IADIS International Journal on Computer Science and Information Systems

Published by IADIS (International Association for Development of the Information Society) • ISSN (Online): 1646-3692 • ISSN (Print): 1646-3692
100% Open Access
Double-Blind Peer Review
Crossref DOI Persistent IDs
Open Access Peer-Reviewed Original Research

Institutionalization of Information Systems Security Policies Adoption: Factors and Guidelines

Isabel Maria Lopes *
Instituto Politécnico de Bragança *
Portugal Filipe de Sá-Soares *
Centro ALGORITMI *
Departamento de Sistemas de Informação *
Universidade Researcher *
* do Minho, Portugal (Portugal)
* do Minho, Portugal (Portugal)
* do Minho, Portugal (Portugal)
* do Minho, Portugal (Portugal)
* do Minho, Portugal (Portugal)
* do Minho, Portugal (Portugal)

Abstract

Information systems security policies are pointed out in literature as one of the main controls to be applied by organizations for protecting their information systems. Despite this, it has been observed that, in several sectors of activity, the number of organizations having adopted that control is low. This study aimed to identify the factors which condition the adoption of information systems security policies by organizations. Methodologically, the study involved interviewing the officials in charge of information systems in 44 Town Councils in Portugal. The factors facilitating and inhibiting the adoption of information systems security policies are presented and discussed. Based on these factors, a set of recommendations to enhance the adoption of information systems security policies is proposed. The study used Institutional Theory as a theoretical framework.

Keywords

Information Systems Security Policies Adoption Information Systems Security Institutionalization Institutional Theory.
Full-Text PDF Available

Read Complete Peer-Reviewed Manuscript

Includes full econometric models, data tables, policy recommendations, declarations, and citations.

Declarations & Ethics

Funding: This research received academic dissemination support through ESCAP / JournalsHub publishing programs.
Conflicts of Interest: The authors declare no competing financial or institutional interests.
Peer Review: Double-blind peer reviewed by international subject specialists.
License: Creative Commons Attribution 4.0 International (CC BY 4.0).
How to Cite This Article
APA / MLA / BibTeX
Lopes, et al. (2014). Institutionalization of Information Systems Security Policies Adoption: Factors and Guidelines. IADIS International Journal on Computer Science and Information Systems, 9(2). https://doi.org/10.33965/ijcsis_2014_v9i2_07
Lopes, et al. "Institutionalization of Information Systems Security Policies Adoption: Factors and Guidelines." IADIS International Journal on Computer Science and Information Systems, vol. 9, no. 2, 2014. https://doi.org/10.33965/ijcsis_2014_v9i2_07
Lopes, et al. "Institutionalization of Information Systems Security Policies Adoption: Factors and Guidelines." IADIS International Journal on Computer Science and Information Systems 9, no. 2 (2014). https://doi.org/10.33965/ijcsis_2014_v9i2_07