Information Security in Cross-Enterprise Collaborative Knowledge Work

Ann Majchrzak, Sirkka L. Järvenpää · SSRN Electronic Journal · 2004

Collaboration across enterprises is becoming increasingly necessary in today’s competitive marketplace. Such cross-enterprise collaboration requires simultaneously rich knowledge sharing and maximal information security, an often paradoxical accord. Current approaches to information security do not effectively manage this paradox in collaborative knowledge processes that take on an emergent nature. We propose a knowledge worker centric model of information security that considers individual and organizational factors that affect the decisions knowledge workers make whether to share or not in a collaborative relationship. These dynamic decisions involve trading off the consequences of sharing against the consequences of not sharing. We discuss strategies that help ensure that the appropriate balance is struck. A knowledge worker centric approach to security helps promote secure sharing in emergent collaborative knowledge work. Information security breaches as top management challenge Any time two individuals at two different organizations collaborate, there exists the opportunity for an information security breach. A security breach occurs when events, activities, or circumstances lead a person, acting in an organizational role, to deviate from security standards either in the fact of their occurrence or in their consequence, producing harm to the organization. Security breaches take many forms (e.g., password compromises, computer viruses, illicit access, unauthorized sharing). Here we focus on unauthorized sharing of private or confidential organizational information. These breaches may be inadvertent; that is, committed by people who lack criminal intent and immediate self-interested financial gain, or they may be intentional. Examples of types of information security breaches include sharing corporate secrets with a collaborative partner, providing individuals from a partner organization with access to proprietary or confidential information, and failing to follow security procedures to prevent a third party from gaining access to proprietary information.

Read the paper · More papers on PaperTik