Existing research shows that the Information Systems Security policies' (ISSPs) inability to reflect current practice is a perennial problem resulting in users' non-compliant behaviors. While the existing compliance approaches are beneficial in many ways, they do not consider the complexity of Information Systems Security (ISS) management and practice where different actors adhere to different and sometimes conflicting values. The unsolved value conflicts often lead to unworkable ISS processes and users' resistance. To address this shortcoming, this paper suggests a value conflicts analysis as a starting point for implementing work-friendly ISSPs. We show that the design and implementation of a work-friendly ISSP should involve the negotiation for different values held by the different actors within an organization. © 2012 IFIP International Federation for Information Processing.
CITATION STYLE
Kolkowska, E., & De Decker, B. (2012). Analyzing value conflicts for a work-friendly ISS policy implementation. In IFIP Advances in Information and Communication Technology (Vol. 376 AICT, pp. 339–351). https://doi.org/10.1007/978-3-642-30436-1_28
Mendeley helps you to discover research relevant for your work.