{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T17:26:51Z","timestamp":1754155611577,"version":"3.41.2"},"reference-count":97,"publisher":"Emerald","issue":"2","license":[{"start":{"date-parts":[[2023,11,7]],"date-time":"2023-11-07T00:00:00Z","timestamp":1699315200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ITP"],"published-print":{"date-parts":[[2025,3,14]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-subheading\">Purpose<\/jats:title><jats:p>The purpose of this research is to study how compliance evaluation becomes performed in practice. Compliance evaluation is a common practice among organizations that need to evaluate their posture against a set of criteria (e.g. a standard, legislative framework and \u201cbest practices\u201d). The results of these evaluations have significant importance for organizations, especially in the context of information security and continuity. The\u00a0author argues that how these evaluations become performed is not merely a \u201csocial\u201d activity but shaped by the materiality of the evaluation criteria<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Design\/methodology\/approach<\/jats:title><jats:p>The authors adopt a sociomaterial practice-based view to study the compliance evaluation through in situ participant observations from compliance evaluation workshops to evaluate organizational compliance against a information security and business continuity criteria. The empirical material was analyzed to construct vignettes that serve to illustrate the practice of compliance evaluation.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Findings<\/jats:title><jats:p>The research analysis shows how the information security and business continuity criteria themselves partake in the compliance evaluations by operating through (ventriloqually) the evaluators on three strata: the material, the textual and the structural. The author also provides a conceptualization of a hybrid agency.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-subheading\">Originality\/value<\/jats:title><jats:p>This research contributes to lack of studies on the organizational-level compliance. Further, the research is an original contribution to information security and business continuity management by focusing on the practices of compliance evaluation. Further, the research has theoretical novelty by adopting the ventriloqual agency as a hybrid agency to study the sociomateriality of a phenomenon.<\/jats:p><\/jats:sec>","DOI":"10.1108\/itp-03-2022-0156","type":"journal-article","created":{"date-parts":[[2023,11,4]],"date-time":"2023-11-04T09:36:36Z","timestamp":1699090596000},"page":"604-625","source":"Crossref","is-referenced-by-count":1,"title":["Evaluating compliance for organizational information security and business continuity: three strata of ventriloqual agency"],"prefix":"10.1108","volume":"38","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3733-830X","authenticated-orcid":false,"given":"Marko","family":"Niemimaa","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","published-online":{"date-parts":[[2023,11,7]]},"reference":[{"issue":"3","key":"key2025031312453597400_ref001","doi-asserted-by":"publisher","DOI":"10.1016\/J.IM.2022.103623","article-title":"Standardizing information security \u2013 a structurational analysis","volume":"59","year":"2022","journal-title":"Information and Management"},{"issue":"Special Issue","key":"key2025031312453597400_ref002","first-page":"413","article-title":"Circuits of power in creating de jure standards: shaping an international information systems security standard","volume":"30","year":"2006","journal-title":"MIS Quarterly"},{"volume-title":"Meeting the Universe Halfway: Quantum Physics and the Entanglement of Matter and Meaning","year":"2007","key":"key2025031312453597400_ref003"},{"issue":"3","key":"key2025031312453597400_ref004","doi-asserted-by":"crossref","first-page":"404","DOI":"10.2307\/2393937","article-title":"Technicians in the workplace: ethnographic evidence for bringing work into organizational studies","volume":"41","year":"1996","journal-title":"Administrative Science Quarterly"},{"issue":"2","key":"key2025031312453597400_ref005","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1057\/ejis.2009.8","article-title":"If someone is watching, I\u2019ll do what I'm asked: mandatoriness, control, and information security","volume":"18","year":"2009","journal-title":"European