Need 15 Page APA formatted document on INFORMATION SECURITY CONTROL THEORY

profilehome student
Introduction.docx

Introduction

In today’s face paced business environments, organizations operate in a digitally connected environment. Businesses utilize Information Technology (IT) resources and systems for handling, operating, and sharing data and information within all aspects of the organizational structure. IT resources facilitate the entire business in terms of better performance, fast and accurate data handling and storage, personnel productivity, business process issue-resolving, marketing, and other applications (Warkentin & Willison, 2009). An important aspect of the business process is that of the data transmission and the transmission and storage of sensitive information that flows and is maintained across an organizations’ IT network. This data use is what drives the organizations bottom line and its’ efficient access and use is what assists leadership in their strategies to maximum profit. Within this domain, threats, both internal and external, to the business’ Information Systems (IS) is an on-going concern for the entire organization.

Organizations today face huge risks issues regarding IT security. The information security control theory was developed and introduced for managing IT security issues. The theory developed certain security standards, guidelines, and policies that assist the organization in maintaining security aspects of data transmission over its’ IT networks (Allen et. al., 2014). Additionally, information security control theory ensures the organizations’ total security protection of its systems, data and information. The information security control theory addresses care of data security, privacy, integrity, and availability. A survey of research articles from 2009-2020, discussing the many aspects of this topic, have been evaluated. It becomes apparent that a gap in the research appears; what remains underserved in the literature is that if an organization applies and follows the guidelines outlined in Information Security Theory, How well does it integrated into the existing systems and processes, how does it impact the organizations’ economic bottom-line and how can that integration and impact be measured?

Discussion of Literature Survey

The vulnerability and cyber threats over the systems may raise different threat issues for the business sectors (Warkentin & Willison, 2009). It is well known that proper security control standards need to be deployed that addresses the behavioral and policy adherence issues. Enterprises focus on information technology and the information system security policies and they prefer to deploy security control policies for both employees and the end-users. The goal is to provide assured protection of the organizational information systems (Herath & Rao, 2009). As such, organizations consider deterrence theory, self-determination theory, protection-motivation theory for IS security control best practices. The digital and cloud arenas in which data privacy is overwhelmed with challenges and this information needs strict security as exploitation can happen on regular and continual basis (Anderson et. al., 2017).

The information systems of any organization are a continual topic of debate for management professionals. The on-going onslaught of security issues raise new threats for the organization. Behavioral research over the IS may improve practical relevance and the contextual relevance of the subject (Siponen & Vance, 2014). Violation of IS security policies poses many legal and regulatory issues, many of which include steep fines and or incarceration.

A focus on the dispositional and situational factors via various case studies details how those factors impact the violations of the information security policies (Johnston et. al., 2016). Many of the threats to the organizational information systems are taking place from the inside with the help of internal employees. The individuals' behavior, many times regarded as irritational, is based on motivation, intention, and determination (Moody et. al., 2018). The need for information security, especially in a business environment, is to ensure the psychological settings for individuals are directly related to the willingness of individuals to perform and cope with the policies and regulations. to their mechanisms' research topic.

Big data utilizes veracity, velocity, variety, and volume in ensuring data protection is maintained (Baesens et. al., 2016). The skill sets required of management to ensure facts are interpreted as expected and the information and the employees handling the information meet the security and data policies' standards requires specific and routine training. Data risks need to be tested with the help of a penetration testing (McDermott, 2001) This recommended testing will include testing all the software available for its credibility regardless of the time in which the software was developed. Testing occurs as a system test but also as an individual module test. Security decisions and policy formulation is one of management's functions, which assists in addressing threats that need to be addressed (DiGrazia & Kevin, 2018).

