Organizational Learning for the Incident Management Process: Lessons from High Reliability Organizations



Full text

Journal of Information System Security
Volume 4, Number 3 (2008)
Pages 323
ISSN 1551-0123
Gerd Van Den Eede — Tilburg University, Belgium
Willem J. Muhren — Tilburg University, Belgium
Bartel Van de Walle — Tilburg University, Belgium
Information Institute Publishing, Washington DC, USA




Organizations typically struggle in their quest to combine effectiveness and efficiency. Experimentation and trial-and-error are regarded as important processes for organizational learning, but do not always lead to an organizational-wide optimum in terms of efficiency. Certain organizations, socalled High Reliability Organizations (HROs), exist that operate in hazardous environments but manage to structure themselves to be efficient and stay highly reliable. These organizations in high-tension industries are deprived from the luxury of going through trial-and-error learning, but we state that exactly this is accountable for the HROs' success. More particularly, the way system components are coupled accounts to a great extent for the explanation of HRO's reliability. Through a case study of the IT Incident Management process at a large European financial services provider, we investigate how people involved in a process of such a mainstream organization, where reliability is of great concern, can learn from HROs to achieve a greater reliability while working efficiently. It appears that the characteristics that make an HRO distinct from other organizations are - at least to some extent - present in the IT Incident Management process. Our main conclusion however is that considerable opportunities remain unseized to lift the HRO qualities to a still higher level.




Incident Management Process, Organizational Learning, Loose Coupling, High Reliability Organizations




