Organization Members Developing Information Security Policies : a Case Study

Abstract
Information security policies (ISPs) have a key role in organizational information security. Research has introduced processes for ISP development, including lifecycle models. There are also recommendations to include contextual issues in the ISP development to ensure that the ISP provides tailored protection to the organization’s assets. One way of ensuring this is to include organization members in the development efforts. We identified six functions for the organization member participation from the research literature. Then, we presented two case studies of organizations where the personnel was included in the ISP development process. We found that the participation of the organization members did add value to the process through these functions but that there were also some negative effects. The inclusion of organization members in ISP development can help in gathering feedback directly at the beginning of the lifecycle without the need to go through the entire cycle to identify issues.
Main Authors
Format
Conferences Conference paper
Published
2023
Subjects
Publication in research information system
Publisher
Association for Information Systems
Original source
https://aisel.aisnet.org/icis2023/cyber_security/cyber_security/14/
The permanent address of the publication
https://urn.fi/URN:NBN:fi:jyu-202401101133Käytä tätä linkitykseen.
Parent publication ISBN
978-1-958200-07-0
Review status
Peer reviewed
ISSN
1026-1079
Conference
International Conference on Information Systems
Language
English
Is part of publication
ICIS 2023 : Proceedings of the International Conference on Information Systems
Citation
License
In CopyrightOpen Access
Additional information about funding
Tekes, New methods for developing information security policies (NM4DISP)
Copyright© Association for Information Systems

Share