Engagement et pratiques des organisations en matière de gouvernance de la sécurité de l’information

Nathalie Dagorn, Nicolas Poussing


This article looks at the issue of information security governance. To respond to the shortcomings identified in the literature, it explores (i) the process of organizations’ engagement in the governance of information security, and (ii) the practices of the organizations involved. The statistical and econometric analysis of data from a survey conducted with one hundred and twenty large companies in Luxembourg suggests that the knowledge of organizations involved in the governance of information security or promoting this approach, the expected performance, and the effort undertaken, are potential determinants of the organizations’ engagement in the process. These results may be analyzed under the unified theory of acceptance and use of technology (UTAUT) developed by Venkatesh et al. (2003). The data from organizations also helps to draw a picture of current practices in the matter of information security governance. The major originality of the research lies in the very high participation rate (85.71%) by organizations in the study, which gives the results a strong validity in what is, moreover, an extremely sensitive and confidential field. At the theoretical level, the research improves knowledge of the two issues explored. In practice, it provides managers with feedback on current practices implemented by the organizations in the field of information security governance and draws some recommendations. These contributions may also have an impact on public policies and on institutions promoting information security governance.


Engagement, governance, pratices, information security, UTAUT

DOI: http://dx.doi.org/10.9876/sim.v17i1.439

