while business-based information security management has no significant direct effect on security knowledge sharing. A mediation analysis revealed that the reason for the nonsignificant direct relation between business-based information security management and security knowledge sharing is the fully mediating effect of coordinating information security processes. Thus, the results disentangles the interrelated influences of behavioral information security governance factors on security knowledge sharing by showing that information security governance sets the platform to establish security knowledge sharing, and coordinating processes realize the effect of both the structure of the information security function and the alignment of information security management with business needs. A multigroup analysis identified that national culture had a significant moderating effect on the association between four of the six proposed relations. In Sweden - which is seen as a less individualist, feminine country - managers tend to focus their efforts on implementing controls that are aligned with business activities and employees' need; monitoring the effectiveness of the implemented controls, and assuring that the controls are not too obtrusive to the end-user. On the contrary, US organizations establish security knowledge sharing in their organization through formal arrangements and structures.These results imply that Swedish managers perceive it to be important to involve, or at least know how their employees cope with the decisions that have been made, thus favoring local participation in information security management, while US managers may feel the need to have more central control when running their information security function.rnThe findings suggest that national culture should be taken into consideration in future studies - in particular when investigating organizations operating in a global environment - and understand how it affects behaviors and decision-making.
机译:本文对哪些行为信息安全治理因素驱动了组织中信息安全知识共享的建立进行了实证研究。数据是从位于世界不同地理区域的组织收集的,从美国和瑞典这两个国家/地区收集的数据量使我们能够研究行为信息安全治理因素对建立安全知识共享的影响因国家文化而异。该研究遵循混合方法研究设计,其中收集了定性数据以建立研究的研究模型并开发调查工具,该工具被分发给578名信息安全主管。结果表明,协调已实施的安全知识共享机制的过程对组织中安全知识共享的建立具有直接的重大影响。组织结构的影响(例如,用于制定和部署统一的全公司策略的集中安全功能,以及使用指导委员会来促进信息安全计划的影响)稍弱,而基于业务的信息安全管理对安全性没有明显的直接影响知识共享。调解分析显示,基于业务的信息安全管理与安全知识共享之间不存在直接关系的原因是协调信息安全流程的充分调解效果。因此,结果表明,信息安全治理为建立安全知识共享建立了平台,协调过程实现了信息安全功能结构和信息安全管理两者的作用,从而消除了行为信息安全治理因素对安全知识共享的相互影响。使信息安全管理与业务需求保持一致。一项多组分析确定,民族文化对六个拟议关系中的四个之间的联系具有显着的调节作用。在瑞典-一个被视为个人主义程度较低的女性化国家-经理倾向于将精力集中在实施与业务活动和员工需求相一致的控制上;监视已实施控件的有效性,并确保控件对最终用户不会太过麻烦。相反,美国组织通过正式的安排和结构在组织中建立安全知识共享,这些结果表明瑞典管理人员认为参与或至少知道其员工如何应对已做出的决定很重要。有利于当地参与信息安全管理,而美国经理人可能会觉得在行使其信息安全职能时需要加强中央控制。rn研究结果表明,在未来的研究中应考虑到国家文化,尤其是在调查从事安全性调查的组织时全球环境-并了解其如何影响行为和决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号