Paper Type

ERF

Abstract

Organizations continue to suffer personally identifiable information (PII) breaches despite heavy investment in security technology and compliance programs. Research on PII protection remains fragmented across technical safeguards, threat taxonomies, and privacy governance, leaving a limited understanding of how organizations integrate these elements into sustained protection capabilities. Grounded in the dynamic capabilities framework, this study develops and will empirically test an integrative moderated-mediation model in which Safeguard Portfolio Sophistication mediates the relationship between PII Threat Taxonomy Use and PII Protection Capability, and Governance and Security-Privacy Climate moderates both the first-stage and second-stage paths. The model maps sensing, seizing, and transforming onto the core dimensions of dynamic capabilities. Hypotheses will be tested using partial least squares structural equation modeling on a cross-sectional survey of senior security and privacy managers. Procedural and statistical remedies for common method bias, as well as planned robustness checks, are fully specified.

Paper Number

1451

Comments

SIG SEC

Share

COinS
 
Aug 15th, 12:00 AM

Building Organizational Capabilities for PII Protection: A Dynamic Capabilities on Threat Taxonomies and Safeguard Portfolios

Organizations continue to suffer personally identifiable information (PII) breaches despite heavy investment in security technology and compliance programs. Research on PII protection remains fragmented across technical safeguards, threat taxonomies, and privacy governance, leaving a limited understanding of how organizations integrate these elements into sustained protection capabilities. Grounded in the dynamic capabilities framework, this study develops and will empirically test an integrative moderated-mediation model in which Safeguard Portfolio Sophistication mediates the relationship between PII Threat Taxonomy Use and PII Protection Capability, and Governance and Security-Privacy Climate moderates both the first-stage and second-stage paths. The model maps sensing, seizing, and transforming onto the core dimensions of dynamic capabilities. Hypotheses will be tested using partial least squares structural equation modeling on a cross-sectional survey of senior security and privacy managers. Procedural and statistical remedies for common method bias, as well as planned robustness checks, are fully specified.

When commenting on articles, please be friendly, welcoming, respectful and abide by the AIS eLibrary Discussion Thread Code of Conduct posted here.