2006
DOI: 10.1108/09685220610655861
|View full text |Cite
|
Sign up to set email alerts
|

An empirical study of information security policy on information security elevation in Taiwan

Abstract: Purpose -With the popularity of e-commerce, information security is vital to most organizations. For managers, building and implementing an information security policy (ISP) has long been assumed to be an effective managerial measure to elevate an organization's security level. This paper attempts to investigate the dominant factors for an organization to build an ISP, and whether an ISP may elevate an organization's security level? Design/methodology/approach -A survey was designed and the data were collected… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
20
0

Year Published

2009
2009
2020
2020

Publication Types

Select...
9
1

Relationship

0
10

Authors

Journals

citations
Cited by 42 publications
(27 citation statements)
references
References 13 publications
0
20
0
Order By: Relevance
“…One of the most significant roles of information security policy is to precisely specify user's rights and responsibilities and to successfully communicate it to all users, to ensure there is a mutual and coherent understanding of information security that is embraced by the organization [11]. This eliminates excuses for employees who fail to follow and execute security practices aligned with the organization's policy [23].…”
Section: Role and Scope Of The Information Security Policymentioning
confidence: 99%
“…One of the most significant roles of information security policy is to precisely specify user's rights and responsibilities and to successfully communicate it to all users, to ensure there is a mutual and coherent understanding of information security that is embraced by the organization [11]. This eliminates excuses for employees who fail to follow and execute security practices aligned with the organization's policy [23].…”
Section: Role and Scope Of The Information Security Policymentioning
confidence: 99%
“…One increasingly important mechanism for protecting corporate information, and in so doing helping to safeguard organizational knowledge assets, is through the formulation and application of a formal information security policy [Hinde, 2002;von Solms & von Solms, 2004]. The broad consensus within the literature is that the information security is a high level document, which defines the organizations' goals, intentions and priorities, with respect to the management of information security, as well as highlighting the roles, rights and responsibilities of individual members of staff, with respect to the attainment of the security objectives [Hong et al, 2006;Hone & Eloff 2002a]. Given their perceived importance, it is not surprising that there is already an established literature, with respect to the importance and role of the policy, as well as approaches to its formulation and dissemination.…”
Section: Introductionmentioning
confidence: 99%
“…Research has considered the role [18], importance [35], structure [4], and content [12] of the information security policy, but none have directly addressed the essential tension between the need to both share and protect information that is fundamental to organizations like an HIE. Our theoretical model addresses that tension and we apply the model to an HIE to understand how the tension is managed through the information security policy development process in such an organization.…”
Section: Formulating Policiesmentioning
confidence: 99%