arrow
Return

Value conflicts for information security management

delete2011-12-01
delete113
PRE
AI
K
Karin Hedström *
F
Fredrik Karlsson
J
Jonathan P. Allen
DOI:10.1016/j.jsis.2011.06.001delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
A business's information is one of its most important assets, making the protection of information a strategic issue. In this paper, we investigate the tension between information security policies and information security practice through longitudinal case studies at two health care facilities. The management of information security is traditionally informed by a control-based compliance model, which assumes that human behavior needs to be controlled and regulated. We propose a different theoretical model: the value-based compliance model, assuming that multiple forms of rationality are employed in organizational actions at one time, causing potential value conflicts. This has strong strategic implications for the management of information security. We believe health care situations can be better managed using the assumptions of a value-based compliance model. (C) 2011 Elsevier B.V. All rights reserved.
Keywords:
Information systems security
Information security
Health care information systems
Values
Value conflicts
Management of information security
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Strategic Information Systems cover
Journal of Strategic Information Systems
IF:
11.8
Papers:
686
Citations:
4.5K

Organization

U
University of San Francisco
Scholars:
1.1K
Papers: 874
Citations: 1.0K
O
Orebro University
Scholars:
5.0K
Papers: 4.7K
Citations: 51