Paradoxical tensions in the implementation of digital security governance: Toward an ambidextrous approach to governing digital security

被引:2
作者
Schinagl, Stef [1 ]
Shahim, Abbas [1 ]
Khapova, Svetlana [1 ]
机构
[1] Vrije Univ VU Amsterdam, Sch Business & Econ SBE, Amsterdam, Netherlands
关键词
Digital security governance; Ambidexterity; Paradox; Tensions; Cybersecurity governance; Cyberattacks; HIGH-RELIABILITY; INFORMATION; ORGANIZATIONS; FRAMEWORK; STRATEGY; MODEL; BACK;
D O I
10.1016/j.cose.2022.102903
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to increasing numbers of cyberattacks, security is one of the leading challenges to contemporary organizations. As contradictory demands (e.g., tensions in digital organizations) intensify, organizations increasingly find it difficult to implement digital security governance (DSG) as part of their regular or-ganizational change activities. Based on data from forty-two interviews with Dutch CISOs and CIOs of large organizations that are active in various sectors, we identify three key paradoxical tensions that af-fect DSG implementation. We found that in a digital context, paradoxical tensions are pressurized and become out of balance. Disbalance among tensions exposes friction that hinders the implementation of DSG mechanisms. Finally, we present a conceptual model that sets direction for ambidextrous digital se-curity. Understanding how to engage with tensions in an ambidextrous way determines the success of DSG implementations in today's complex digital environments.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
引用
收藏
页数:14
相关论文
共 54 条
  • [1] Agerfalk P.J., 2021, Technology, Work and Globalization, P53, DOI [10.1007/978-3-030-64884-8_2, DOI 10.1007/978-3-030-64884-8_2]
  • [2] Artefactual and empirical contributions in information systems research
    Agerfalk, Par J.
    Karlsson, Fredrik
    [J]. EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2020, 29 (02) : 109 - 113
  • [3] Information security governance challenges and critical success factors: Systematic review
    AlGhamdi, Sultan
    Khin Than Win
    Vlahu-Gjorgievska, Elena
    [J]. COMPUTERS & SECURITY, 2020, 99
  • [4] Assal H, 2018, PROCEEDINGS OF THE FOURTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, P281
  • [5] Ambidextrous Cybersecurity: The Seven Pillars (7Ps) of Cyber Resilience
    Carayannis, Elias G.
    Grigoroudis, Evangelos
    Rehman, Scheherazade S.
    Samarakoon, Navodhya
    [J]. IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2021, 68 (01) : 223 - 234
  • [6] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [7] Information systems security research agenda: Exploring the gap between research and practice
    Dhillon, Gurpreet
    Smith, Kane
    Dissanayaka, Indika
    [J]. JOURNAL OF STRATEGIC INFORMATION SYSTEMS, 2021, 30 (04)
  • [8] A systematic review of cyber-resilience assessment frameworks
    Estay, Daniel A. Sepulveda
    Sahay, Rishikesh
    Barfod, Michael B.
    Jensen, Christian D.
    [J]. COMPUTERS & SECURITY, 2020, 97
  • [9] Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture
    Flores, Waldo Rocha
    Antonsen, Egil
    Ekstedt, Mathias
    [J]. COMPUTERS & SECURITY, 2014, 43 : 90 - 110
  • [10] Gale M., 2022, Computers Security, V121, P102840, DOI DOI 10.1016/J.COSE.2022.102840