Document Type
Article
Publication Date
6-2024
Version
Post-print
Abstract
Drawing inspiration from bureaucracy and information security literature, we develop the theory of security bureaucracy—an evolutionary framework that describes how organizations arrive at their information-securing approaches. Within this framework, we describe three general bureaucratic archetypes (i.e., Security Prototype, Security Structure, and Security Superstructure) that emerge from the interplay between control and expertise. We also expound on the phenomenon of security bureaucracy and delineate how organizations can transition from coercive “iron cages” to enabling “iron shields” in information securing. We also use our security establish-enforce-enculturate (3E) evolutionary framework to inform a proposed variance model of security bureaucracy. Our efforts offer significant insights and implications for organizational information security research and practice.
Journal Name
Information and Organization
Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.
Recommended Citation
Li, Y., Posey, C., & Stafford, T. (2024). Bureaucracies in information securing: Transitioning from iron cages to iron shields. Information and Organization, 34(3), 100526. (post-print)
Comments
This is a post-print. The final published version is available at https://10.1016/j.infoandorg.2024.100526