To read this content please select one of the options below:

Organizational practices as antecedents of the information security management performance: An empirical investigation

Daniel Pérez-González (Department of Business Administration, University of Cantabria, Santander, Spain)
Sara Trigueros Preciado (Department of Business Administration, University of Cantabria, Santander, Spain)
Pedro Solana-Gonzalez (Department of Business Administration, University of Cantabria, Santander, Spain)

Information Technology & People

ISSN: 0959-3845

Article publication date: 12 June 2019

Issue publication date: 23 September 2019

994

Abstract

Purpose

The purpose of this paper is to expand current knowledge about the security organizational practices and analyze its effects on the information security management performance.

Design/methodology/approach

Based on the literature review, the authors propose a research model together with hypotheses. The survey questionnaires were developed to collect data, which then validated the measurement model. The authors collected 111 responses from CEOs at manufacturing small- and medium-sized enterprises (SMEs) that had already implemented security policies. The hypothesized relationships were tested using the structural equation model approach with EQS 6.1 software.

Findings

Results validate that information security knowledge sharing, information security education and information security visibility, as well as security organizational practices, have a positive effect on the information security management performance.

Research limitations/implications

The consideration of organizational aspects of information security should be taken into account by academics, practitioners and policymakers in SMEs. Besides, the work helps validate novel constructs used in recent research (information security knowledge sharing and information security visibility).

Practical implications

The authors extend previous works by analyzing how security organizational practices affect the performance of information security. The results suggest that an improved performance of information security in the industrial SMEs requires innovative practices to foster knowledge sharing among employees.

Originality/value

The literature recognizes the need to develop empirical research on information security focused on SMEs. Besides the need to identify organizational practices that improve information security, this paper empirically investigates SMEs’ organizational practices in the security of information and analyzes its effects on the performance of information security.

Keywords

Citation

Pérez-González, D., Preciado, S.T. and Solana-Gonzalez, P. (2019), "Organizational practices as antecedents of the information security management performance: An empirical investigation", Information Technology & People, Vol. 32 No. 5, pp. 1262-1275. https://doi.org/10.1108/ITP-06-2018-0261

Publisher

:

Emerald Publishing Limited

Copyright © 2019, Emerald Publishing Limited

Related articles