A holistic view on organizational IT security: The influence of contextual aspects during IT security decisions

6Citations
Citations of this article
28Readers
Mendeley users who have this article in their library.

Abstract

Decisions regarding organizational IT security are often approximated by models drawing on normative statistical decision theories even though several IS researchers and studies in cognate disciplines have argued for the importance of contextual aspects. Based on findings in organizational and behavioral science and 25 expert interviews, this paper proposes a framework, postulating that IT security (investment) decisions are largely influenced by such contextual aspects: organizational, environmental, economic, and not least of all by cognitive and behavioral aspects of decision-makers. Subsequently, we review organizational IT security literature building on Straub and Welke's Security Risk Planning Model and the previously postulated conceptual framework. This critical literature review highlights the scarcity of studies analyzing IT security decision-making from a behavioral, environmental, and organizational perspective and thus argues for the importance and future consideration of contextual aspects regarding IT security decisions.

Cite

CITATION STYLE

APA

Heidt, M., Gerlach, J. P., & Buxmann, P. (2019). A holistic view on organizational IT security: The influence of contextual aspects during IT security decisions. In Proceedings of the Annual Hawaii International Conference on System Sciences (Vol. 2019-January, pp. 6145–6154). IEEE Computer Society. https://doi.org/10.24251/hicss.2019.739

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free