Identifying Governance Dimensions to Evaluate Information Systems Security in Organizations

Gurpreet S. Dhillon, Gurvirender P. S. Tejay, Weiyin Hong · 2007

Prior studies in information systems security have a limited emphasis on empirically identifying security dimensions. This research paper presents the results of an empirical study to understand governance dimensions of information systems security. The research study was conducted in three phases involving interviews, an exploratory phase and a confirmatory phase. The exploratory phase generated a 4-factor, 16-item model for behavioral security of an organization. The confirmatory phase involving structural equation modeling validated the impact of governance dimensions on the overall information systems security of an organization. Data was collected from two different samples of 163 and 175 respondents for each phase respectively. The results suggest that the governance dimensions impact information system security of an organization through behavioral security

Read the paper · More papers on PaperTik