DocumentCode
1588390
Title
When IT Risk Management Produces More Harm than Good: The Phenomenon of ´Mock Bureaucracy´
Author
Wiesche, Manuel ; Schermann, Michael ; Krcmar, Helmut
fYear
2013
Firstpage
4502
Lastpage
4511
Abstract
This paper investigates the complications of designing effective governance for IT risk management (IT-RM). Literature on formal governance suggests that either a coercive (i.e., to force employees´ effort and compliance) or an enabling (i.e., to help employees better to master their tasks) design of procedures help to avoid what literature calls ´mock bureaucracy´ (i.e., rules are promulgated for their symbolic value but ignored in practice). Our analysis of two organizations, however, implies that both coercive and enabling governance for IT-RM may lead to mock bureaucracy. We categorize antecedents of ´mock´ IT-RM procedures and identify important design challenges for IT-RM research and practice. Our study contributes to the IT governance body of knowledge by linking types of bureaucracy to IT governance tasks and providing anti-patterns associated with IT-RM procedures.
Keywords
Guidelines; Organizations; Risk management; Security; Standards organizations; IT governance; IT risk management; coercive; enabling; mock bureaucracy;
fLanguage
English
Publisher
ieee
Conference_Titel
System Sciences (HICSS), 2013 46th Hawaii International Conference on
Conference_Location
Wailea, HI, USA
ISSN
1530-1605
Print_ISBN
978-1-4673-5933-7
Electronic_ISBN
1530-1605
Type
conf
DOI
10.1109/HICSS.2013.607
Filename
6480386
Link To Document