The increasing frequency, impact, consequence and sophistication of cybersecurity attacks is becoming a strategic concern for boards and executive management of organisations. Consequently, in addition to focusing on productivity and performance, organisations are prioritizing Information Security Management (ISM). However, research has revealed little or no conceptualisation of a dynamic ISM capability and its link to organisational performance. In this research, we set out to 1) define and describe an organisational level dynamic ISM capability, 2) to develop a strategic model that links resources with this dynamic capability, and then 3) empirically demonstrate how dynamic ISM capability contributes to firm performance. By drawing on Resource-Based Theory (RBT) and Dynamic Capabilities View (DCV), we have developed the Dynamic ISM Capability model to address the identified gap. As we develop this research, we will empirically test this model to demonstrate causality between ISM capability and organisational performance.
翻译:网络安全攻击日益频繁、影响、后果和复杂,正成为各组织董事会和行政管理部门的一个战略关切问题,因此,除了注重生产力和业绩外,各组织正在优先注重信息安全管理(ISM),然而,研究显示,对动态的ISM能力及其与组织业绩的联系的概念化很少或根本没有。在这项研究中,我们提出:(1) 界定和描述组织一级的动态ISM能力;(2) 开发一种战略模式,将资源与这种动态能力联系起来;(3) 经验性地展示动态ISM能力如何有助于稳定业绩。我们借助基于资源的理论(RBT)和动态能力视图(DCV),开发了动态ISM能力模型,以解决所查明的差距。我们开发这一研究时,我们将用实验性方法测试这一模式,以证明ISM能力与组织业绩之间的因果关系。