Conflict Resolution in an ISO/IEC 27001 Standard Implementation: A Contradiction Management Perspective

dc.contributor.authorSoliman, Wael
dc.contributor.authorOjalainen, Anniina
dc.date.accessioned2022-12-27T19:15:22Z
dc.date.available2022-12-27T19:15:22Z
dc.date.issued2023-01-03
dc.description.abstractThe ISO/IEC 27001 standard provides organizations with guidelines to help them evaluate, document, and improve their information security processes. In practice, however, the generality of the standard can create a conflict between its requirements and the adopters’ expectations. To better understand how an organization manages such conflicts, we conduct a case study in a Finnish corporation during the standard’s implementation in one of its units. Two critical conflicts emerged: Conflict I reflects a tension between the standard requirement for disciplinary measures vis-à-vis the organization’s punishment-averse culture. Conflict II reflects a tension between the organization’s aspiration for concrete code reviewing instructions vis-à-vis the lack thereof in the standard. Our findings reveal that whereas the conflict resolution process was similar in managing both conflicts, their content was radically different. Specifically, whereas conflict I’s resolution was paradoxical, conflict II’s resolution was dialectical. We discuss the theoretical and practical implications of our findings.
dc.format.extent10
dc.identifier.doi10.24251/HICSS.2023.590
dc.identifier.isbn978-0-9981331-6-4
dc.identifier.other1322503e-73bf-4cf9-822c-06f319aa3e9f
dc.identifier.urihttps://hdl.handle.net/10125/103223
dc.language.isoeng
dc.relation.ispartofProceedings of the 56th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectInternational Perspectives for Cybersecurity
dc.subjectconflict resolution
dc.subjectcontextualism
dc.subjectdialectics
dc.subjectiso/iec 27001
dc.subjectparadox
dc.titleConflict Resolution in an ISO/IEC 27001 Standard Implementation: A Contradiction Management Perspective
dc.type.dcmitext
prism.startingpage4839

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0472.pdf
Size:
407.61 KB
Format:
Adobe Portable Document Format