An integrative study of information systems security effectiveness
International Journal of Information ManagementPublished 28 February 2003Open access
Atreyi Kankanhalli, Hock‐Hai Teo, Bernard C. Y. Tan, Kwok‐Kee Wei
Citations492
SJR quartileQ4
SJR score0.11
SNIP0.06
Generate an AI Snapshot to get a quick, structured summary of this paper.
Study Snapshot
ObjectiveStudy objective
MethodsResearch methodology
PopulationPopulation studied
Sample sizeSample sizes
OutcomesStudy outcomes here
ResultsStudy results comes here
LimitationsResearch study limitations comes here
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
This study develops an integrative model of IS security effectiveness and empirically tests the model, finding greater deterrent efforts and preventive measures were found to lead to enhancedIS security effectiveness.
Abstract
10.1016/S0268-4012(02)00105-6
Keywords
Computer Science
Academy of Management JournalORGANIZATIONAL INNOVATION: A META-ANALYSIS OF EFFECTS OF DETERMINANTS AND MODERATORS.
6,409 Citations1991Fariborz Damanpour
Psychology Press eBooksA First Course in Factor Analysis
4,461 Citations2013Andrew L. Comrey, Howard B. Lee
Long Range PlanningStrategic planning for information systems
1,206 Citations1990Antônio Carlos dos Santos
Strategic Planning for Information Systems describes tools, techniques and management frameworks to both align strategies for IS and IT with business strategy, as well as seek out new opportunities through innovative deployment of technology.
Advanced Methods of Marketing Research
1,150 Citations1994Richard P. Bagozzi
MIS QuarterlyCoping With Systems Risk: Security Planning Models for Management Decision Making1
1,124 Citations1998Detmar W. Straub, Richard J. Welke
Results of comparative qualitative studies in two information services Fortune 500 firms identify an approach that can effectively deal with systems risk, and this theory-based security program includes use of a security risk planning model, education/training in security awareness, and Countermeasure Matrix analysis.
MIS QuarterlyKey Issues in Information Systems Management
828 Citations1987James C. Brancheau, James C. Wetherbe
The research confirmed the expected in some areas and revealed surprises in other areas, and a number of conclusions are drawn about managing information systems and about the changing nature of the IS executive's job.
Information Systems ResearchEffective IS Security: An Empirical Study
728 Citations1990Detmar W. Straub
Investigation of whether a management decision to invest in IS security results in more effective control of computer abuse indicates that security countermeasures that include deterrent administrative procedures and preventive security software will result in significantly lower computer abuse.
MIS QuarterlyDeterminants of Success for Computer Usage in Small Business
708 Citations1988William DeLone
Investigates the factors associated with successful computer use in small manufacturing firms and indicates that chief executive knowledge of computers and involvement in computer operations are vital to CBIS success.
MIS QuarterlyKey Issues in Information Systems Management: 1994-95 SIM Delphi Results1
704 Citations1996James C. Brancheau, Brian D. Janz +1 more
Signaling an evolutionary shift in IS management, this study shows that business relationship issues have declined in importance compared to technology infrastructure issues.
MIS QuarterlyInformation Technology and Corporate Strategy: A Research Perspective
648 Citations1986J. Yannis Bakos, Michael E. Treacy
The major efforts to arrive at a relevant framework are surveyed and the focus then turns to the major research issues in understanding the impact of information technology on competitive strategy.
Management ScienceOrganizational Context and the Success of Management Information Systems
558 Citations1978Phillip Ein-Dor, Eli Segev
Law & Society ReviewPerceptual Research on General Deterrence: A Critical Review
464 Citations1986Kirk R. Williams, Richard Hawkins
MIS QuarterlyThreats to Information Systems: Today’s Reality, Yesterday’s Understanding
416 Citations1992Karen D. Loch, Houston H. Carr +1 more
A study investigating MIS executives' concern about a variety of threats found computer viruses to be a particular concern, highlighting a gap between the use of modern technology and the understanding of the security implications inherent in its use.
Communications of the ACMTechnical opinion: Information system security management in the new millennium
397 Citations2000Gurpreet Dhillon, James Backhouse
This “Technical Opinion” focuses on understanding the nature of information security in the next millennium and suggests a set of principles that would help in managing information securityIn the future.
MIS QuarterlyDiscovering and Disciplining Computer Abuse in Organizations: A Field Study1
329 Citations1990Detmar W. Straub, William D. Nance
Results of the study suggest that purposeful detection of abuse incidents is used less than other methods of discovering abuse and that certain perpetrators are able to hide their identities and abusive activities.
Journal of Management Information SystemsPreventive and Deterrent Controls for Software Piracy
296 Citations1997Ram D. Gopal, G. Lawrence Sanders
An analytical model is developed to test the implications of antipiracy measures on publisher profits and suggests that preventive controls decrease profits and deterrent controls can potentially increase profits.
Information Systems ResearchOrganizational Characteristics and Information Systems Planning: An Empirical Study
291 Citations1994G. Premkumar, William R. King
A research model is developed that links two major dimensions of IS planning-the quality of the planning process and planning effectiveness-with a set of eight organizational factors derived from contingency research in IS planning, strategic business planning, organizational studies, and technology innovation.
