2007 40th Annual Hawaii International Conference on System Sciences (HICSS'07) 2007
DOI: 10.1109/hicss.2007.58
|View full text |Cite
|
Sign up to set email alerts
|

An Action Research Program to Improve Information Systems Security Compliance across Government Agencies

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
8
0

Year Published

2009
2009
2023
2023

Publication Types

Select...
2
2
2

Relationship

0
6

Authors

Journals

citations
Cited by 10 publications
(8 citation statements)
references
References 20 publications
0
8
0
Order By: Relevance
“…Our survey findings are based on five projects exploring action research and safety and may be somewhat biased, due to the small size of the study. Our survey reveals that an action research approach contributes to safety improvements and improved understanding of security issues, as described by Smith et al (2007).…”
Section: Resilience At Interfacesmentioning
confidence: 93%
See 1 more Smart Citation
“…Our survey findings are based on five projects exploring action research and safety and may be somewhat biased, due to the small size of the study. Our survey reveals that an action research approach contributes to safety improvements and improved understanding of security issues, as described by Smith et al (2007).…”
Section: Resilience At Interfacesmentioning
confidence: 93%
“…trying to influence practice by new guidelines followed by reflections and discussions in a group setting of how practice can be improved by the use of the guidelines. Smith et al (2007) discussed the use of ISO standard ISO/IEC 27002 (2005) in government. They described how information systems security compliance across government agencies was improved by using action research.…”
Section: Resilience At Interfacesmentioning
confidence: 99%
“…In other cases, compliance with information security is not well established within the information security operations [60]. Researchers have argued that security compliance can be improved through more security awareness programs [61]; senior management involvement with a high awareness and education, and comprehensive understanding of security issues [62]; security awareness and training programs which increase understanding of the possible risks [63]; and assessment of compliance with the applicable laws and regulations [64]. Others have argued that constant monitoring and enforcement of individual employees' behaviors will influence compliance with policy [65,66].…”
Section: Information Security Compliancementioning
confidence: 99%
“…Action research is beginning to take root in e-Government, and recent studies cover a wide variety of themes including: design and development of information systems (Pardo & Scholl, 2002;Wastell, Kawalek, Langmead-Jones, & Ormerod, 2004), focus groups in service development (Axelsson & Melin, 2007), citizen participation (Axelsson & Melin, 2008), security (Smith, Jamieson, & Winchester, 2007) and how an organization moves from one e-Government stage to the next (Lee, 2010). The choice of theme seems to have little influence on the decision to use action research.…”
Section: Introductionmentioning
confidence: 99%
“…The choice of theme seems to have little influence on the decision to use action research. However they show some convergence in methodological approach, tending either to use canonical action research (Scholl, 2004;Smith et al, 2007;Wastell et al, 2004), or to avoid specifying much methodological detail.…”
Section: Introductionmentioning
confidence: 99%