Practice-Based Discourse Analysis of InfoSec Policies
2015 (English)In: ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SPRINGER-VERLAG BERLIN , 2015, Vol. 455, p. 297-310Conference paper, Published paper (Refereed)
Abstract [en]
Employees poor compliance with information security policies is a perennial problem for many organizations. Existing research shows that about half of all breaches caused by insiders are accidental, which means that one can question the usefulness of information security policies. In order to support the formulation of practical, from the employees perspective, information security policies, we propose eight tentative quality criteria. These criteria were developed using practice-based discourse analysis on three information security policy documents from a health care organisation.
Place, publisher, year, edition, pages
SPRINGER-VERLAG BERLIN , 2015. Vol. 455, p. 297-310
Keywords [en]
Information security policy; Discourse analysis; Communicative analysis; Quality criteria
National Category
Other Engineering and Technologies
Identifiers
URN: urn:nbn:se:liu:diva-123170DOI: 10.1007/978-3-319-18467-8_20ISI: 000364779100020ISBN: 978-3-319-18467-8 (print)OAI: oai:DiVA.org:liu-123170DiVA, id: diva2:877268
Conference
30th IFIP TC 11International Information Security and Privacy Conference (SEC)
2015-12-062015-12-042015-12-06