Information security management needs more holistic approach: A literature review

被引:233
|
作者
Soomro, Zahoor Ahmed [1 ]
Shah, Mahmood Hussain [1 ]
Ahmed, Javed [1 ]
机构
[1] Univ Cent Lancashire, Lancashire Business Sch, Preston PR1 2HE, Lancs, England
关键词
Information security; Management; Information security policy; Managerial practices; Business information architecture; Business IT alignment; Cloud computing; Systematic; Information architecture; ENTERPRISE ARCHITECTURE; STRATEGIC ALIGNMENT; SYSTEMS SECURITY; BUSINESS; TECHNOLOGY; RISK; PERSPECTIVE; AWARENESS; POLICIES; ISSUES;
D O I
10.1016/j.ijinfomgt.2015.11.009
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information technology has dramatically increased online business opportunities; however these opportunities have also created serious risks in relation to information security. Previously, information security issues were studied in a technological context, but growing security needs have extended researchers' attention to explore the management role in information security management. Various studies have explored different management roles and activities, but none has given a comprehensive picture of these roles and activities to manage information security effectively. So it is necessary to accumulate knowledge about various managerial roles and activities from literature to enable managers to adopt these for a more holistic approach to information security management. In this paper, using a systematic literature review approach, we synthesised literature related to management's roles in information security to explore specific managerial activities to enhance information security management. We found that numerous activities of management, particularly development and execution of information security policy, awareness, compliance training, development of effective enterprise information architecture, IT infrastructure management, business and IT alignment and human resources management, had a significant impact on the quality of management of information security. Thus, this research makes a novel contribution by arguing that a more holistic approach to information security is needed and we suggest the ways in which managers can play an effective role in information security. This research also opens up many new avenues for further research in this area. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:215 / 225
页数:11
相关论文
共 50 条
  • [2] A HOLISTIC APPROACH TO THE MANAGEMENT OF INFORMATION
    VICKERS, P
    ASLIB PROCEEDINGS, 1985, 37 (01): : 19 - 30
  • [3] Holistic Information Security Management and Compliance Framework
    Grigaliunas, Sarunas
    Schmidt, Michael
    Bruzgiene, Rasa
    Smyrli, Panayiota
    Andreou, Stephanos
    Lopata, Audrius
    ELECTRONICS, 2024, 13 (19)
  • [4] Holistic Approach for Governing Information System Security
    Spremic, Mario
    WORLD CONGRESS ON ENGINEERING - WCE 2013, VOL II, 2013, : 1242 - 1247
  • [5] Security Management in Health Care Information Systems A literature review
    Smaradottir, Berglind Fjola
    PROCEEDINGS 2017 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI), 2017, : 1742 - 1746
  • [6] Toward an Integrated Approach to Information Management: A Literature Review
    Chatzipanagiotou, Niki
    STRATEGIC INNOVATIVE MARKETING, 2017, : 667 - 673
  • [7] Towards a holistic approach to sustainable risk management in agriculture in the EU: a literature review
    Arata, Linda
    Cerroni, Simone
    Santeramo, Fabio Gaetano
    Trestini, Samuele
    Severini, Simone
    BIO-BASED AND APPLIED ECONOMICS, 2023, 12 (03): : 165 - 182
  • [8] The hunt for computerized support in information security policy management A literature review
    Rostami, Elham
    Karlsson, Fredrik
    Kolkowska, Ella
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (02) : 215 - 259
  • [9] A holistic approach to information management: Theory and practice
    Manwani, Sharm
    Fishwick, Mike
    Rankin, Gerry
    ECMLG 2007: PROCEEDINGS OF THE 3RD EUROPEAN CONFERENCE ON MANAGEMENT, LEADERSHIP AND GOVERNANCE, 2007, : 157 - 166
  • [10] Information Security Risk Management by a Holistic Approach: a Case Study for Vietnamese e-Government
    Ha Le Viet
    On Phung Van
    Hoa Nguyen Ngoc
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2020, 20 (06): : 72 - 82