Employees need to be properly trained to be able to use the deployed systems without interference. In addition, employees need to be educated on proper identification and handling of confidential information and the use of restricted programs. They also need to understand which software packages should not be run on organizational computers (Ma & Kenneth, 2008). The exposure of data to third parties, which can take advantage of and leak the information. Information system security (ISS) indicates the best security practices throughout organizations for maintaining proper security aspects and ensures the preventions of the potential security threat issues (Niemimaa & Niemimaa, 2017). The policies for the ISS assist in engaging proper security practices over the organizational operations and for personnel performance requirements (Cram et. al., 2019). Security policy compliances are essential to the information systems assets deployment and maintainability requirements throughout the organizational structure.

Security control policies over the information system become an essential requirement of the organizations. At the same time, adherence to IS rules is essential for maintaining proper security control (Myyry et. al., 2009). On the other hand, employees' non-adherence behaviors to information security may raise issues and the adherence to information security can be explained with moral values and reasoning. Contemporary organizations prefer information systems for operating business processes on a large scale and the adaptations of the IT infrastructure assists in proper business integration and sharing information. All threat issues via the business information systems during transmission raise concern for the entire organization (Anderson et. al., 2017) and it is recommended they should deploy information security control theory best practices for maintaining security concerns during data transfer operations.

Organizational information security policies, which play a major role in maintaining proper security concerns over the IT applications in the organizational business (Cram, et. al., 2017) assist the organization in detecting, analyzing, evaluating potential security issues, and deploying a certain level of security for mitigating and preventing security issues. Specific research focuses on the essential concerns regarding privacy and security issues within the information systems of large organizations. The research is reexamined and evaluated for better understanding of policy and proposing the steps required for enhancing the effectiveness of security and privacy concerns of the information system (Lowry, et. al., 2017). Proper assessments are strongly encouraged that require identifying potential security and privacy issues and changes to the policy and procedures are proposed as per the legal and regulatory requirements.

Conclusion

The research articles retrieved from the European Journal of Information Systems and Management of Information Systems clearly demonstrate the reliability and the validity of the sampled research works and the context into which the research provides. From these articles, it is understood that the security and privacy concerns across all information systems becomes an essential requirement (Cram et. al., 2019.). Proper, timely and efficient collaboration both internally and externally is the goal for all organizations and their reliance on IT is the center piece and the focal point for ensuring the collaboration meets the required goals and business objectives. The research articles surveyed have discussed the necessary and essential requirements and proposed many solution suggestions and recommended best practices for utilizing the many components of information security control theory. What is discovered as a gap to the surveyed research, is a method of evaluation that measures the ease or disruption of ISS control methods integration into existing business processes and once these measures are deployed what is the impact to the organizations bottom-line?

Security and privacy threats via IS are becoming more sophisticated and methods to penetrate, destroy or steal data is becoming more and more prevalent. Weak system security aspects lead attackers to exploit organizational IS and with those attacks, hampers the overall business performance and productivity. The business challenge is to deploy the suggested best practices, in a timely and non-disruptive and economical way thus avoiding serious disruptions to business operations and or causing significant detrimental circumstances to the organizations’ economic bottom-line. Thus, the research gap that needs to be addressed is two-fold, one, methods to and measurements of the ease of integration of the information system control theory recommended policies and procedures and two, how to measure the impacts of those deployments from both a micro (small hardware, software and or policy changes) and macro (enterprise wide changes) levels to the organizations operational and economic bottom-lines.

References

Allen, D., Karanasios, S., & Norman, A. (2014). Information sharing and interoperability: the case of major incident management. European Journal of Information Systems, 23(4), 418-432.

Anderson, C., Baskerville, R., & Kaul, M. (2017). Information security control theory: Achieving a sustainable reconciliation between sharing and protecting the privacy of information. Journal of Management Information Systems, 34(4), 1082-1112.

Bhattacherjee, A., & Park, S. (2014). Why end-users move to the cloud: a migration-theoretic analysis. European Journal of Information Systems, 23(3), 357-372.

Boss, S., Kirsch, L., Angermeier, I., Shingler, R., & Boss, R. (2009). If someone is watching, I'll do what I'm asked: mandatoriness, control, and information security. European Journal of Information Systems, 18(2), 151-164.