Journal of Information Systems"},{"issue":"5-6","key":"key2025031312453597400_ref006","doi-asserted-by":"publisher","first-page":"737","DOI":"10.1177\/0170840612443626","article-title":"Standardization cycles: a process perspective on the formation and diffusion of transnational standards","volume":"33","year":"2012","journal-title":"Organization Studies"},{"journal-title":"Canadian Journal of Higher Education","article-title":"Correlates and consequences of degree purchasing among Canadian university students, 2005","year":"2005","key":"key2025031312453597400_ref007"},{"issue":"5-6","key":"key2025031312453597400_ref008","doi-asserted-by":"publisher","first-page":"613","DOI":"10.1177\/0170840612450120","article-title":"The dynamics of standardization: three perspectives on standards in organization studies","volume":"33","year":"2012","journal-title":"Organization Studies"},{"issue":"2","key":"key2025031312453597400_ref009","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1016\/j.infoandorg.2014.03.001","article-title":"What have we learned from the Smart Machine?","volume":"24","year":"2014","journal-title":"Information and Organization"},{"issue":"1","key":"key2025031312453597400_ref010","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1016\/J.JSIS.2010.09.006","article-title":"Compliance with institutional imperatives on environmental sustainability: building theory on the role of Green IS","volume":"20","year":"2011","journal-title":"The Journal of Strategic Information Systems"},{"key":"key2025031312453597400_ref011","doi-asserted-by":"crossref","unstructured":"Cecez-Kecmanovic, D. (2016), \u201cFrom substantialist to process metaphysics -- Exploring shifts in IS research\u201d, in Introna, L., Kavanagh, D., Kelly, S., Orlikowski, W. and Scott, S. (Eds), Beyond Interpretivism? New Encounters with Technology and Organization, Springer, Cham, Switzerland, pp.\u00a035-57.","DOI":"10.1007\/978-3-319-49733-4_3"},{"issue":"3","key":"key2025031312453597400_ref012","doi-asserted-by":"crossref","first-page":"809","DOI":"10.25300\/MISQ\/2014\/38:3.3","article-title":"The sociomateriality of information systems: current status, future directions","volume":"38","year":"2014","journal-title":"MIS Quarterly"},{"issue":"2","key":"key2025031312453597400_ref013","doi-asserted-by":"crossref","first-page":"561","DOI":"10.25300\/MISQ\/2014\/38.2.11","article-title":"Reframing success and failure of information systems: a performative perspective","volume":"38","year":"2014","journal-title":"MIS Quarterly"},{"issue":"1","key":"key2025031312453597400_ref014","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/J.JCAE.2018.11.002","article-title":"The impact of internal audit attributes on the effectiveness of internal control over operations and compliance","volume":"15","year":"2019","journal-title":"Journal of Contemporary Accounting and Economics"},{"key":"key2025031312453597400_ref015","first-page":"958","article-title":"Management of information security: challenges and research directions","volume":"20","year":"2007","journal-title":"Communications of the ACM"},{"issue":"4","key":"key2025031312453597400_ref016","doi-asserted-by":"publisher","first-page":"2274","DOI":"10.1016\/J.DSS.2006.08.002","article-title":"Continuous auditing with a multi-agent system","volume":"42","year":"2007","journal-title":"Decision Support Systems"},{"first-page":"1","article-title":"Ethnographic field research: interpreting one's entrance into the field as thrownness","year":"2014","key":"key2025031312453597400_ref017"},{"issue":"4","key":"key2025031312453597400_ref018","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1016\/j.istr.2010.04.005","article-title":"Information security management: an entangled research challenge","volume":"14","year":"2009","journal-title":"Information Security Technical Report"},{"issue":"3","key":"key2025031312453597400_ref019","doi-asserted-by":"crossref","first-page":"373","DOI":"10.1177\/1350508404041998","article-title":"Textual agency: how texts do things in organizational settings","volume":"11","year":"2004","journal-title":"Organization"},{"issue":"3","key":"key2025031312453597400_ref020","doi-asserted-by":"crossref","first-page":"475","DOI":"10.1177\/0893318915584825","article-title":"Studying agency from a ventriloqual perspective","volume":"29","year":"2015","journal-title":"Management Communication