当前位置: X-MOL 学术Information Technology & People › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Evaluating compliance for organizational information security and business continuity: three strata of ventriloqual agency
Information Technology & People ( IF 4.481 ) Pub Date : 2023-11-07 , DOI: 10.1108/itp-03-2022-0156
Marko Niemimaa

Purpose

The purpose of this research is to study how compliance evaluation becomes performed in practice. Compliance evaluation is a common practice among organizations that need to evaluate their posture against a set of criteria (e.g. a standard, legislative framework and “best practices”). The results of these evaluations have significant importance for organizations, especially in the context of information security and continuity. The author argues that how these evaluations become performed is not merely a “social” activity but shaped by the materiality of the evaluation criteria

Design/methodology/approach

The authors adopt a sociomaterial practice-based view to study the compliance evaluation through in situ participant observations from compliance evaluation workshops to evaluate organizational compliance against a information security and business continuity criteria. The empirical material was analyzed to construct vignettes that serve to illustrate the practice of compliance evaluation.

Findings

The research analysis shows how the information security and business continuity criteria themselves partake in the compliance evaluations by operating through (ventriloqually) the evaluators on three strata: the material, the textual and the structural. The author also provides a conceptualization of a hybrid agency.

Originality/value

This research contributes to lack of studies on the organizational-level compliance. Further, the research is an original contribution to information security and business continuity management by focusing on the practices of compliance evaluation. Further, the research has theoretical novelty by adopting the ventriloqual agency as a hybrid agency to study the sociomateriality of a phenomenon.



中文翻译:

评估组织信息安全和业务连续性的合规性:腹语机构的三个层次

目的

本研究的目的是研究合规性评估在实践中如何进行。合规性评估是组织中的常见做法,需要根据一组标准(例如标准、立法框架和“最佳实践”)评估其状况。这些评估的结果对于组织具有重要意义,特别是在信息安全和连续性方面。作者认为,这些评估的实施方式不仅仅是一种“社会”活动,而是由评估标准的实质性决定的

设计/方法论/途径

作者采用基于社会物质实践的观点,通过合规评估研讨会的现场参与者观察来研究合规评估,以根据信息安全和业务连续性标准评估组织合规性。对经验材料进行了分析,构建了说明合规性评估实践的小插图。

发现

研究分析显示了信息安全和业务连续性标准本身如何通过评估者(腹语地)在三个层面上进行操作来参与合规性评估:材料、文本和结构。作者还提供了混合机构的概念。

原创性/价值

这项研究导致缺乏对组织层面合规性的研究。此外,该研究通过关注合规性评估实践,对信息安全和业务连续性管理做出了原创性贡献。此外,该研究通过采用腹语机构作为混合机构来研究现象的社会物质性,具有理论新颖性。

更新日期:2023-11-05
down
wechat
bug