Technoethics and Organizing: Exploring Ethical Hacking within a Canadian University

Ethical hacking is one important information security risk management strategy business and academic organizations use to protect their information assets from the growing threat of hackers. Most published books on ethical hacking have focused on its technical applications in risk assessment practic...

Full description

Bibliographic Details
Main Author: Abu-Shaqra, Baha
Other Authors: Luppicini, Rocci
Language:en
Published: Université d'Ottawa / University of Ottawa 2015
Subjects:
Online Access:http://hdl.handle.net/10393/32266
http://dx.doi.org/10.20381/ruor-3920
Description
Summary:Ethical hacking is one important information security risk management strategy business and academic organizations use to protect their information assets from the growing threat of hackers. Most published books on ethical hacking have focused on its technical applications in risk assessment practices. This thesis addressed a gap within the organizational communication literature on ethical hacking. Taking a qualitative exploratory case study approach, the thesis paired technoethical inquiry theory with Karl Weick’s sensemaking model to explore ethical hacking in a Canadian university. In-depth interviews with key stakeholder groups and a document review were conducted. Guided by the Technoethical Inquiry Decision-making Grid (TEI-DMG), a qualitative framework for use in technological assessment, findings pointed to the need to expand the communicative and social considerations involved in decision making about ethical hacking practices. Guided by Weick’s theory, findings pointed to security awareness training for increasing sensemaking opportunities and reducing equivocality in the information environment.