Quarterly"},{"issue":"6","key":"key2025031312453597400_ref021","doi-asserted-by":"crossref","first-page":"605","DOI":"10.1057\/s41303-017-0059-9","article-title":"Organizational information security policies: a review and research framework","volume":"26","year":"2017","journal-title":"European Journal of Information Systems"},{"issue":"2","key":"key2025031312453597400_ref022","doi-asserted-by":"publisher","first-page":"525","DOI":"10.25300\/MISQ\/2019\/15117","article-title":"Seeing the forest and the trees","volume":"43","year":"2019","journal-title":"MIS Quarterly"},{"issue":"3","key":"key2025031312453597400_ref023","first-page":"183","article-title":"Maximizing employee compliance with cybersecurity policies","volume":"19","year":"2020","journal-title":"MIS Quarterly Executive"},{"issue":"4","key":"key2025031312453597400_ref024","doi-asserted-by":"publisher","DOI":"10.1016\/J.JSIS.2021.101693","article-title":"Information systems security research agenda: exploring the gap between research and practice","volume":"30","year":"2021","journal-title":"The Journal of Strategic Information Systems"},{"issue":"7","key":"key2025031312453597400_ref025","doi-asserted-by":"crossref","first-page":"897","DOI":"10.1177\/0170840615575191","article-title":"From rational myth to self-fulfilling prophecy? Understanding the persistence of means\u2013ends decoupling as a consequence of the latent functions of policy enactment","volume":"36","year":"2015","journal-title":"Organization Studies"},{"issue":"1","key":"key2025031312453597400_ref026","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1111\/J.1467-9930.1991.TB00058.X","article-title":"Legal ambiguity and the politics of compliance: affirmative action officers' dilemma","volume":"13","year":"1991","journal-title":"Law and Policy"},{"issue":"2","key":"key2025031312453597400_ref027","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1057\/EJIS.2015.9","article-title":"Factors influencing the intention to comply with data protection regulations in hospitals: based on gender differences in behaviour and deterrence","volume":"25","year":"2015","journal-title":"European Journal of Information Systems"},{"key":"key2025031312453597400_ref028","doi-asserted-by":"publisher","first-page":"11209","DOI":"10.1007\/s10668-022-02524-y","article-title":"Understanding compliance with voluntary sustainability standards: a machine learning approach","volume":"25","year":"2022","journal-title":"Environment, Development and Sustainability"},{"volume-title":"The Interpretation of Cultures: Selected Essays","year":"1973","key":"key2025031312453597400_ref029"},{"volume-title":"The Interpretation of Cultures","year":"1973","key":"key2025031312453597400_ref030"},{"issue":"1","key":"key2025031312453597400_ref031","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1057\/JIT.2013.16","article-title":"The role of investment management systems in regulatory compliance: a post-financial crisis study of displacement mechanisms","volume":"29","year":"2014","journal-title":"Journal of Information Technology"},{"issue":"2","key":"key2025031312453597400_ref032","first-page":"75","article-title":"Criteria for assessing the trustworthiness of naturalistic inquiries","volume":"29","year":"1981","journal-title":"Educational Technology Research and Development"},{"key":"key2025031312453597400_ref033","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1145\/3462757.3466081","article-title":"A\u00a0combined rule-based and machine learning approach for automated GDPR compliance checking","year":"2021"},{"issue":"2","key":"key2025031312453597400_ref034","doi-asserted-by":"crossref","first-page":"140","DOI":"10.1057\/ejis.2009.7","article-title":"Frame misalignment: interpreting the implementation of information systems security certification in an organization","volume":"18","year":"2009","journal-title":"European Journal of Information Systems"},{"issue":"3-Part-2","key":"key2025031312453597400_ref035","doi-asserted-by":"publisher","first-page":"918","DOI":"10.1287\/isre.1110.0393","article-title":"Institutional influences on information systems security innovations","volume":"23","year":"2012","journal-title":"Information Systems Research"},{"issue":"2","key":"key2025031312453597400_ref036","doi-asserted-by":"crossref","first-page":"282","DOI":"10.1287\/isre.2015.0569","article-title":"The role of extra-role behaviors and social controls in information security policy effectiveness","volume":"26","year":"2015","journal-title":"Information Systems