To read this content please select one of the options below:

Information security in supply chains: a management control perspective

Sindhuja P N (Department of Operations & IT, ICFAI Business School Hyderabad, Hyderabad, India.)
Anand S. Kunnathur (Department of IOTM, University of Toledo, Toledo, Ohio, United States.)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 9 November 2015

13868

Abstract

Purpose

This paper aims to discuss the need for management control system for information security management that encapsulates the technical, formal and informal systems. This motivated the conceptualization of supply chain information security from a management controls perspective. Extant literature on information security mostly focused on technical security and managerial nuances in implementing and enforcing technical security through formal policies and quality standards at an organizational level. However, most of the security mechanisms are difficult to differentiate between businesses, and there is no one common platform to resolve the security issues pertaining to varied organizations in the supply chain.

Design/methodology/approach

The paper was conceptualized based on the review of literature pertaining to information security domain.

Findings

This study analyzed the need and importance of having a higher level of control above the already existing levels so as to cover the inter-organizational context. Also, it is suggested to have a management controls perspective for an all-encompassing coverage to the information security discipline in organizations that are in the global supply chain.

Originality/value

This paper have conceptualized the organizational and inter-organizational challenges that need to be addressed in the context of information security management. It would be difficult to contain the issues of information security management with the existing three levels of controls; hence, having a higher level of security control, namely, the management control that can act as an umbrella to the existing domains of security controls was suggested.

Keywords

Citation

P N, S. and Kunnathur, A.S. (2015), "Information security in supply chains: a management control perspective", Information and Computer Security, Vol. 23 No. 5, pp. 476-496. https://doi.org/10.1108/ICS-07-2014-0050

Publisher

:

Emerald Group Publishing Limited

Copyright © 2015, Emerald Group Publishing Limited

Related articles