4.6 Article

A neo-institutional perspective on the establishment of information security knowledge sharing practices

Journal

INFORMATION & MANAGEMENT
Volume 59, Issue 1, Pages -

Publisher

ELSEVIER
DOI: 10.1016/j.im.2021.103574

Keywords

Information security knowledge sharing establishment; Neoinstitutional theory; Security compliance; Security culture

Ask authors/readers for more resources

Information security knowledge sharing is crucial for an organization's protection, but many organizations struggle to establish effective practices due to a lack of understanding. This study explores the influence of institutional forces on ISKS practices, highlighting the importance of establishing such practices for employee compliance and security culture.
Information security knowledge sharing (ISKS) among an organization's employees is vital to the organization's ability to protect itself from any number of prevalent threats, yet for many organizations, their ability to establish ISKS practices is hampered by a lack of understanding of where and how the key drivers of these practices will emerge. Based on neoinstitutional theory and a multi-study field survey of 834 professional managers in the USA, we develop and test a model that explains the establishment of ISKS practices in an organization as a product of the institutional forces abut to the organization providing normative, mimetic, and coercive influences on top management beliefs and participations in ISKS. Our findings also emphasize the importance of establishing ISKS practices for ensuring employee compliance with information security policies and an effective culture of security. Prior research has shown the importance of institutional forces on organizational processes as well as the importance of ISKS to organizational security efforts. However, this study is one of the early studies to provide insight into the manner, in which institutional forces hold sway over the people responsible for establishing the ISKS practices of a firm; insight that it is essential for firms that have yet to establish such practices or have struggled in their attempts to do so.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.6
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

Article Computer Science, Information Systems

The perspective of national ERP vendors in achieving ERP project success in government organisations: a case of Saudi Arabia

Abdullah Ibrahim Alkraiji, Uchitha Jayawickrama, Femi Olan, Md Asaduzzaman, Maduka Subasinghage, Samanthika Gallage

Summary: This paper aims to explore the Key Influencing Factors (KIFs) during pre-implementation and implementation of ERP projects from the perspective of national ERP vendors. A mixed methods study was conducted on 10 national ERP vendors involved in government sector projects in Saudi Arabia. The prioritisation of KIFs revealed the most important factors to be ERP capabilities and stakeholder managers.

ENTERPRISE INFORMATION SYSTEMS (2022)

Article Computer Science, Information Systems

Enhancing ERP Responsiveness Through Big Data Technologies: An Empirical Investigation

Florie Bandara, Uchitha Jayawickrama, Maduka Subasinghage, Femi Olan, Hawazen Alamoudi, Majed Alharthi

Summary: Organizations are integrating big data technologies with ERP systems to enhance ERP responsiveness. However, managing the integration between ERP systems and big data technologies is a challenge, leading to a lack of ERP responsiveness. This study examines the factors impacting ERP responsiveness with a focus on big data technologies. The results identify 12 factors and their relationships that impact ERP responsiveness, offering practical implications for ERP and big data management practice.

INFORMATION SYSTEMS FRONTIERS (2023)

Article Computer Science, Information Systems

Governing Intra-project Modular Interdependencies in ISD Projects: A Control Theory Perspective

Subasinghage Maduka Nuwangi, Darshana Sedera, Shirish C. Srivastava

Summary: This study examines the control mechanisms for managing modularized ISD projects, uncovering the influence of intra-project modular dependencies on the choice of control mechanisms. Results show that in scenarios with low-level dependencies, formal outcome and formal behavior control mechanisms are preferred, while flexible project practices and volatile client requirements may reduce the reliance on formal controls. Additionally, the level of informal clan control is influenced by the level of interdependencies between intra-project modules.

COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS (2021)

Article Computer Science, Information Systems

A Teaching Case on Information Systems Development Outsourcing: Lessons from a Failure

Subasinghage Maduka Nuwangi, Darshana Sedera

COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS (2020)

Article Information Science & Library Science

Knowledge capabilities in supply chain networks: a taxonomy

Robert Ogulin, Gustavo Guzman, Subasinghage Maduka Nuwangi

JOURNAL OF KNOWLEDGE MANAGEMENT (2020)

Article Computer Science, Information Systems

VISTA: An inclusive insider threat taxonomy, with mitigation strategies

Karen Renaud, Merrill Warkentin, Ganna Pogrebna, Karl van der Schyff

Summary: Insider threats can cause significant damage due to insiders' access and trust. To mitigate these threats, organizations must understand different types of insider threats and employ tailored measures.

INFORMATION & MANAGEMENT (2024)

Article Computer Science, Information Systems

How the Terminator might affect the car manufacturing industry: Examining the role of pre-announcement bias for AI-based IS adoptions

Quirin Demlehner, Sven Laumer

Summary: This article discusses the challenges brought by the rapid development of artificial intelligence in the adoption of technology at an individual level. It focuses on the role of biases and examines their impact on user decision making. Through a case study of three German car manufacturers, the article highlights the importance of the pre-announcement phase in information systems adoption and provides a comprehensive analysis of biases caused by individuals' cognitive limitations. It also reveals a notable spillover effect of users' experiences and opinions on AI from their personal lives to their professional lives, which contradicts previous findings in IS research.

INFORMATION & MANAGEMENT (2024)

Article Computer Science, Information Systems

Impact of online information on the pricing and profits of firms with different levels of brand reputation

Xinyu Sun, Yan Zhang, Juan Feng

Summary: This study investigates the impact of online information on brand reputation and brand premium in the online market. The findings suggest that the presence of online information may change the situation of brand premium, and firms with lower reputation can potentially earn higher profits under certain conditions. Additionally, as the gap in brand reputation increases, the profits of both firms may also increase, leading to a win-win situation in brand competition.

INFORMATION & MANAGEMENT (2024)