Research"},{"issue":"4","key":"key2025031312453597400_ref037","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1016\/j.istr.2008.10.010","article-title":"Information security management standards: compliance, governance and risk management","volume":"13","year":"2008","journal-title":"Information Security Technical Report"},{"issue":"1","key":"key2025031312453597400_ref038","doi-asserted-by":"publisher","first-page":"383","DOI":"10.14318\/hau4.1.021","article-title":"That's enough about ethnography","volume":"4","year":"2014","journal-title":"Hau: Journal of Ethnographic Theory"},{"issue":"4","key":"key2025031312453597400_ref039","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1177\/1476127014554575","article-title":"Producing persuasive findings: demystifying ethnographic textwork in strategy and organization research","volume":"12","year":"2014","journal-title":"Strategic Organization"},{"issue":"5","key":"key2025031312453597400_ref040","doi-asserted-by":"publisher","DOI":"10.1016\/J.BAR.2018.06.001","article-title":"The role of auditing in the fight against corruption","volume":"51","year":"2019","journal-title":"The British Accounting Review"},{"issue":"1","key":"key2025031312453597400_ref041","doi-asserted-by":"crossref","first-page":"67","DOI":"10.2307\/249410","article-title":"A set of principles for conducting and evaluating interpretive field studies in information systems","volume":"23","year":"1999","journal-title":"MIS Quarterly"},{"key":"key2025031312453597400_ref042","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1016\/j.cose.2012.07.001","article-title":"Organizational power and information security rule compliance","volume":"33","year":"2013","journal-title":"Computers and Security"},{"issue":"3","key":"key2025031312453597400_ref043","doi-asserted-by":"crossref","first-page":"33","DOI":"10.4018\/ijsodit.2013070103","article-title":"Influences of frame incongruence on information security policy outcomes: an interpretive case study","volume":"3","year":"2013","journal-title":"International Journal of Social and Organizational Dynamics in IT (IJSODIT)"},{"issue":"3","key":"key2025031312453597400_ref044","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1287\/isre.14.3.221.16560","article-title":"Generalizing generalizability in information systems research","volume":"14","year":"2003","journal-title":"Information Systems Research"},{"issue":"1","key":"key2025031312453597400_ref045","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1287\/isre.2015.0607","article-title":"Mandatory standards and organizational information security","volume":"27","year":"2016","journal-title":"Information Systems Research"},{"issue":"1","key":"key2025031312453597400_ref046","doi-asserted-by":"crossref","first-page":"147","DOI":"10.2307\/23043493","article-title":"When flexible routines meet flexible technologies: affordance, constraint, and the imbrication of human and material agencies","volume":"35","year":"2011","journal-title":"MIS Quarterly"},{"issue":"2","key":"key2025031312453597400_ref047","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1016\/j.infoandorg.2013.02.002","article-title":"Theoretical foundations for the study of sociomateriality","volume":"23","year":"2013","journal-title":"Information and Organization"},{"first-page":"1","volume-title":"GDPR Compliance in the Context of Continuous Integration","year":"2020","key":"key2025031312453597400_ref097"},{"issue":"1","key":"key2025031312453597400_ref096","first-page":"460","article-title":"Designing monitoring systems for continuous certification of cloud Services: Deriving meta-requirements and design guidelines","volume":"44","year":"2019","journal-title":"Communications of the Association for Information Systems"},{"issue":"6","key":"key2025031312453597400_ref048","doi-asserted-by":"crossref","first-page":"907","DOI":"10.1287\/orsc.1080.0398","article-title":"Perspective\u2014making doubt generative: rethinking the role of doubt in the research process","volume":"19","year":"2008","journal-title":"Organization Science"},{"issue":"6","key":"key2025031312453597400_ref049","doi-asserted-by":"crossref","first-page":"1499","DOI":"10.5465\/amj.2010.57319198","article-title":"The dangers of decoupling: the relationship between compliance programs, legitimacy perceptions, and Institutionalized misconduct","volume":"53","year":"2010","journal-title":"Academy of Management