Publication | Closed Access
Implementation and effectiveness of organizational information security measures
149
Citations
30
References
2008
Year
CybersecurityEngineeringInformation SecurityOrganizational BehaviorAuditingSecurity AwarenessManagementSystem SecurityOrganizational SystemsSecurity ManagementCybersecurity PolicyInformation ManagementInformation Security ManagersInformation Security ManagementOrganization TheorySecurityNorwegian OrganizationsBusinessSecurity GovernanceTechnology
The study highlights the non‑technological aspects of information security and examines how combinations of organizational measures differ from single‑measure approaches. The paper investigates how organizational information security measures are implemented and evaluates their effectiveness. A survey of information security managers in selected Norwegian organizations was used to collect data. Technical‑administrative measures are most commonly implemented, yet awareness‑creating activities—though less frequent—are judged more effective, revealing an inverse relationship between implementation frequency and perceived effectiveness.
Purpose The purpose of this paper is to study the implementation of organizational information security measures and assess the effectiveness of such measures. Design/methodology/approach A survey was designed and data were collected from information security managers in a selection of Norwegian organizations. Findings Technical‐administrative security measures such as security policies, procedures and methods are the most commonly implemented organizational information security measures in a sample of Norwegian organizations. Awareness‐creating activities are applied by the organizations to a considerably lesser extent, but are at the same time these are assessed as being more effective organizational measures than technical‐administrative ones. Consequently, the study shows an inverse relationship between the implementation of organizational information security measures and assessed effectiveness of the organizational information security measures. Originality/value Provides insight into the non‐technological side of information security. While most other studies look at the effectiveness of single organizational security measures, the present study considers combinations of organizational security measures.
| Year | Citations | |
|---|---|---|
Page 1
Page 1