Article navigation

The Donn B. Parker Award

Article Type: 2009 Awards for Excellence From: Information Management & Computer Security, Volume 17, Issue 5

This award is named after Donn B. Parker, who, in the early 1970s, through his research and many publications introduced business management to the concept of computer security. His coining of the term ``computer abuse'' helped to draw attention to this important business function. Donn Parker is now heavily involved in the International Information Integrity Institute, the so-called I4 Research group at SRI International.

The following article was selected for this year's Outstanding Paper Award for Information Management & Computer Security

"Knowing is doing: an empirical validation of the relationship between managerial information security awareness and action''

Namjoo ChoiInformatics, State University of New York at Albany, Albany, New York, USADan KimComputer Information Systems, University of Houston-Clear Lake, Houston, Texas, USAJahyun GooInformation Technology and Operations Management, Florida Atlantic University, Boca Raton, Florida, USAAndrew WhitmoreInformatics, State University of New York at Albany, Albany, New York, USA

Purpose – The purpose of this paper is to empirically validate the conjectural relationship between managerial information security awareness(MISA) and managerial actions toward information security (MATIS).Design/methodology/approach – A model is developed and the relationship between MISA and MATIS is tested using a large set of empirical data collected across different types and sizes of enterprises. The hypotheses of the research model are tested with regression analysis.Findings – The results of the study provide empirical support that MATIS is directly and positively related to MISA.Research limitations/implications– The R2, an estimate of the proportion of the total variation in the data set that is explained by the model, is relatively low. This fact implies that there are other constructs in addition to MISA that play a crucial role in determining MATIS. The paper suggests that intention to act and the risk-cost tradeoff of the MATIS are other possible constructs that should be incorporated into future research. The conceptual model employed as a theoretical basis also suggests that other factors such as the environment in which an organization operates (e.g. industry) also plays a major role in determining information security decisions independently of MISA. Other possible limitations include the use of secondary data in the study.Practical implications– The results indicate that developing strategies to raise an organization's MISA should impact MATIS and thus improve information security performance.Originality/value – The study provides empirical evidence supporting the unproven link between MISA and MATIS.Keywords Data security, Information systems, Management strategy

www.emeraldinsight.com/10.1108/09685220810920558

This article originally appeared in Volume 16 Number 5, 2008, pp. 484-501, Information Management & Computer Security

The following articles were selected for this year's Highly Commended Award

"Process-variance models in information security awareness research''

Angeliki TsohouSpyros KokolakisMaria KarydaEvangelos Kiountouzis

This article originally appeared in Volume 16 Number 3, 2008, Information Management & Computer Security

"A test of interventions for security threats from social engineering''

Michael Workman

This article originally appeared in Volume 16 Number 5, 2008, Information Management & Computer Security

or Create an Account

Close subscription notice
Close access options