What do we know about information security governance? "From the basement to the boardroom": towards digital security governance

被引:20
|
作者
Schinagl, Stef [1 ]
Shahim, Abbas [1 ]
机构
[1] Vrije Univ Amsterdam, Sch Business & Econ, Amsterdam, Netherlands
关键词
Technology; Information security governance; Literature review; Digitalisation; Cyber; Digital security governance; MANAGEMENT; FRAMEWORK; RISK; ORGANIZATIONS; MODEL; STRATEGY; CULTURE; PRIVACY;
D O I
10.1108/ICS-02-2019-0033
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Purpose This paper aims to review the information security governance (ISG) literature and emphasises the tensions that exist at the intersection of the rapidly changing business climate and the current body of knowledge on ISG. Design/methodology/approach The intention of the authors was to conduct a systematic literature review. However, owing to limited empirical papers in ISG research, this paper is more conceptually organised. Findings This paper shows that security has shifted from a narrow-focused isolated issue towards a strategic business issue with "from the basement to the boardroom" implications. The key takeaway is that protecting the organisation is important, but organizations must also develop strategies to ensure resilient businesses to take advantage of the opportunities that digitalization can bring. Social implications This paper helps individuals to understand that they have increasing rights with regard to privacy and security and a say in what parties they assign business to. Originality/value This paper makes a novel contribution to ISG research. To the authors' knowledge, this is the first attempt to review and structure the ISG literature.
引用
收藏
页码:261 / 292
页数:32
相关论文
共 50 条
  • [1] Governance: What Do We Know, and How Do We Know It?
    Fukuyama, Francis
    [J]. ANNUAL REVIEW OF POLITICAL SCIENCE, VOL 19, 2016, 19 : 89 - 105
  • [2] WHAT DO WE KNOW ABOUT DIFFERENT SYSTEMS OF CORPORATE GOVERNANCE?
    Goergen, Marc
    [J]. JOURNAL OF CORPORATE LAW STUDIES, 2007, 7 (01) : 1 - 15
  • [3] Towards a Framework for Strategic Security Context in Information Security Governance
    Maynard, Sean B.
    Tan, Terrence
    Ahmad, Atif
    Ruighaver, Tobias
    [J]. PACIFIC ASIA JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2018, 10 (04): : 65 - 88
  • [4] Digital Security Governance and Risk Anticipation: What About the Role of Security Officials in Privacy Protection?
    Eijkman, Quirine
    [J]. INTERNATIONAL POLITICAL SOCIOLOGY, 2014, 8 (01) : 116 - 118
  • [5] What do we know about what is going on inside the boardroom?
    Francoeur, Claude
    Aube, Caroline
    Sponem, Samuel
    Farzaneh, Faranak
    [J]. TEAM PERFORMANCE MANAGEMENT, 2018, 24 (5-6) : 250 - 264
  • [6] What do we need to know about global food security?
    Cassman, Kenneth G.
    [J]. GLOBAL FOOD SECURITY-AGRICULTURE POLICY ECONOMICS AND ENVIRONMENT, 2012, 1 (02): : 81 - 82
  • [7] WHAT DO WE REALLY KNOW ABOUT WHAT WE KNOW? THE NATURE OF RELATIONSHIP GOVERNANCE IN THE REVERSE SUPPLY CHAIN
    Frankel, Robert
    Mollenkopf, Diane A.
    Russo, Ivan
    Coleman, B. Jay
    Dapiran, G. Peter
    [J]. LOOKING FORWARD, LOOKING BACK: DRAWING ON THE PAST TO SHAPE THE FUTURE OF MARKETING, 2016, : 96 - 99
  • [8] What we talk about when we talk about cybersecurity: security in internet governance debates
    Wolff, Josephine
    [J]. INTERNET POLICY REVIEW, 2016, 5 (03):
  • [9] What do we know about consumers' ontological security in disaster scenarios?
    Fawaz, Rayan S.
    Okazaki, Shintaro
    Bourliataux-Lajoinie, Stephane
    Roessner, Anna
    [J]. INTERNATIONAL JOURNAL OF CONSUMER STUDIES, 2023, 47 (04) : 1483 - 1499
  • [10] Towards a holistic Information Security Governance Framework for SOA
    Coetzee, Marijke
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 155 - 160