Journal"},{"issue":"2","key":"key2025031312453597400_ref050","doi-asserted-by":"publisher","DOI":"10.1145\/3466689","article-title":"Machine learning and survey-based predictors of InfoSec non-compliance","volume":"13","year":"2021","journal-title":"ACM Transactions on Management Information Systems (TMIS)"},{"issue":"3","key":"key2025031312453597400_ref051","doi-asserted-by":"crossref","first-page":"831","DOI":"10.25300\/MISQ\/2014\/38.3.09","article-title":"Dynamic reconfiguration in planetary exploration: a\u00a0sociomaterial ethnography","volume":"38","year":"2014","journal-title":"MIS Quarterly"},{"issue":"9","key":"key2025031312453597400_ref052","doi-asserted-by":"crossref","first-page":"1103","DOI":"10.1002\/smj.1957","article-title":"Using private management standard certification to reduce information asymmetries in corrupt environments","volume":"33","year":"2012","journal-title":"Strategic Management Journal"},{"issue":"1","key":"key2025031312453597400_ref053","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1016\/j.infoandorg.2013.02.001","article-title":"Sociomateriality\u2014taking the wrong turning?","volume":"23","year":"2013","journal-title":"Information and Organization"},{"issue":"23","key":"key2025031312453597400_ref054","first-page":"1","article-title":"Investigating information systems with ethnographic research","volume":"2","year":"1999","journal-title":"Communications of the Association for Information Systems"},{"volume-title":"Qualitative Research in Business and Management","year":"2009","key":"key2025031312453597400_ref055"},{"issue":"1","key":"key2025031312453597400_ref056","doi-asserted-by":"crossref","first-page":"17","DOI":"10.2307\/23043487","article-title":"A set of principles for conducting critical research in information systems","volume":"35","year":"2011","journal-title":"MIS Quarterly"},{"first-page":"1","article-title":"Entanglement of infrastructures and action: exploring the material foundations of technicians' work in smart infrastructure context","year":"2016","key":"key2025031312453597400_ref057"},{"issue":"4","key":"key2025031312453597400_ref058","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1145\/3025099.3025105","article-title":"Sociomateriality and information systems research: quantum radicals and cartesian conservatives","volume":"47","year":"2016","journal-title":"ACM SIGMIS Database: The DATABASE for Advances in Information Systems"},{"key":"key2025031312453597400_ref059","unstructured":"Niemimaa, M. and Laaksonen, A.E. (2015), \u201cMateriality, rules and regulation: new trends in management and organization studies\u201d, in de Vaujany, F.-X., Mitev, N., Lanzara, G.F. and Mukherjee, A. (Eds), Palgrave Macmillan, Hampshire, pp.\u00a0223-249."},{"issue":"1","key":"key2025031312453597400_ref060","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1057\/s41303-016-0025-y","article-title":"Information systems security policy implementation in practice: from best practices to situated practices","volume":"26","year":"2017","journal-title":"European Journal of Information Systems"},{"key":"key2025031312453597400_ref061","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1080\/0960085X.2019.1624141","article-title":"Abductive innovations in information security policy development: an ethnographic study","volume":"28","year":"2019","journal-title":"European Journal of Information Systems"},{"year":"2011","key":"key2025031312453597400_ref062","article-title":"Designing information systems security policy methods: a meta-theoretical approach"},{"issue":"6","key":"key2025031312453597400_ref063","doi-asserted-by":"crossref","first-page":"592","DOI":"10.1057\/ejis.2012.3","article-title":"Conceptualising improvisation in information systems security","volume":"21","year":"2012","journal-title":"European Journal of Information Systems"},{"issue":"4","key":"key2025031312453597400_ref064","doi-asserted-by":"crossref","first-page":"313","DOI":"10.1108\/09593840710839770","article-title":"The great legitimizer: ICT as myth and ceremony in the Indian healthcare sector","volume":"20","year":"2007","journal-title":"Information Technology and People"},{"issue":"5","key":"key2025031312453597400_ref065","doi-asserted-by":"crossref","first-page":"697","DOI":"10.1111\/joms.12114","article-title":"Exploring material-discursive practices","volume":"52","year":"2015","journal-title":"Journal of Management Studies"},{"key":"key2025031312453597400_ref066","doi-asserted-by":"publisher","DOI":"10.1016\/J.COSE.2019.101608","article-title":"State