Embedding information security management in organisations: improving participation and engagement through intra-organisational Liaison

4Citations
Citations of this article
24Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Effective information security management (ISM) is contingent on intra-organisational liaison (IOL) between security personnel and stakeholders in ISM processes. IOL is a set of activities undertaken by information security personnel to communicate with internal stakeholders to increase their participation and involvement in the ISM process. Unfortunately, IOL in many organisations tends to be undertaken in an ad hoc and informal manner rather than as part of a formal and systematic process. We argue that IOL activities should be planned and embedded into mainstream ISM practices. Our review of the relevant literature did not find ‘best practice’ guidelines on intra-organisational liaison (IOL) between security personnel and stakeholders in ISM. Based on findings from an in-depth exploratory study where we interviewed thirty-four information security professionals, we develop a novel framework that explains how intra-organisational liaison can be improved and specifically what IOL practices and activities are critical for effective communication with ISM stakeholders.

Cite

CITATION STYLE

APA

Alshaikh, M., Chang, S., Ahmad, A., Maynard, S. B., & Alammary, A. (2023). Embedding information security management in organisations: improving participation and engagement through intra-organisational Liaison. Security Journal, 36(3), 530–557. https://doi.org/10.1057/s41284-022-00352-3

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free