Original Article
European Journal of Information Systems (2009) 18, 140–150; doi:10.1057/ejis.2009.7; published online 31 March 2009
Frame misalignment: interpreting the implementation of information systems security certification in an organization
Carol W Hsu1
1Department of Information Management, National Taiwan University, Taiwan
Correspondence: Carol W. Hsu, Department of Information Management, National Taiwan University, No.1, Sec. 4, Roosevelt Road, Taipei City 106, Taiwan. Tel: +886 2 3366 1196; Fax: +886 2 3366 1199
Received 1 April 2008; Revised 16 August 2008; Re-revised 15 January 2009; Accepted 23 February 2009; Published online 31 March 2009.
Abstract
Although several studies have discussed the framework and value of information systems (IS) security standards and certification, there has been relatively little empirical research on how different groups of stakeholders in an organization interpret and behave during the implementation process. In an attempt to fill this research gap, this study employs a socio-cognitive perspective, namely the concept of frames analysis, to investigate how the managers and employees of a financial institution make sense of IS security certification, BS 7799 Part 2, and how these interpretations influence their actions. Using an interpretive case study approach, the findings show that the expectations of management have a strong impact on the implementation of the certification process. Moreover, the incongruence between the perceptions of managers and those of the certification team and other employees means that IS security management concepts may not be fully embedded in the organization's work practices and routines. This article argues that during the certification process, managers should place more emphasis on the identification of frame incongruence and undertake early intervention to align frames in order to achieve overall security effectiveness in the organization.
Keywords:
IS security, technological frames, IS security standard, security certification, interpretive research, institutionalization
MORE ARTICLES LIKE THIS
These links to content published by Palgrave Macmillan are automatically generated.
RESEARCH
Frame misalignment: interpreting the implementation of information systems security certification in an organizationEuropean Journal of Information Systems Original Article
Creating a Green Brand for Competitive DistinctionAsian Business & Management Article
The roles of internal audit in complying with the Sarbanes?Oxley ActInternational Journal of Disclosure and Governance Original Article
Institutional assessment tools for sustainability in higher education: strengths, weaknesses, and implications for practice and theoryHigher Education Policy Article
The Sarbanes-Oxley Act of 2002 (SOX): A redundant regulation for the banking industryJournal of Banking Regulation Original Article
See all 13 matches for Research


