• DocumentCode
    1588390
  • Title

    When IT Risk Management Produces More Harm than Good: The Phenomenon of ´Mock Bureaucracy´

  • Author

    Wiesche, Manuel ; Schermann, Michael ; Krcmar, Helmut

  • fYear
    2013
  • Firstpage
    4502
  • Lastpage
    4511
  • Abstract
    This paper investigates the complications of designing effective governance for IT risk management (IT-RM). Literature on formal governance suggests that either a coercive (i.e., to force employees´ effort and compliance) or an enabling (i.e., to help employees better to master their tasks) design of procedures help to avoid what literature calls ´mock bureaucracy´ (i.e., rules are promulgated for their symbolic value but ignored in practice). Our analysis of two organizations, however, implies that both coercive and enabling governance for IT-RM may lead to mock bureaucracy. We categorize antecedents of ´mock´ IT-RM procedures and identify important design challenges for IT-RM research and practice. Our study contributes to the IT governance body of knowledge by linking types of bureaucracy to IT governance tasks and providing anti-patterns associated with IT-RM procedures.
  • Keywords
    Guidelines; Organizations; Risk management; Security; Standards organizations; IT governance; IT risk management; coercive; enabling; mock bureaucracy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Sciences (HICSS), 2013 46th Hawaii International Conference on
  • Conference_Location
    Wailea, HI, USA
  • ISSN
    1530-1605
  • Print_ISBN
    978-1-4673-5933-7
  • Electronic_ISBN
    1530-1605
  • Type

    conf

  • DOI
    10.1109/HICSS.2013.607
  • Filename
    6480386