Paper Type
Complete
Paper Number
PACIS2026-2102
Description
An organization can receive prefectural commendation and pass ISO/IEC 27001 certification while its own officers report that colleagues 'treat ISO as a project, they engage when there is an audit and return to previous rhythms once it ends.' This paper asks why. Using a qualitative multiple-case study of three Taiwanese administrative legal entities implementing ISO/IEC 27001 under equivalent regulatory mandates, we advance four arguments: (1) institutional pressures function as activation conditions but do not determine governance depth; (2) resource capabilities modulate institutional absorption through three distinct mechanisms, threshold, transmission, and substitution modulation, each producing a characteristic governance trajectory; (3) temporal resources occupy a prerequisite position, demanding VRIN restructuring from horizontal to vertical dependency logic; and (4) governance maturity is a socially constituted judgment whose criteria differ systematically across organizational roles, generating governance intelligence failures. The study contributes a resource modulation typology, a multi-criteria maturity construct, and a three-pathway governance diagnostic.
Recommended Citation
Tseng, Hsiao-Ting; XU, SI-HUA; and Lo, Chia-Lun, "Compliance Without Governance: Institutional Pressures, Resource Modulation Mechanisms, and the Social Construction of ISO/IEC 27001 Maturity in Semi-Public Organizations" (2026). PACIS 2026 Proceedings. 15.
https://aisel.aisnet.org/pacis2026/dig_sec/dig_sec/15
Compliance Without Governance: Institutional Pressures, Resource Modulation Mechanisms, and the Social Construction of ISO/IEC 27001 Maturity in Semi-Public Organizations
An organization can receive prefectural commendation and pass ISO/IEC 27001 certification while its own officers report that colleagues 'treat ISO as a project, they engage when there is an audit and return to previous rhythms once it ends.' This paper asks why. Using a qualitative multiple-case study of three Taiwanese administrative legal entities implementing ISO/IEC 27001 under equivalent regulatory mandates, we advance four arguments: (1) institutional pressures function as activation conditions but do not determine governance depth; (2) resource capabilities modulate institutional absorption through three distinct mechanisms, threshold, transmission, and substitution modulation, each producing a characteristic governance trajectory; (3) temporal resources occupy a prerequisite position, demanding VRIN restructuring from horizontal to vertical dependency logic; and (4) governance maturity is a socially constituted judgment whose criteria differ systematically across organizational roles, generating governance intelligence failures. The study contributes a resource modulation typology, a multi-criteria maturity construct, and a three-pathway governance diagnostic.
Comments
08-Security