Title of article :
Theorizing the concept and role of assurance in information systems security
Author/Authors :
Janine L. Spears، نويسنده , , Henri Barki، نويسنده , , Russell R. Barton، نويسنده ,
Issue Information :
روزنامه با شماره پیاپی سال 2013
Pages :
8
From page :
598
To page :
605
Abstract :
Assurance has different meanings, depending on the source, audience, and interpretation. We applied institutional theory and the Capability Maturity Model to conceptualize assurance: its symbolic aspects to gain social acceptance, and its substantive aspects to improve organizational capability and effectiveness in performing IS security risk management (SRM). An empirical study examined assurance-seeking behavior and outcomes for regulatory compliance. Some degree of process maturity in SRM was found necessary for producing convincing verbal accounts and compliance evidence. Findings suggest that unless an organizationʹs assurance claims are based on achieving Level 4 maturity, assurance will be based more on symbolism than effectiveness.
Keywords :
Regulatory compliance , assurance , Institutional Theory , Information systems security , Process maturity , Organizational legitimacy
Journal title :
Information and Management
Serial Year :
2013
Journal title :
Information and Management
Record number :
1227110
Link To Document :
بازگشت