of the art in information security policy development","volume":"88","year":"2020","journal-title":"Computers and Security"},{"key":"key2025031312453597400_ref067","doi-asserted-by":"publisher","first-page":"688","DOI":"10.1016\/J.JEBO.2021.03.019","article-title":"Political beliefs affect compliance with government mandates","volume":"185","year":"2021","journal-title":"Journal of Economic Behavior and Organization"},{"issue":"5","key":"key2025031312453597400_ref068","doi-asserted-by":"publisher","first-page":"1262","DOI":"10.1108\/ITP-06-2018-0261\/FULL\/XML","article-title":"Organizational practices as antecedents of the information security management performance: an empirical investigation","volume":"32","year":"2019","journal-title":"Information Technology and People"},{"key":"key2025031312453597400_ref069","doi-asserted-by":"crossref","unstructured":"Pentland, B.T. and Singh, H. (2012), \u201cMateriality and organizing: social interaction in a technological world\u201d, in Leonardi, P.M., Nardi, B.A. and Kallinikos, J. (Eds), Materiality and Organizing: Social Interaction in a Technological World, Oxford University Press Oxford, Oxford, pp.\u00a0287-295.","DOI":"10.1093\/acprof:oso\/9780199664054.003.0014"},{"volume-title":"The Audit Explosion","year":"1994","key":"key2025031312453597400_ref070"},{"key":"key2025031312453597400_ref071","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1016\/j.cose.2015.10.006","article-title":"Information security policy compliance model in organizations","volume":"56","year":"2016","journal-title":"Computers and Security"},{"year":"2020","key":"key2025031312453597400_ref072","article-title":"Building an apparatus: disclosing affectivity in sociomaterial research"},{"journal-title":"MIT Sloan Management Review","article-title":"Three cultures of management: the key to organizational learning","year":"1996","key":"key2025031312453597400_ref073"},{"issue":"1","key":"key2025031312453597400_ref074","doi-asserted-by":"crossref","first-page":"3","DOI":"10.2307\/3250978","article-title":"A confessional account of an ethnography about knowledge work","volume":"24","year":"2000","journal-title":"MIS Quarterly"},{"issue":"2","key":"key2025031312453597400_ref075","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1016\/j.infoandorg.2013.02.003","article-title":"Sociomateriality\u2014taking the wrong turning? A response to Mutch","volume":"23","year":"2013","journal-title":"Information and Organization"},{"key":"key2025031312453597400_ref076","doi-asserted-by":"publisher","DOI":"10.1145\/3342558.3345421","article-title":"Towards automated auditing with machine learning","volume-title":"Proceedings of the ACM Symposium on Document Engineering, DocEng 2019, Association for Computing Machinery","year":"2019"},{"issue":"3","key":"key2025031312453597400_ref077","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1108\/IMCS-05-2013-0041","article-title":"Information security: critical review and future directions for research","volume":"22","year":"2014","journal-title":"Information Management and Computer Security"},{"issue":"1","key":"key2025031312453597400_ref078","doi-asserted-by":"publisher","first-page":"294","DOI":"10.17705\/1jais.00041","article-title":"The circuits-of-power framework for studying power in institutionalization of information systems","volume":"4","year":"2003","journal-title":"Journal of the Association for Information Systems"},{"issue":"8","key":"key2025031312453597400_ref079","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1145\/1145287.1145316","article-title":"Information security standards focus on the existence of process, not its content","volume":"49","year":"2006","journal-title":"Communications of the ACM"},{"first-page":"1551","article-title":"A critical assessment of IS security research between 1990-2004","year":"2007","key":"key2025031312453597400_ref080"},{"issue":"5","key":"key2025031312453597400_ref081","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1016\/j.im.2008.12.007","article-title":"Information security management standards: problems and solutions","volume":"46","year":"2009","journal-title":"Information and Management"},{"issue":"3","key":"key2025031312453597400_ref082","doi-asserted-by":"crossref","first-page":"463","DOI":"10.2307\/25750687","article-title":"Circuits of power: a study of mandated compliance to an information systems