Frame misalignment: interpreting the implementation of information systems security certification in an organization
Carol W Hsu
European Journal of Information Systems, 2009, vol. 18, issue 2, 140-150
Abstract:
Although several studies have discussed the framework and value of information systems (IS) security standards and certification, there has been relatively little empirical research on how different groups of stakeholders in an organization interpret and behave during the implementation process. In an attempt to fill this research gap, this study employs a socio-cognitive perspective, namely the concept of frames analysis, to investigate how the managers and employees of a financial institution make sense of IS security certification, BS 7799 Part 2, and how these interpretations influence their actions. Using an interpretive case study approach, the findings show that the expectations of management have a strong impact on the implementation of the certification process. Moreover, the incongruence between the perceptions of managers and those of the certification team and other employees means that IS security management concepts may not be fully embedded in the organization's work practices and routines. This article argues that during the certification process, managers should place more emphasis on the identification of frame incongruence and undertake early intervention to align frames in order to achieve overall security effectiveness in the organization.
Date: 2009
References: Add references at CitEc
Citations:
Downloads: (external link)
http://hdl.handle.net/10.1057/ejis.2009.7 (text/html)
Access to full text is restricted to subscribers.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:taf:tjisxx:v:18:y:2009:i:2:p:140-150
Ordering information: This journal article can be ordered from
http://www.tandfonline.com/pricing/journal/tjis20
DOI: 10.1057/ejis.2009.7
Access Statistics for this article
European Journal of Information Systems is currently edited by Par Agerfalk
More articles in European Journal of Information Systems from Taylor & Francis Journals
Bibliographic data for series maintained by Chris Longhurst ().