Skip to main content

Lund University Publications

LUND UNIVERSITY LIBRARIES

It is not my job : exploring the disconnect between corporate security policies and actual security practices in SMEs

Sadok, Moufida ; Alter, Steven and Bednar, Peter LU (2020) In Information and Computer Security 28(3). p.467-483
Abstract

Purpose: This paper aims to present empirical results exemplifying challenges related to information security faced by small and medium enterprises (SMEs). It uses guidelines based on work system theory (WST) to frame the results, thereby illustrating why the mere existence of corporate security policies or general security training often is insufficient for establishing and maintaining information security. Design/methodology/approach: This research was designed to produce a better appreciation and understanding of potential issues or gaps in security practices in SMEs. The research team interviewed 187 employees of 39 SMEs in the UK. All of those employees had access to sensitive information. Gathering information through interviews... (More)

Purpose: This paper aims to present empirical results exemplifying challenges related to information security faced by small and medium enterprises (SMEs). It uses guidelines based on work system theory (WST) to frame the results, thereby illustrating why the mere existence of corporate security policies or general security training often is insufficient for establishing and maintaining information security. Design/methodology/approach: This research was designed to produce a better appreciation and understanding of potential issues or gaps in security practices in SMEs. The research team interviewed 187 employees of 39 SMEs in the UK. All of those employees had access to sensitive information. Gathering information through interviews (instead of formal security documentation) made it possible to assess security practices from employees’ point of view. Findings: Corporate policies that highlight information security are often disconnected from actual work practices and routines and often do not receive high priority in everyday work practices. A vast majority of the interviewed employees are not involved in risk assessment or in the development of security practices. Security practices remain an illusory activity in their real-world contexts. Research limitations/implications: This paper focuses only on closed-ended questions related to the following topics: awareness of existing security policy; information security practices and management and information security involvement. Practical implications: The empirical findings show that corporate information security policies in SMEs often are insufficient for maintaining security unless those policies are integrated with visible and recognized work practices in work systems that use or produce sensitive information. The interpretation based on WST provides guidelines for enhancing information system security. Originality/value: Beyond merely reporting empirical results, this research uses WST to interpret the results in a way that has direct implications for practitioners and for researchers.

(Less)
Please use this url to cite or link to this publication:
author
; and
organization
publishing date
type
Contribution to journal
publication status
published
subject
keywords
Information security, Security practices, SMEs, Socio-technical approach, Work system theory
in
Information and Computer Security
volume
28
issue
3
pages
7 pages
publisher
Emerald Group Publishing Limited
external identifiers
  • scopus:85085917677
ISSN
2056-4961
DOI
10.1108/ICS-01-2019-0010
language
English
LU publication?
yes
id
9df6c46b-fbf6-4300-88db-30bfb1fc61ec
date added to LUP
2020-07-02 17:07:19
date last changed
2022-04-18 23:15:20
@article{9df6c46b-fbf6-4300-88db-30bfb1fc61ec,
  abstract     = {{<p>Purpose: This paper aims to present empirical results exemplifying challenges related to information security faced by small and medium enterprises (SMEs). It uses guidelines based on work system theory (WST) to frame the results, thereby illustrating why the mere existence of corporate security policies or general security training often is insufficient for establishing and maintaining information security. Design/methodology/approach: This research was designed to produce a better appreciation and understanding of potential issues or gaps in security practices in SMEs. The research team interviewed 187 employees of 39 SMEs in the UK. All of those employees had access to sensitive information. Gathering information through interviews (instead of formal security documentation) made it possible to assess security practices from employees’ point of view. Findings: Corporate policies that highlight information security are often disconnected from actual work practices and routines and often do not receive high priority in everyday work practices. A vast majority of the interviewed employees are not involved in risk assessment or in the development of security practices. Security practices remain an illusory activity in their real-world contexts. Research limitations/implications: This paper focuses only on closed-ended questions related to the following topics: awareness of existing security policy; information security practices and management and information security involvement. Practical implications: The empirical findings show that corporate information security policies in SMEs often are insufficient for maintaining security unless those policies are integrated with visible and recognized work practices in work systems that use or produce sensitive information. The interpretation based on WST provides guidelines for enhancing information system security. Originality/value: Beyond merely reporting empirical results, this research uses WST to interpret the results in a way that has direct implications for practitioners and for researchers.</p>}},
  author       = {{Sadok, Moufida and Alter, Steven and Bednar, Peter}},
  issn         = {{2056-4961}},
  keywords     = {{Information security; Security practices; SMEs; Socio-technical approach; Work system theory}},
  language     = {{eng}},
  number       = {{3}},
  pages        = {{467--483}},
  publisher    = {{Emerald Group Publishing Limited}},
  series       = {{Information and Computer Security}},
  title        = {{It is not my job : exploring the disconnect between corporate security policies and actual security practices in SMEs}},
  url          = {{http://dx.doi.org/10.1108/ICS-01-2019-0010}},
  doi          = {{10.1108/ICS-01-2019-0010}},
  volume       = {{28}},
  year         = {{2020}},
}