Burton-Jones, A., McLean, E., & Monod, E. (2015). Theoretical perspectives in IS research: from variance and process to conceptual latitude and conceptual fit. European journal of information systems, 24(6), 664-679.

Catherine L. Anderson, & Ritu Agarwal. (2010). Practicing Safe Computing: A Multimethod Empirical Examination of Home Computer User Security Behavioral Intentions. MIS Quarterly34(3), 613. https://doi.org/10.2307/25750694

Cram, W., D'arcy, J., & Proudfoot, J. (2019). Seeing the forest and the trees: a meta-analysis of the antecedents to information security policy compliance. MIS Quarterly, 43(2), 525-554.

Cram, W., Proudfoot, J., & D’arcy, J. (2017). Organizational information security policies: a review and research framework. European Journal of Information Systems, 26(6), 605-641.

Detmar W. Straub, & Richard J. Welke. (1998). Coping with Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly22(4), 441. https://doi.org/10.2307/249551

Dinev, T., Xu, H., Smith, J., & Hart, P. (2013). Information privacy and correlates: an empirical attempt to bridge and distinguish privacy-related concepts. European Journal of Information Systems, 22(3), 295-316.

Herath, T., & Rao, H. (2009). Protection motivation and deterrence: a framework for security policy compliance in organisations. European Journal of Information Systems, 18(2), 106-125.

Janine L. Spears, & Henri Barki. (2010). User Participation in Information Systems Security Risk Management. MIS Quarterly34(3), 503. https://doi.org/10.2307/25750689

Johnston, A., Warkentin, M., McBride, M., & Carter, L. (2016). Dispositional and situational factors: influences on information security policy violations. European Journal of Information Systems, 25(3), 231-251.

Lowry, P., Dinev, T., & Willison, R. (2017). Why security and privacy research lies at the centre of the information systems (IS) artefact: Proposing a bold research agenda. European Journal of Information Systems, 26(6), 546-563.

Middleton, C., Scheepers, R., & Tuunainen, V. (2014). When mobile is the norm: researching mobile information systems and mobility as post-adoption phenomena. European Journal of Information Systems, 23(5), 503-512.

Middleton, C., Scheepers, R., & Tuunainen, V. (2014). When mobile is the norm: researching mobile information systems and mobility as post-adoption phenomena. European Journal of Information Systems, 23(5), 503-512.

Miltgen, C., & Peyrat-Guillard, D. (2014). Cultural and generational influences on privacy concerns: a qualitative study in seven European countries. European journal of information systems, 23(2), 103-125.

Moody, G. D., Siponen, M., & Pahnila, S. (2018). Toward a Unified Model of Information Security Policy Compliance. MIS Quarterly42(1), 285-A22.

Moody, G., Galletta, D., & Dunn, B. (2017). Which phish get caught? An exploratory study of individuals′ susceptibility to phishing. European Journal of Information Systems26(6), 564–584. https://doi.org/10.1057/s41303-017-0058-x

Myyry, L., Siponen, M., Pahnila, S., Vartiainen, T., & Vance, A. (2009). What levels of moral reasoning and values explain adherence to information security rules? An empirical study. European Journal of Information Systems, 18(2), 126-139.

Niemimaa, E., & Niemimaa, M. (2017). Information systems security policy implementation in practice: from best practices to situated practices. European Journal of Information Systems, 26(1), 1-20.

Siponen, M., & Vance, A. (2014). Guidelines for improving the contextual relevance of field surveys: the case of information security policy violations. European Journal of Information Systems, 23(3), 289-305.

Turel, O. (2016). Untangling the complex role of guilt in rational decisions to discontinue the use of a hedonic Information System. European Journal of Information Systems, 25(5), 432-447.

Warkentin, M., & Willison, R. (2009). Behavioral and policy issues in information systems security: the insider threat. European Journal of Information Systems, 18(2), 101-105.

Yoon, C., Hwang, J., & Kim, R. (2019). Exploring factors that influence students’ behaviors in information security. Journal of information systems education, 23(4), 7.