ISSN 1477-7029
First published in 2002

   


Business Journal of Business Research Methods - Go to Home Page

   

Paper 1 - Summary
   

Home Papers in this Issue Previous Issues Site Map

    .

Home
About the Journal
Scope
Editorial Board
Submission Guidelines
Call for Papers
Book Reviews


D
ownloadable documents on this site require Adobe Acrobat Reader (which you can download here - FREE)

ECRM: The European Conference on Research Methodology for Business and Management Studies

Click for Information on ECKM 2003 Conference

Volume 5 Issue 2 July 2007

Wasting Time: The Mission Impossible with Respect to Technology-Oriented Security Approaches
Andreas E Wagner and Carole Brooke
Lincoln Business School, University of Lincoln, UK

   

The internet has revolutionised the business world to an extent perhaps never previously witnessed. It provides a means of computing and communication, but it also presents new risks. Practice shows that a lot of organisations fail to secure their ICT-networks. A clear understanding of security is needed by organisations. This includes understanding how ICT can be harnessed to leverage business performance as well as what ICT can enable this to happen but even so most organisations have an awareness of security which is strongly orientated towards technology. In contrast, behavioural aspects of security and risk are notably under prioritized. This paper will argue that this serious imbalance needs to be rectified by any organisation seeking to reduce their ICT security risks.

Organisations tend to focus on the ability of technology to minimise risks. This assumption and approach is misguided. Instead, we will focus on how a critical approach is more useful to exposing these issues. The key to secure systems is employees' perception and the action they take in accordance with the learned and perceived need for an understanding of compliance. Our research makes strong claims for the necessity to address the individual user. All it takes for an attacker to succeed in their endeavours is for one user to operate outside the boundaries of compliance. This can result in an unauthorised individual gaining access to crucial assets or a foothold into the organisation’s ICT–network.

This paper is based on preliminary research conducted as part of a PhD thesis. Its main focus is demonstrating the value in adopting a critical approach to research. It just happens to be ICT that is the subject area.

Keywords: critical research; ICT security; organizational misbehaviour; learning; compliance

Download FULL PAPER

Back to Contents

Home Up Papers in this Issue Previous Issues Site Map

EJBRM is published by Academic Conferences International Limited
Curtis Farm, Kidmore End, Nr Reading RG4 9AY, England
Tel: +44 (0)1189 724148, Fax: +44 (0)1189 724691, Email: info@ejbrm.com

Website designed by www.itdesigners.com 

Send mail to jen@itdesigners.com with questions or comments about this web site.
Copyright © 2002-2005 Electronic Journal of Business Research Methods
Last modified: November 07, 2005
ISSN 1477-7029