To read this content please select one of the options below:

Formulating information systems risk management strategies through cultural theory

Aggeliki Tsohou (Department of Information and Communication Systems Engineering, University of the Aegean, Samos, Greece)
Maria Karyda (Department of Information and Communication Systems Engineering, University of the Aegean, Samos, Greece)
Spyros Kokolakis (Department of Information and Communication Systems Engineering, University of the Aegean, Samos, Greece)
Evangelos Kiountouzis (Department of Informatics, Athens University of Economics and Business, Athens, Greece)

Information Management & Computer Security

ISSN: 0968-5227

Article publication date: 1 May 2006

5650

Abstract

Purpose

The purpose of this paper is to examine the potential of cultural theory as a tool for identifying patterns in the stakeholders' perception of risk and its effect on information system (IS) risk management.

Design/methodology/approach

Risk management involves a number of human activities which are based on the way the various stakeholders perceive risk associated with IS assets. Cultural theory claims that risk perception within social groups and structures is predictable according to group and individual worldviews; therefore this paper examines the implications of cultural theory on IS risk management as a means for security experts to manage stakeholders perceptions.

Findings

A basic theoretical element of cultural theory is the grid/group typology, where four cultural groups with differentiating worldviews are identified. This paper presents how these worldviews affect the process of IS risk management and suggests key issues to be considered in developing strategies of risk management according to the different perceptions cultural groups have.

Research limitations/implications

The findings of this research are based on theoretical analysis and are not supported by relevant empirical research. Further research is also required for incorporating the identified key issues into information security management systems (ISMS).

Originality/value

IS security management overlooks stakeholders' risk perception; for example, there is no scheme developed to understand and manage the perception of IS stakeholders. This paper proposes some key issues that should be taken into account when developing strategies for addressing the issue of understanding and managing the perception of IS stakeholders.

Keywords

Citation

Tsohou, A., Karyda, M., Kokolakis, S. and Kiountouzis, E. (2006), "Formulating information systems risk management strategies through cultural theory", Information Management & Computer Security, Vol. 14 No. 3, pp. 198-217. https://doi.org/10.1108/09685220610670378

Publisher

:

Emerald Group Publishing Limited

Copyright © 2006, Emerald Group Publishing Limited

Related articles