Perceived significance of information security governance to predict the information security service quality in software service industry: An empirical analysis

被引:7
作者
Bahl, Sanjay [1 ]
Wali, O.P. [1 ]
机构
[1] Indian Institute of Foreign Trade, New Delhi
来源
Information Management and Computer Security | 2014年 / 22卷 / 01期
关键词
Corporate governance; Indian software service providers; Information security governance; Information security service quality; IT outsourcing; Supply chain; TQM;
D O I
10.1108/IMCS-01-2013-0002
中图分类号
学科分类号
摘要
Purpose - Information security is a growing concern in society, across businesses and government. As the offshore IT services market continues to grow providing numerous benefits, there are also perceived risks with respect to the quality of information security delivered in the supply chain. This paper aims to examine, as a case, the perceptions of Indian software services provider (service provider) employees with respect to information security governance and its impact on information security service quality that is delivered to customers. Design/methodology/approach - The paper provides a framework built upon the existing dimensions and instruments for total quality management and service quality, suitably modified to reflect the context of information security. SmartPLS, a structural equation modelling technique, has been used to analyse field survey data collected from across various Indian cities and companies. Findings - Significant finding is that information security governance in an IT outsourcing company providing software services has a highly significant impact on the information security service quality, which can be predicted. The paper also establishes that there is a positive relationship collectively between elements of information security governance and information security service quality. Research limitations/implications - Since data used in this study were taken solely from the responses of employees of outsourced service companies in India, it does not show if this translates into service improvements as perceived by the customer. Practical implications - Information security governance should be made an integral part of corporate governance and is an effective strategic technique, if software outsourcing business enterprises want to achieve a competitive edge, provide client satisfaction and create trust. Originality/value - The paper presents empirical data validation of the connection between information security governance and quality of service. Copyright © 2014 Emerald Group Publishing Limited. All rights reserved.
引用
收藏
页码:2 / 23
页数:21
相关论文
共 78 条
[11]  
Chin W.W., Issues and opinion on structural equation modelling, MIS Quarterly, 22, 1, pp. 7-16, (1998)
[12]  
Chin W.W., The partial least squares approach for structural equation modelling, Modern Methods for Business Research, Methodology for Business and Management, pp. 295-336, (1998)
[13]  
Chin W.W., Newsted P.R., Structural equation modeling analysis with small samples using partial least squares, Statistical Strategies for Small Sample Research, pp. 307-342, (1999)
[14]  
Chin W.W., Marcolin B.L., Newsted P.R., A partial least squares latent variable modeling approach for measuring interaction effects: Results from a Monte Carlo simulation study and voice mail emotion/adoption study, Proceedings of the Seventeenth International Conference on Information Systems, (1996)
[15]  
Leading Practices and Guidelines for Enterprise Security Governance, (2006)
[16]  
Cook L.S., Verma R., Exploring the linkages between quality system, service quality, and performance excellence: Service providers' perspectives, Quality Management Journal, 9, 2, pp. 44-56, (2002)
[17]  
Cronbach L.J., Coefficient alpha and the internal structure of tests, Psychometrika, 16, 3, pp. 297-334, (1951)
[18]  
Curkovic S., Melnyk S., Calantone R., Handfield R., Validating the Malcolm Baldrige National Quality Award framework through structural equation modelling, International Journal Production Research, 38, 4, pp. 765-791, (2000)
[19]  
Fink D., A security framework for information systems outsourcing, Information Management & Computer Security, 2, 4, pp. 3-8, (1994)
[20]  
Firesmith D.G., Common Concepts Underlying Safety, Security, and Survivability Engineering, (2003)