Institutionalization of information security: Case of the Indonesian banking sector.
详细信息   
  • 作者:Nasution ; Muhamad Faisal Fariduddin Attar.
  • 学历:Doctor
  • 年:2012
  • 导师:Dhillon,Gurpreet S.,eadvisorChin,Amita G.ecommittee memberKasper,George M.ecommittee memberRedmond,Richard R.ecommittee memberWood,Van R.ecommittee member
  • 毕业院校:Virginia Commonwealth University
  • Department:Information Systems.
  • ISBN:9781267574671
  • CBH:3523906
  • Country:USA
  • 语种:English
  • FileSize:5044154
  • Pages:305
文摘
This study focuses on the institutionalization of information security in the banking sector. This study is important to pursue since it explicates the internalization of information security governance and practices and how such internalization develops an organizational resistance towards security breach. The study argues that information security governance and practices become institutionalized through social integration of routines and system integration of relevant technologies. The objective is to develop an understanding of how information security governance and practices in the Indonesian banking sector become institutionalized. Such objective is built on an argument that information security governance and practices become institutionalized through social integration of routines and system integration of relevant technologies. Pursuing this study is necessary to conceptualize the incorporation of security governance and practices as routines,the impact of security breaches on such routines,and the effects of a central governing body on such routines altogether. Accordingly,the concept of institutionalization is developed using Barley and Tolberts 1997) combination of institutional theory and structuration theory to explain the internalization of security governance and practices at an organizational level. Scotts 2008) multilevel institutional processes based on institutional theory is needed to elaborate security governance and practices in an organization-to-organization context. The research design incorporates the interpretive case-study method to capture communicative interactions among respondents. Doing so provides answers to the following research questions: 1) how institutions internalize information security governance and practices,2) how an external governing body affects the institutionalization of information security governance and practices in institutions,and 3) how security breaches re-institutionalize information security governance and practices in institutions. Several important findings include the habitualized security routines,information stewardship,and institutional relationship in information-security context. This study provides contributions to the body of literature,such as depicting how information security becomes internalized in an organization and the interaction among organizations engaged in implementing information security.

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700