CISOs and organisational culture: Their own worst enemy?

被引:52
作者
Ashenden, Debi [1 ]
Sasse, Angela [2 ]
机构
[1] Cranfield Univ, Def Acad UK, Swindon SN6 8LA, Wilts, England
[2] UCL, Dept Comp Sci, London WC1E 6BT, England
关键词
Security awareness; Human factors; Information security management; Organisational culture; Discourse analysis; DISCOURSE;
D O I
10.1016/j.cose.2013.09.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many large organisations now have a Chief Information Security Officer (CISO1). While it may seem obvious that their role is to define and deliver organisational security goals, there has been little discussion on what makes a CISO able to deliver this effectively. In this paper, we report the results from 5 in-depth interviews with CISOs, which were analysed using organisational behaviour theory. The results show that the CISOs struggle to gain credibility within their organisation due to: a perceived lack of power, confusion about their role identity, and their inability to engage effectively with employees. We conclude that as the CISO role continues to develop CISOs need to reflect on effective ways of achieving credibility in their organisations and, in particular, to work on communicating with employees and engaging them in security initiatives. We also identify a key responsibility for effective CISOs; that is to remove the blockages that prevent information security from becoming 'business as usual' rather than a specialist function. For researchers, our findings offer a new piece of the emerging picture of human factors in information security initiatives. (C) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:396 / 405
页数:10
相关论文
共 25 条
[1]   Users are not the enemy [J].
Adams, A ;
Sasse, MA .
COMMUNICATIONS OF THE ACM, 1999, 42 (12) :41-46
[2]   A qualitative study of users' view on information security [J].
Albrechtsen, Eirik .
COMPUTERS & SECURITY, 2007, 26 (04) :276-289
[3]   Varieties of discourse: On the study of organizations through discourse analysis [J].
Alvesson, M ;
Karreman, D .
HUMAN RELATIONS, 2000, 53 (09) :1125-1149
[4]  
[Anonymous], 1996, BRIT J MANAGE
[5]  
[Anonymous], 2004, ORG CULTURE LEADERSH
[6]  
Bryman A., 2018, Samhallsvetenskapliga metoder
[7]   The logic of small samples in interview-based qualitative research [J].
Crouch, Mira ;
McKenzie, Heather .
SOCIAL SCIENCE INFORMATION SUR LES SCIENCES SOCIALES, 2006, 45 (04) :483-499
[8]   Current directions in IS security research: towards socio-organizational perspectives [J].
Dhillon, G ;
Backhouse, J .
INFORMATION SYSTEMS JOURNAL, 2001, 11 (02) :127-153
[9]  
Dhillon G., 1995, THESIS LONDON SCH EC
[10]  
Dick P., 2004, Essential guide to qualitative methods in organizational research, P203