Home > Research > Publications & Outputs > Conceptualizing the role of IS security complia...
View graph of relations

Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Published
Publication date15/12/2019
Host publication40th International Conference on Information Systems, ICIS 2019
PublisherAssociation for Information Systems
ISBN (electronic)9780996683197
<mark>Original language</mark>English
Event40th International Conference on Information Systems, ICIS 2019 - Munich, Germany
Duration: 15/12/201918/12/2019

Conference

Conference40th International Conference on Information Systems, ICIS 2019
Country/TerritoryGermany
CityMunich
Period15/12/1918/12/19

Publication series

Name40th International Conference on Information Systems, ICIS 2019

Conference

Conference40th International Conference on Information Systems, ICIS 2019
Country/TerritoryGermany
CityMunich
Period15/12/1918/12/19

Abstract

Research shows that information systems security operates between two main distinct functioning modes, either prevention before a security incident occurs, or response which follows from an incident, usually external to the organisation. In this paper, we argue that this shift between prevention and response modes also happens due to inherent internal tensions created between pressures for digital transformation and the established forces for security compliance. We show how a digital transformation project introduced a security incident and challenged the IS security compliance function, a process that reflected these two approaches to IS security in organizations. We conduct a participatory observation study of the implementation of Robotic Process Automation (RPA) in a financial services organization. We examine the shift from prevention to response in this project and identify generative drivers of digital transformation, and drivers of IS security compliance. Our analysis leads to the development of a process model that explains how organizations move from prevention to response when faced with tensions between IS security compliance and digital transformation.

Bibliographic note

Publisher Copyright: © 40th International Conference on Information Systems, ICIS 2019. All rights reserved.