Management of Information Security: Challenges and Research Directions
Document Type
Article
Publication Date
9-2007
Abstract
Over the past decade management of information systems security has emerged to be a challenging task. Given the increased dependence of businesses on computer-based systems and networks, vulnerabilities of systems abound. Clearly, exclusive reliance on either the technical or the managerial controls is inadequate. Rather, a multifaceted approach is needed. In this paper, based on a panel presented at the 2007 Americas Conference on Information Systems held in Keystone, Colorado, we provide examples of failures in information security, identify challenges for the management of information systems security, and make a case that these challenges require new theory development via examining reference disciplines. We identify these disciplines, recognize applicable research methodologies, and discuss desirable properties of applicable theories.
Source Publication
Communications of the Association for Information Systems (e-ISSN eISSN 1529-3181)
Recommended Citation
Choobineh, J., Dhillon, G., Grimaila, M. R., & Rees, J. (2007). Management of Information Security: Challenges and Research Directions. Communications of the Association for Information Systems, 20, 958–971. https://doi.org/10.17705/1CAIS.02057
Comments
The "Link to Full Text" button on this page loads the open access article version of record, hosted at the AIS repository.
© Association for Information Systems (AIS). Use for profit is not allowed.