2020
DOI: 10.1177/0162243919901159
|View full text |Cite
|
Sign up to set email alerts
|

Governing Uncertainty or Uncertain Governance? Information Security and the Challenge of Cutting Ties

Abstract: Information security governance has become an elusive goal and a murky concept. This paper problematizes both information security governance and the broader concept of governance. What does it mean to govern information security, or for that matter, anything? Why have information technologies proven difficult to govern? And what assurances can governance provide for the billions of people who rely on information technologies every day? Drawing together several distinct bodies of literature—including multiple … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

0
21
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
6
1

Relationship

0
7

Authors

Journals

citations
Cited by 15 publications
(21 citation statements)
references
References 70 publications
0
21
0
Order By: Relevance
“…The study of governance of cybersecurity requires interdisciplinary research [30] drawing, among others, from governance theory, actor-network theory, and the study of sociotechnical regimes [35]. Research on Internet governance has already utilised actor-network theory and interpretative policy analysis to conceptualise multi-stakeholder arrangements engaging heterogeneous actors [36,37].…”
Section: Methodsmentioning
confidence: 99%
“…The study of governance of cybersecurity requires interdisciplinary research [30] drawing, among others, from governance theory, actor-network theory, and the study of sociotechnical regimes [35]. Research on Internet governance has already utilised actor-network theory and interpretative policy analysis to conceptualise multi-stakeholder arrangements engaging heterogeneous actors [36,37].…”
Section: Methodsmentioning
confidence: 99%
“…More specifically, if provision of water is a matter of public interest, what about the protection of industrial facilities, algorithms and data surrounding it? In analyzing the notion of governance, we take on board its conceptual fluidity and multiple meanings across disciplines (Rothstein et al 2013;Slayton 2020). For our analysis, we understand governance and its outcomes (i.e., regulations) as actions and actors aiming to achieve specific goals pertaining to the protection of public interest.…”
Section: Introductionmentioning
confidence: 99%
“…In particular, most studies have not comprehensively or clearly explained the processes of establishing security governance in organizations or provided guidelines for its implementation [6,21]. Implementing security governance remains difficult in complex connected digital environments because of "cutting ties", i.e., tensions [14]. Conflicts between information security values and work efficiency are the most common [5].…”
Section: Introductionmentioning
confidence: 99%
“…However, security governance literature is relatively immature, i.e. largely descriptive and provides both limited practical and theoretical guidance [6,13,14]. In particular, studies lack empirical understanding about the processes of establishing security governance in organizations or provided guidelines for its implementation [6,21].…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation