| The Industrial Internet has introduced information technology into the industrial economy,and has gradually become an important infrastructure for industrial enterprises to promote the digital and intelligent transformation.Industrial Internet includes network,platform,data,security and other elements,involving the country,industry,platform and enterprise multilevel subject.Industrial Internet is promoting enterprises from closed information to open and coordinated development,the application of industrial Internet for enterprise energy saving,optimization and efficiency at the same time,but also brought potential information security risks.Hacking,extortion virus and other security problems emerge in endlessly,brought serious losses to many enterprises,industrial Internet security penetration into all the links of enterprise production process,such as data acquisition,transmission,storage,analysis,so once the security threats,not only will endanger the enterprise itself will even affect the social stability.Different from traditional enterprise information security,industrial Internet enterprises present the characteristics of technology specialization,equipment customization and so on,with higher requirements for information security,so how industrial Internet enterprises should build information security capabilities to ensure information security has become a realistic issue to be solved in the industry.The current research on the influencing factors of information security management is mainly concentrated in many aspects such as technology,behavioral management,and security investment.The lack of unified framework guidance of enterprise information management security work is efficient and orderly.Therefore,this study proposes the following three research issues based on IT capabilities:(1)how to build an enterprise’s information security capabilities;(2)What are the key factors that affect the information security capacity of the enterprise;(3)whether the information security capacity can effectively improve Enterprise information security management performance.Study intends to guide enterprises’ information security management through the construction of information security capabilities.In research on IT capabilities,many scholars build IT capabilities into a multidimensional constructing readings from various aspects such as technology,personnel,management,and resources,and confirmed the positive impact of IT capabilities on the business performance of the enterprise,but ignored Construction of the ability of security.Information security ability is proposed on the basis of IT capabilities.Based on the four stages of the closed-loop theory of Security Action,this article divides information security ability into four dimensions: deterrent ability,prevention ability,detection ability,and repair ability,and introduced the key influencing factors of information security capabilities,as well as information security of information security capabilities,as well as information security of information security capabilities,as well as information security of information security capabilities,as well as information security of information security capabilities,as well as information security of information security capabilities,as well as information security of information security capabilities,as well as information security of information security capabilities.The influence mechanism of ability on information security management performance.The results of the study show that(1)Significant path coefficients of deterrence,prevention capabilities,and detection capabilities,and the repair ability has not been verified as one of the dimensions of information security capabilities.Therefore,information security capabilities are finally divided into three dimensions: deterrence,prevention and detection.(2)Significant business consistency,technology-goal consistency,and the system environment significantly affect information security capabilities.The improvement of corporate information security capabilities will improve corporate information security management performance.The theoretical contribution of this article is to build a framework of information security capabilities from four aspects: deterrence,prevention,detection,and repair,enrich the connotation of information technology capabilities,expand the research on information security capabilities,and use empirical research to observe the organization from organizations.The three aspects of technology and the environment have explored the key influencing elements of information security capabilities,and verified the positive impact of information security capabilities on the performance of enterprise information security management.In practice,research can guide enterprises to build their own information security capabilities.Based on information security capabilities frameworks to help enterprises clarify countermeasures when facing problems at various stages,to achieve lower-cost and high efficiency information security defense paths,enhance corporate information safety management performance. |