Information Systems ResearchAn Empirical Investigation of Factors Influencing the Success of Customer-Oriented Strategic Systems
288 Citations1990Blaize Horner Reich, Izak Benbasat
The study investigated eleven systems to discover the factors which enabled or inhibited the following outcomes: developing a first-mover customer-oriented strategic system (COSS); achieving a high level of adoption of the COSS by customers; obtaining competitive advantage from the Coss.
Crime and JusticeResearch in Criminal Deterrence: Laying the Groundwork for the Second Decade
273 Citations1980Philip J. Cook
Journal of Management Information SystemsPassword Security: An Empirical Study
250 Citations1999Moshe Zviran, William J. Haga
The core characteristics of user-generated passwords and associations among those characteristics are investigated to address the gap in evaluating the characteristics of real-life passwords and present the results of an empirical study on password usage.
American Sociological ReviewToward a Theory of Criminal Deterrence
246 Citations1976Matthew Silberman
OmegaInformation systems success factors in small business
235 Citations1992Cs Yap, Cpp Soh +1 more
This paper presents the findings of an empirical study of key factors associated with computer-based information system (CBIS) success in small businesses and finds CBIS success is positively associated with consultant effectiveness, level of vendor support, length of the small business's CBIS experience, and level of user participation.
Journal of Management Information SystemsOrganizational Context and Information Systems Success: A Contingency Approach
227 Citations1990Louis Raymond
Data analysis results indicate that while organizational time frame and is sophistication have a direct effect upon satisfaction and usage, the effect of size, maturity, and resources is mediated by IS sophistication.
Information & ManagementSecurity concerns of system users
208 Citations1991Dale L. Goodhue, Detmar W. Straub
Fighting computer crime
176 Citations1983Donn B. Parker
Based on his 30 years as a cybercrime fighter, Donn B. Parker provides valuable technical insight about the means cybercriminals employ, as well as penetrating psychological insights into their criminal behavior and motivations.
University of Zagreb University Computing Centre (SRCE)Strategic Planning of Information Systems
163 Citations1997Josip Brumec
The hypothesis that the efficiency of IT-implementation depends on strategic planning of information system has been set and some new proposals and gudelines are give.
MIS QuarterlyExploring Modes of Facilitative Support for GDSS Technology
152 Citations1993Gary W. Dickson, Joo-Eng Lee Partridge +1 more
Two types of GDSS facilitative support are explored: chauffeur-riven and facilitator-driven; arguments are presented to the effect that, to be effective in a judgment task environment, facilitation must be open and adaptive rather than restrictive.
Information Systems ResearchInformation Technology and Corporate Strategy: A View from the Top
144 Citations1990Sirkka L. Järvenpää, Blake Ives
An analysis of letters over time suggests that the position of IT in the firm, at least as seen by the CEO, was not much different in 1987 than it had been in 1982, but has expanded considerably from its position in 1972 and 1973.
European Journal of Information SystemsStructures of responsibility and security of information systems
131 Citations1996Judy Backhouse, Gurpreet Dhillon
It is argued that an analysis of structures of responsibility in organizations leads to the development of secure information systems and an improved theoretical and conceptual foundation for analysing information systems security is suggested.
European Journal of Information SystemsRisk analysis: an interpretive feasibility tool in justifying information systems security
119 Citations1991Richard Baskerville
Perhaps risk analysis is misconceived: its ostensible value as a predictive technique is less relevant than its value as an effective communications link between the security and management professionals who must make decisions concerning capital investments in information systems security.
Computer System and Network Security
66 Citations2017Gregory B. White, Eric A. Fisch +1 more
Introductory in nature, this important book covers all aspects related to the growing field of computer security in a single text that has previously been unavailable.
Effective IS Security
48 Citations1990Detmar W. Straub
Investigating whether a management decision to invest in IS security results in more effective control of computer abuse indicates that security countermeasures that include deterrent administrative procedures and preventive security software will result in lower computer abuse.
PubMedManagement policies and procedures needed for effective computer security.
27 Citations1978Madnick Se
This article presents a comprehensive framework for understanding the various aspects of computer security and argues that the necessary control policies and procedures will become increasingly critical as the authors' reliance upon computer-based information systems continues to increase.
Computers & SecurityInformation systems security: Management success factors
15 Citations1987Charles Cresson Wood
This article discusses the managerial perspectives with which an appropriate balance between the managerial and the technical may be struck and illuminates some tried-and-true methods associated with organizational design, raising the level of management awareness, and obtaining needed resources.
ACM SIGSAC ReviewComputer abuse and security: Update on an empirical pilot study
15 Citations1986Detmar W. Straub
Questions about computer abuse abound in the popular press and in the computer trade and professional journals and focus on the extent of the problem and the abusers themselves.
Computers & SecurityComputer security policy: Important issues
12 Citations1988Jan H. P. Eloff
Issues of critical importance in compiling a computer security policy, such as accountability, responsibility and the actual scope of computer security, are addressed.
John Wiley & Sons, Inc. eBooksAuditing Information Systems: A Comprehensive Reference Guide
10 Citations1998Jack J. Champlain
Auditing Information Systems is a first-of-a-kind handbook to auditing in an information systems environment, allowing the nontechnical auditor to quickly and thoroughly assess the effectiveness of a company's controls in physical and logical security as well as other general controls.
