Logo: to the web site of the Swedish Defence University

fhs.se
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • harvard-cite-them-right
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Från störning till standard: IT-incidenter och normförändring: En diskursanalys om konstitutiva och regulativa normer inom svensk informationssäkerhet efter Transportstyrelsens IT-skandal och 1177-läckan
Swedish Defence University.
2025 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Digital vulnerabilities pose a major threat to keeping information secure in modern societies, yet the understanding of norms regarding information security and how they are affected by major incidents remains fairly unexplored. This thesis examines how constitutive norms and regulative norms, within the field of information security, have changed following major IT-related incidents. The thesis covers two incidents, the Swedish Transport Agency’s IT-scandal 2017 and the 1177’s data leak 2019 and aims to contribute to the under-examined field of norms in information security. Using discourse analysis, the study seeks to uncover empirical examples to identify how constitutive norms and regulative norms emerge, spread and are internalised post major Swedish IT-incidents. Utilising a constructivist approach and Sikkink & Finnemore’s norm life cycle theory, the thesis tracks the emergence and spread of norms through the discourse following the incidents. The study shows that regulative norms, such as stricter security analysis and mandatory background checks, have emerged and been strengthened in the aftermath of the incidents. The findings also suggest that it is uncertain whether long term internalisation of regulative norms on a national level has been successfully achieved or if such norms require continuous reinforcement in order to maintain effectiveness. Furthermore, this thesis finds a shift in constitutive norms where public organisations are placing more focus on security rather than cost-efficiency. These findings highlight the importance of both strengthening regulative norms and fostering a deeper cultural shift in constitutive norms to ensure sustainable improvements in information security practices within public organisations.

Place, publisher, year, edition, pages
2025. , p. 43
Keywords [sv]
Informationssäkerhet, regulativa normer, konstitutiva normer, diskursanalys, Transportstyrelsen och 1177-vårdguiden
National Category
Political Science (excluding Public Administration Studies and Globalisation Studies)
Identifiers
URN: urn:nbn:se:fhs:diva-13443OAI: oai:DiVA.org:fhs-13443DiVA, id: diva2:1931822
Subject / course
Political Science with a focus on Crisis Management and Security
Educational program
Swedish Defence University’s Bachelor Program
Uppsok
Social and Behavioural Science, Law
Supervisors
Examiners
Available from: 2025-01-28 Created: 2025-01-27 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Swedish Defence University
Political Science (excluding Public Administration Studies and Globalisation Studies)

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 155 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • harvard-cite-them-right
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf