Darmaningrat, Eko Wahyu Tyas
ORCID: 0000-0001-9272-0029
(2025)
Information Security Policy Implementation in Surabaya, Indonesia: A Mixed-Methods Approach to a Multi-Stakeholder Urban Context.
PhD thesis, University of Sheffield.
Abstract
The absence of a national standard for developing Information Security Policies (ISPs) in Indonesia creates challenges for achieving compliance in interconnected urban digital environments. While ISPs have traditionally been organisational instruments, their development in cities involves multiple stakeholders with differing responsibilities, capacities, and interpretations of compliance. This study examines how ISP compliance is achieved, coordinated, and sustained across organisational boundaries in Surabaya, Indonesia, involving government bodies, market providers, IT consultants, and citizens, using Cram et al.’s (2017) organisational ISP framework as a theoretical lens. An exploratory sequential mixed-methods design was adopted. The study began with 40 semi-structured interviews across the four stakeholder groups. Thematic analysis identified key themes that informed the design of a structured survey, which was completed by 233 respondents to test these themes across a broader sample from the same population. Qualitative findings show that formal standards and bureaucratic control shape ISP development, but stakeholders interpret these constructs differently. Governments are driven by regulatory mandates, market providers by operational continuity and customer trust, IT consultants by technical interpretation and advisory roles, and citizens by transparency and involvement. Although stakeholders share concerns about awareness and enforcement, their motivations differ, indicating that Cram’s constructs carry distinct nuances across stakeholder positions. Coordination is predominantly government-led, with local authorities setting regulatory baselines that other stakeholders operationalise or respond to. These findings inform an extension of Cram’s framework across three cross-boundary dimensions: differentiated communication processes, government-led coordination mechanisms that distribute responsibility, and extended feedback loops that sustain adaptive compliance. Quantitative results confirm broad agreement on ISP principles but reveal gaps between government and non-government groups. This study contributes to the information management body of knowledge by demonstrating how the organisational ISP framework applies to a multi-stakeholder urban context. In practice, the study offers guidance on strengthening coordination, communication, and feedback processes in this context.
Metadata
| Supervisors: | Foster, Jonathan and Israilidis, John |
|---|---|
| Related URLs: | |
| Keywords: | information security policy (ISP), compliance, multi-stakeholder context, governance, mixed-methods, exploratory-sequential mixed methods |
| Awarding institution: | University of Sheffield |
| Academic Units: | The University of Sheffield > Faculty of Social Sciences (Sheffield) > Information School (Sheffield) |
| Date Deposited: | 02 Sep 2026 14:00 |
| Last Modified: | 02 Sep 2026 14:00 |
| Open Archives Initiative ID (OAI ID): | oai:etheses.whiterose.ac.uk:39330 |
Download
Final eThesis - complete (pdf)
Please use the button below to request a copy.
Filename: 210129982 Thesis Tyas_White Rose.pdf
Export
Statistics
Please use the 'Request a copy' link(s) in the 'Downloads' section above to request this thesis. This will be sent directly to someone who may authorise access.
You can contact us about this thesis. If you need to make a general enquiry, please see the Contact us page.