SwePub
Tyck till om SwePub Sök här!
Sök i LIBRIS databas

  Utökad sökning

onr:"swepub:oai:DiVA.org:oru-103050"
 

Sökning: onr:"swepub:oai:DiVA.org:oru-103050" > Tailoring informati...

Tailoring information security policies : a computerized tool and a design theory

Rostami, Elham, 1983- (författare)
Örebro universitet,Handelshögskolan vid Örebro Universitet
Karlsson, Fredrik, professor, 1974- (preses)
Örebro universitet,Handelshögskolan vid Örebro Universitet
Kolkowska, Ella, docent, 1972- (preses)
Örebro universitet,Handelshögskolan vid Örebro Universitet
visa fler...
Gao, Shang, docent, 1982- (preses)
Örebro universitet,Handelshögskolan vid Örebro Universitet
Furnell, Steven, professor (opponent)
University of Nottingham, Nottingham, UK
visa färre...
 (creator_code:org_t)
ISBN 9789175294896
Örebro : Örebro universitet, 2023
Engelska 149 s.
Serie: Örebro Studies in Informatics ; 21
  • Doktorsavhandling (övrigt vetenskapligt/konstnärligt)
Abstract Ämnesord
Stäng  
  • Protecting information assets in organizations is a must and one way for doing it is developing information security policy (ISP) to direct employees’ behavior and define acceptable procedures that employees have to comply with on a daily basis. However, compliance with the ISP is a perennial problem. Non-compliance with ISPs is at least related to two factors: 1) employees’ behavior, and 2) the design of ISPs. Although much attention has been given to understanding and changing employees’ behavior, designing ISPs that are easy to follow has received less attention. Existing research has suggested designing such ISPs using a tailoring approach where the ISP is designed in several versions that fulfill the needs of different target groups of employees. At the same time, tailoring means increased design complexity for information security managers as the designer of ISPs, where computerized tool can aid. Thus, the aim of this thesis is to develop a computerized tool to support information security managers’ tailoring of ISPs and the design principles that such a tool can be based on. To this end, a design science research approach was employed. Using the knowledge from the Situational Method Engineering field as the kernel theory for the design science research project, a set of design principles and a conceptual model were developed in terms of a Unified Modeling Language class diagram. Subsequently, a web-based software (POLCO) was developed based on the proposed conceptual model to support information security managers to design tailored ISPs. The conceptual model and POLCO were developed, demonstrated, and evaluated as a proof-of-concept in three DSR cycles.The thesis contribute to research and practice by proposing the design principles and the conceptual model that can be considered as: 1) a new theory on how to design ISPs, 2) a way to develop software to assist information security managers in designing tailored ISPs. Meanwhile, POLCO as an artifactual contribution can be considered as a starting point for researchers to do studies in the ISP design area.

Ämnesord

SAMHÄLLSVETENSKAP  -- Medie- och kommunikationsvetenskap -- Systemvetenskap, informationssystem och informatik med samhällsvetenskaplig inriktning (hsv//swe)
SOCIAL SCIENCES  -- Media and Communications -- Information Systems, Social aspects (hsv//eng)

Nyckelord

Information security management software
tailorable information security policy
policy component
design science
POLCO

Publikations- och innehållstyp

vet (ämneskategori)
dok (ämneskategori)

Hitta via bibliotek

Till lärosätets databas

Sök utanför SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Stäng

Kopiera och spara länken för att återkomma till aktuell vy