security de jure standard in a government organization","volume":"34","year":"2010","journal-title":"MIS Quarterly"},{"first-page":"4839","article-title":"Conflict resolution in an ISO\/IEC 27001 standard implementation: a contradiction management perspective","year":"2023","key":"key2025031312453597400_ref083"},{"key":"key2025031312453597400_ref084","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/0-387-31167-X_12","article-title":"A holistic risk analysis method for identifying information security risks","year":"2006"},{"issue":"2","key":"key2025031312453597400_ref085","doi-asserted-by":"publisher","first-page":"75","DOI":"10.2308\/JATA.1999.21.2.75","article-title":"Tax professionals' interpretations of ambiguity in compliance and planning decision contexts","volume":"21","year":"1999","journal-title":"Journal of the American Taxation Association"},{"key":"key2025031312453597400_ref086","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1146\/ANNUREV.SOC.012809.102629","article-title":"A world of standards but not a standard world: toward a sociology of standards and standardization*","volume":"36","year":"2010","journal-title":"Annual Review of Sociology"},{"issue":"3","key":"key2025031312453597400_ref087","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1177\/0735275112457914","article-title":"Theory construction in qualitative research from grounded theory to abductive analysis","volume":"30","year":"2012","journal-title":"Sociological Theory"},{"issue":"4","key":"key2025031312453597400_ref088","doi-asserted-by":"crossref","first-page":"337","DOI":"10.1016\/S0167-4048(03)00413-9","article-title":"An integral framework for information systems security management","volume":"22","year":"2003","journal-title":"Computers and Security"},{"issue":"1","key":"key2025031312453597400_ref089","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1108\/17465640610666615","article-title":"Ethnography then and now","volume":"1","year":"2006","journal-title":"Qualitative Research in Organizations and Management: An International Journal"},{"edition":"2nd ed.","volume-title":"Tales of the Field: On Writing Ethnography","year":"2011","key":"key2025031312453597400_ref090"},{"issue":"1","key":"key2025031312453597400_ref091","doi-asserted-by":"crossref","first-page":"218","DOI":"10.1111\/j.1467-6486.2010.00980.x","article-title":"Ethnography as work: some rules of engagement","volume":"48","year":"2011","journal-title":"Journal of Management Studies"},{"issue":"3","key":"key2025031312453597400_ref092","doi-asserted-by":"crossref","first-page":"191","DOI":"10.1016\/j.cose.2004.01.012","article-title":"Towards information security behavioural compliance","volume":"23","year":"2004","journal-title":"Computers and Security"},{"issue":"1","key":"key2025031312453597400_ref093","doi-asserted-by":"publisher","first-page":"4","DOI":"10.17705\/1jais.00420","article-title":"Organizational violations of externally governed privacy and security rules: explaining and predicting selective violations under conditions of strain and excess","volume":"17","year":"2016","journal-title":"Journal of the Association for Information Systems"},{"issue":"5","key":"key2025031312453597400_ref094","doi-asserted-by":"crossref","first-page":"539","DOI":"10.2307\/256975","article-title":"Integrated and decoupled corporate social performance: management commitments, external pressures, and corporate ethics practices","volume":"42","year":"1999","journal-title":"Academy of Management Journal"},{"volume-title":"In the Age of the Smart Machine: The Future of Work and Power","year":"1988","key":"key2025031312453597400_ref095"}],"container-title":["Information Technology &amp; People"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-03-2022-0156\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/ITP-03-2022-0156\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:54:30Z","timestamp":1753394070000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/itp\/article\/38\/2\/604-625\/1240335"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,7]]},"references-count":97,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2023,11,7]]},"published-print":{"date-parts":[[2025,3,14]]}},"alternative-id":["10.1108\/ITP-03-2022-0156"],"URL":"https:\/\/doi.org\/10.1108\/itp-03-2022-0156","relation":{},"ISSN":["0959-3845"],"issn-type":[{"type":"print","value":"0959-3845"}],"subject":[],"published":{"date-parts":[[2023,11,7]]}}}