To read this content please select one of the options below:

An empirical study of information security policy on information security elevation in Taiwan

Kwo‐Shing Hong (Overall Planning Department, Control Yuan of Republic of China, Taipei, Taiwan, Republic of China)
Yen‐Ping Chi (Department of Management Information Systems, National Cheng‐Chi University, Taipei, Taiwan, Republic of China)
Louis R. Chao (Institute of Management Science, Tamkang University, Taipei, Taiwan, Republic of China)
Jih‐Hsing Tang (Department of Management Information Systems, National Dong Hwa University, Hualien, Taiwan, Republic of China)

Information Management & Computer Security

ISSN: 0968-5227

Article publication date: 1 March 2006

2670

Abstract

Purpose

With the popularity of e‐commerce, information security is vital to most organizations. For managers, building and implementing an information security policy (ISP) has long been assumed to be an effective managerial measure to elevate an organization's security level. This paper attempts to investigate the dominant factors for an organization to build an ISP, and whether an ISP may elevate an organization's security level?

Design/methodology/approach

A survey was designed and the data were collected from 165 chief information officers in Taiwan.

Findings

The empirical results show that some organizational characteristics (business type and MIS/IS department size) might be good predictors for the ISP adoption and that the functions, contents, implementation and procedures of an ISP may significantly contribute to managers' perceived elevation of information security.

Practical implications

Building or adopting an ISP is examined empirically to be an effective managerial measure to elevate its security level in Taiwan, and that the building of an information security should focus on the comprehensiveness of its contents, procedures and implementation items, rather than on the documents only.

Originality/value

Few empirical studies have been conducted so far to examine the effectiveness of an ISP, thus the value of this paper is high.

Keywords

Citation

Hong, K., Chi, Y., Chao, L.R. and Tang, J. (2006), "An empirical study of information security policy on information security elevation in Taiwan", Information Management & Computer Security, Vol. 14 No. 2, pp. 104-115. https://doi.org/10.1108/09685220610655861

Publisher

:

Emerald Group Publishing Limited

Copyright © 2006, Emerald Group Publishing Limited

Related articles