Home > Research > Publications & Outputs > Conceptualizing the role of IS security complia...
View graph of relations

Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Published

Standard

Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes. / Raza, Hassan; Baptista, Joao; Constantinides, Panos.
40th International Conference on Information Systems, ICIS 2019. Association for Information Systems, 2019. (40th International Conference on Information Systems, ICIS 2019).

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Harvard

Raza, H, Baptista, J & Constantinides, P 2019, Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes. in 40th International Conference on Information Systems, ICIS 2019. 40th International Conference on Information Systems, ICIS 2019, Association for Information Systems, 40th International Conference on Information Systems, ICIS 2019, Munich, Germany, 15/12/19. <https://aisel.aisnet.org/icis2019/is_development/is_development/9/>

APA

Raza, H., Baptista, J., & Constantinides, P. (2019). Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes. In 40th International Conference on Information Systems, ICIS 2019 (40th International Conference on Information Systems, ICIS 2019). Association for Information Systems. https://aisel.aisnet.org/icis2019/is_development/is_development/9/

Vancouver

Raza H, Baptista J, Constantinides P. Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes. In 40th International Conference on Information Systems, ICIS 2019. Association for Information Systems. 2019. (40th International Conference on Information Systems, ICIS 2019).

Author

Raza, Hassan ; Baptista, Joao ; Constantinides, Panos. / Conceptualizing the role of IS security compliance in projects of digital transformation : Tensions and shifts between prevention and response modes. 40th International Conference on Information Systems, ICIS 2019. Association for Information Systems, 2019. (40th International Conference on Information Systems, ICIS 2019).

Bibtex

@inproceedings{d50fd5c9762d4c36ab98a13b985e5640,
title = "Conceptualizing the role of IS security compliance in projects of digital transformation: Tensions and shifts between prevention and response modes",
abstract = "Research shows that information systems security operates between two main distinct functioning modes, either prevention before a security incident occurs, or response which follows from an incident, usually external to the organisation. In this paper, we argue that this shift between prevention and response modes also happens due to inherent internal tensions created between pressures for digital transformation and the established forces for security compliance. We show how a digital transformation project introduced a security incident and challenged the IS security compliance function, a process that reflected these two approaches to IS security in organizations. We conduct a participatory observation study of the implementation of Robotic Process Automation (RPA) in a financial services organization. We examine the shift from prevention to response in this project and identify generative drivers of digital transformation, and drivers of IS security compliance. Our analysis leads to the development of a process model that explains how organizations move from prevention to response when faced with tensions between IS security compliance and digital transformation.",
keywords = "Digital Innovation, Digital Transformation, IS Security Compliance",
author = "Hassan Raza and Joao Baptista and Panos Constantinides",
note = "Publisher Copyright: {\textcopyright} 40th International Conference on Information Systems, ICIS 2019. All rights reserved.; 40th International Conference on Information Systems, ICIS 2019 ; Conference date: 15-12-2019 Through 18-12-2019",
year = "2019",
month = dec,
day = "15",
language = "English",
series = "40th International Conference on Information Systems, ICIS 2019",
publisher = "Association for Information Systems",
booktitle = "40th International Conference on Information Systems, ICIS 2019",
address = "United States",

}

RIS

TY - GEN

T1 - Conceptualizing the role of IS security compliance in projects of digital transformation

T2 - 40th International Conference on Information Systems, ICIS 2019

AU - Raza, Hassan

AU - Baptista, Joao

AU - Constantinides, Panos

N1 - Publisher Copyright: © 40th International Conference on Information Systems, ICIS 2019. All rights reserved.

PY - 2019/12/15

Y1 - 2019/12/15

N2 - Research shows that information systems security operates between two main distinct functioning modes, either prevention before a security incident occurs, or response which follows from an incident, usually external to the organisation. In this paper, we argue that this shift between prevention and response modes also happens due to inherent internal tensions created between pressures for digital transformation and the established forces for security compliance. We show how a digital transformation project introduced a security incident and challenged the IS security compliance function, a process that reflected these two approaches to IS security in organizations. We conduct a participatory observation study of the implementation of Robotic Process Automation (RPA) in a financial services organization. We examine the shift from prevention to response in this project and identify generative drivers of digital transformation, and drivers of IS security compliance. Our analysis leads to the development of a process model that explains how organizations move from prevention to response when faced with tensions between IS security compliance and digital transformation.

AB - Research shows that information systems security operates between two main distinct functioning modes, either prevention before a security incident occurs, or response which follows from an incident, usually external to the organisation. In this paper, we argue that this shift between prevention and response modes also happens due to inherent internal tensions created between pressures for digital transformation and the established forces for security compliance. We show how a digital transformation project introduced a security incident and challenged the IS security compliance function, a process that reflected these two approaches to IS security in organizations. We conduct a participatory observation study of the implementation of Robotic Process Automation (RPA) in a financial services organization. We examine the shift from prevention to response in this project and identify generative drivers of digital transformation, and drivers of IS security compliance. Our analysis leads to the development of a process model that explains how organizations move from prevention to response when faced with tensions between IS security compliance and digital transformation.

KW - Digital Innovation

KW - Digital Transformation

KW - IS Security Compliance

M3 - Conference contribution/Paper

AN - SCOPUS:85099320895

T3 - 40th International Conference on Information Systems, ICIS 2019

BT - 40th International Conference on Information Systems, ICIS 2019

PB - Association for Information Systems

Y2 - 15 December 2019 through 18 December 2019

ER -