Reinforcing the security of corporate information resources: A critical review of the role of the acceptable use policy

نویسندگان

  • Neil F. Doherty
  • Leonidas Anastasakis
  • Heather Fulford
چکیده

Increasingly users are seen as the weak link in the chain, when it comes to the security of corporate information. Should the users of computer systems act in any inappropriate or insecure manner, then they may put their employers in danger of financial losses, information degradation or litigation, and themselves in danger of dismissal or prosecution. This is a particularly important concern for knowledge-intensive organisations, such as Universities, as the effective conduct of their core teaching and research activities is becoming ever more reliant on the availability, integrity and accuracy of computer-based information resources. One increasingly important mechanism for reducing the occurrence of inappropriate behaviours, and in so doing, protecting corporate information, is through the formulation and application of a formal ‘acceptable use policy (AUP). Whilst the AUP has attracted some academic interest, it has tended to be prescriptive and overly focussed on the role of the Internet, and there is relatively little empirical material that explicitly addresses the purpose, positioning or content of real acceptable use policies. The broad aim of the study, reported in this paper, is to fill this gap in the literature by critically examining the structure and composition of a sample of authentic policies – taken from the higher education sector rather than simply making general prescriptions about what they ought to contain. There are two important conclusions to be drawn from this study: 1) the primary role of the AUP appears to be as a mechanism for dealing with unacceptable behaviour, rather than proactively promoting desirable and effective security behaviours, and 2) the wide variation found in the coverage and positioning of the reviewed policies is unlikely to be fostering a coherent approach to security management, across the higher education sector.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Critical Success Factors in implementing information security governance (Case study: Iranian Central Oil Fields Company)

The oil industry, as one of the main industries of the country, has always faced cyber attacks and security threats. Therefore, the integration of information security in corporate governance is essential and a governance challenge. The integration of information security and corporate governance is called information security governance. In this research, we identified "critical success factor...

متن کامل

Information Technology & Social Role of Users in Collection Development of Library and Information Centers

The process of collection development, collection generating and obtaining information is of basic debates in libraries and information centers which a lot of articles have been written about the methods of collection development of information as well as the application of information technology, accordingly, to this day. This article, as opposed to other articles, which are about the prevaili...

متن کامل

طراحی مدل سیاست گذاری رسانه ایی سازمان تامین اجتماعی ایران

Introduction: Mass media plays a crucial role in information distribution and thus in the political market and public policy making. Theory predicts that the information provided by mass media reflects the media’s incentives to provide news to different types of groups in society, and affects these groups’ influence in policy-making. A few empirical studies have tried to assess the effect of me...

متن کامل

طراحی مدل سیاست گذاری رسانه ایی سازمان تامین اجتماعی ایران

Introduction: Mass media plays a crucial role in information distribution and thus in the political market and public policy making. Theory predicts that the information provided by mass media reflects the media’s incentives to provide news to different types of groups in society, and affects these groups’ influence in policy-making. A few empirical studies have tried to assess the effect of me...

متن کامل

Coordination of promotional effort, corporate social responsibility and periodic review replenishment decisions in a two-echelon socially responsible supply chain

In this paper, we explore the issue of coordination in a manufacturer-retailer supply chain where the manufacturer is socially responsible and invests in CSR activities. On the other hand, the retailer invests in promotional efforts and uses a periodic review order-up-to policy for replenishing items. First, the decentralized decision-making structure is modeled to calculate the minimum accepta...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Int J. Information Management

دوره 31  شماره 

صفحات  -

تاریخ انتشار 2011