ABSTRACT

Sundt (2006) and Lobree (2002) claim that laws and regulations affect the implementation of information security in organizations. There is, however, limited information publicly available about how compliance to information security laws is currently dealt with.