首页> 外文期刊>Computers & Security >Information security management in ICT and non-ICT sector companies: A preventive innovation perspective
【24h】

Information security management in ICT and non-ICT sector companies: A preventive innovation perspective

机译:ICT和非ICT部门公司的信息安全管理:预防性创新视角

获取原文
获取原文并翻译 | 示例
           

摘要

Despite the growing dependence of companies on information technology and the increasingly negative impact of security incidents worldwide, there is little research on the management of information security at the company level. This paper seeks to expand knowledge on the implementation of an information security management system based on the widely used international standard ISO/IEC 27001. We present motives, experienced impacts, and obstacles related to ISO/IEC 27001 implementation using data from a survey of 125 ISO/IEC 27001 certified companies in Germany. Since adoption rates vary between ICT and non-ICT sector companies, we highlight sector-related variations. We classify the adoption of this standard as a preventive organizational innovation and apply Structural Equation Modeling to unearth explanations for the comparatively low adoption of this management system standard among companies outside the ICT sector. We, therefore, derive recommendations for policymakers, standardization, and certification bodies to foster its diffusion.
机译:尽管公司对信息技术的依赖性越来越多,但全球安全事件的日益负面影响,但对公司水平的信息安全管理几乎没有研究。本文旨在扩展基于广泛使用的国际标准ISO / IEC 27001的信息安全管理系统的知识。我们使用125调查的数据提出与ISO / IEC 27001实施相关的动机,经验丰富的影响和障碍ISO / IEC 27001 Cerneried Companies in德国。由于收养率因ICT和非ICT部门公司之间而异,因此我们突出了与部门相关的变化。我们将本标准作为预防组织创新的通过,并将结构方程模型应用于ICT部门以外的公司中该管理系统标准的相对低利用的解释。因此,我们推导了对政策制定者,标准化和认证机构的建议,以促进其扩散。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号