arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.35887cs.CRcs.CY

安全领导中的双重契合要求:现代组织中CISO角色履行的扎根理论研究

Dual-Fit Imperative in Security Leadership: A Grounded Theory Investigation of CISO Role Enactment in Modern Organisations

Mazino Benson Onibere

首次发表
浏览论文内容

中文总结 AI 辅助

本研究通过扎根理论访谈澳大利亚安全高管,提出CISO角色有效性源于领导者与内外环境的双重契合,并构建安全领导权变模型(SLCM)以指导领导选拔与继任规划。

中文摘要 AI 辅助

首席信息安全官(CISO)已成为一个具有战略重要性的高管职位,其面临敌对的环境、安全与业务赋能之间不可调和的问责张力,以及一种预防悖论——在这种悖论中,成功对资源分配者而言是不可见的。学术界对CISO角色在不同组织情境中如何运作的理解几乎缺失,使得实践缺乏实证基础。本论文提出的研究问题是:在现代组织中,CISO角色在不同组织情境下是如何履行的?本研究采用建构主义扎根理论,结合溯因推理框架和Gioia方法,基于对二十位澳大利亚安全高管的访谈。CISO角色并非一套统一适用的稳定职责配置,而是一个持续协商的成就。有效性源于双重契合的维持:领导者与内部组织情境之间的契合(CISO-组织契合)以及领导者与外部环境之间的契合(CISO-环境契合)。这些要求随着三个成熟阶段——建立阶段、成熟阶段和战略阶段——而转变,分别由行动导向、管理导向和愿景导向的领导者产生有效性;在一个阶段的有效性可能在另一个阶段削弱有效性。政治资本是领导者应对这些不断变化要求的机制。这些模式被综合为安全领导权变模型(SLCM),这是本论文的主要理论贡献。基于该模型开发的工具将这些见解转化为领导力选拔和继任规划的指导。SLCM将个人-组织契合、个人-环境契合和权变理论扩展到安全领导领域,推进了对问责张力下和不断变化的情境要求中高管有效性的理解。

英文摘要

The Chief Information Security Officer (CISO) has emerged as a strategically prominent executive role, confronting an adversarial environment, irreconcilable accountability tensions between security and business enablement, and a prevention paradox in which success remains invisible to resource allocators. Scholarly understanding of how the role operates across organisational contexts remains virtually absent, leaving practice without empirical foundation. This thesis asks: how is the CISO role enacted across different organisational contexts in modern organisations? The study employs constructivist grounded theory with an abductive reasoning framework and the Gioia method, drawing on twenty interviews with Australian security executives. The CISO role is not a stable configuration of responsibilities applied uniformly, but a continuously negotiated achievement. Effectiveness emerges from dual-fit maintenance: alignment between the leader and the internal organisational context (CISO-Organisation Fit) and the external environment (CISO-Environment Fit). These requirements transform across three maturity phases, Establishment, Maturation, and Strategic, with action-oriented, stewardship-oriented, and vision-oriented leaders generating effectiveness in each; effectiveness in one phase can undermine it in another. Political capital is the mechanism through which leaders navigate these shifting demands. These patterns are synthesised in the Security Leadership Contingency Model (SLCM), the thesis's primary theoretical contribution. Instruments developed from the model translate these insights into guidance for leadership selection and succession planning. The SLCM extends person-organisation fit, person-environment fit, and contingency theory to security leadership, advancing understanding of executive effectiveness under accountability tensions and evolving contextual demands.

发表机构

  • The University of Melbourne(墨尔本大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