Frame misalignment: interpreting the implementation of information systems security certification in an organization

被引:56
作者
Hsu, Carol W. [1 ]
机构
[1] Natl Taiwan Univ, Dept Informat Management, Taipei 106, Taiwan
关键词
IS security; technological frames; IS security standard; security certification; interpretive research; institutionalization; TECHNOLOGICAL FRAMES; STANDARDS; ISO-9000; PERSPECTIVE; ADOPTION;
D O I
10.1057/ejis.2009.7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although several studies have discussed the framework and value of information systems (IS) security standards and certification, there has been relatively little empirical research on how different groups of stakeholders in an organization interpret and behave during the implementation process. In an attempt to fill this research gap, this study employs a socio-cognitive perspective, namely the concept of frames analysis, to investigate how the managers and employees of a financial institution make sense of IS security certification, BS 7799 Part 2, and how these interpretations influence their actions. Using an interpretive case study approach, the findings show that the expectations of management have a strong impact on the implementation of the certification process. Moreover, the incongruence between the perceptions of managers and those of the certification team and other employees means that IS security management concepts may not be fully embedded in the organization's work practices and routines. This article argues that during the certification process, managers should place more emphasis on the identification of frame incongruence and undertake early intervention to align frames in order to achieve overall security effectiveness in the organization. European Journal of Information Systems (2009) 18, 140-150. doi:10.1057/ejis.2009.7; published online 31 March 2009
引用
收藏
页码:140 / 150
页数:11
相关论文
共 52 条
[1]  
Anderson SW, 1999, PROD OPER MANAG, V8, P28
[2]   Strategic response to institutional influences on information systems outsourcing [J].
Ang, S ;
Cummings, LL .
ORGANIZATION SCIENCE, 1997, 8 (03) :235-256
[3]  
[Anonymous], 2006, CSI FBI COMPUTER CRI
[4]  
Backhouse J, 2006, MIS QUART, V30, P413
[5]  
Bandura A., 1986, SOCIAL FDN THOUGHT A, DOI DOI 10.5465/AMR.1987.4306538
[6]   Challenges of EDI adoption for electronic trading in the London Insurance Market [J].
Barrett, MI .
EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 1999, 8 (01) :1-15
[7]   Technical efficiency or adaptation to institutionalized expectations? The adoption of ISO 9000 standards in the German mechanical engineering industry [J].
Beck, N ;
Walgenbach, P .
ORGANIZATION STUDIES, 2005, 26 (06) :841-866
[8]  
Bijker W., 1987, The Social Construction of Technological Systems: New directions in the sociology of Theroy and Technology, P17, DOI DOI 10.1177/030631284014003004
[9]   ISO 9000: Outside the iron cage [J].
Boiral, O .
ORGANIZATION SCIENCE, 2003, 14 (06) :720-737
[10]   TOWARD A MODEL OF ORGANIZATIONS AS INTERPRETATION SYSTEMS [J].
DAFT, RL ;
WEICK, KE .
ACADEMY OF MANAGEMENT REVIEW, 1984, 9 (02) :284-295