Information security management needs more holistic approach: A literature review

被引:233
|
作者
Soomro, Zahoor Ahmed [1 ]
Shah, Mahmood Hussain [1 ]
Ahmed, Javed [1 ]
机构
[1] Univ Cent Lancashire, Lancashire Business Sch, Preston PR1 2HE, Lancs, England
关键词
Information security; Management; Information security policy; Managerial practices; Business information architecture; Business IT alignment; Cloud computing; Systematic; Information architecture; ENTERPRISE ARCHITECTURE; STRATEGIC ALIGNMENT; SYSTEMS SECURITY; BUSINESS; TECHNOLOGY; RISK; PERSPECTIVE; AWARENESS; POLICIES; ISSUES;
D O I
10.1016/j.ijinfomgt.2015.11.009
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information technology has dramatically increased online business opportunities; however these opportunities have also created serious risks in relation to information security. Previously, information security issues were studied in a technological context, but growing security needs have extended researchers' attention to explore the management role in information security management. Various studies have explored different management roles and activities, but none has given a comprehensive picture of these roles and activities to manage information security effectively. So it is necessary to accumulate knowledge about various managerial roles and activities from literature to enable managers to adopt these for a more holistic approach to information security management. In this paper, using a systematic literature review approach, we synthesised literature related to management's roles in information security to explore specific managerial activities to enhance information security management. We found that numerous activities of management, particularly development and execution of information security policy, awareness, compliance training, development of effective enterprise information architecture, IT infrastructure management, business and IT alignment and human resources management, had a significant impact on the quality of management of information security. Thus, this research makes a novel contribution by arguing that a more holistic approach to information security is needed and we suggest the ways in which managers can play an effective role in information security. This research also opens up many new avenues for further research in this area. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:215 / 225
页数:11
相关论文
共 50 条
  • [21] A holistic literature review on entrepreneurial Intention: A scientometric approach
    Batista-Canino, Rosa M.
    Santana-Hernandez, Lidia
    Medina-Brito, Pino
    JOURNAL OF BUSINESS RESEARCH, 2024, 174
  • [22] The Evaluation of Management Information Systems: A Dynamic and Holistic Approach
    Farbey, Barbara
    EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 1994, 3 (03) : 240 - 241
  • [23] Information security management - A practical approach
    Dey, Manik
    2007 AFRICON, VOLS 1-3, 2007, : 587 - 592
  • [24] Information Technology as the Enabler for Organizational Agility and the Needs of Information Security Management
    Zaini, Muhamad Khairulnizam
    Masrek, Mohamad Noorman
    Sani, Mad Khir Johari Abdullah
    SUSTAINABLE ECONOMIC GROWTH, EDUCATION EXCELLENCE, AND INNOVATION MANAGEMENT THROUGH VISION 2020, VOLS I-VII, 2017, : 2255 - 2267
  • [25] An Ontological Approach to Information Security Management
    Pereira, Teresa
    Santos, Henrique
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2012, : 368 - 375
  • [26] A PROCESS APPROACH TO INFORMATION SECURITY MANAGEMENT
    VONSOLMS, R
    VONSOLMS, SH
    CARROLL, JM
    COMPUTER SECURITY, 1993, 37 : 385 - 399
  • [27] Information security management: A bibliographic review
    Cardenas-Solano, Leidy-Johanna
    Martinez-Ardila, Hugo
    Becerra-Ardila, Luis-Eduardo
    PROFESIONAL DE LA INFORMACION, 2016, 25 (06): : 931 - 948
  • [28] A HOLISTIC LITERATURE REVIEW OF BUILDING INFORMATION MODELING FOR PREFABRICATED CONSTRUCTION
    Zhang, Shengxi
    Li, Zhongfu
    Li, Tianxin
    Yuan, Mengqi
    JOURNAL OF CIVIL ENGINEERING AND MANAGEMENT, 2021, 27 (07) : 485 - 499
  • [29] Building information modeling (BIM) for facilities management-literature review and future needs
    Yalcinkaya, Mehmet
    Singh, Vishal
    IFIP Advances in Information and Communication Technology, 2014, 442 : 1 - 10
  • [30] A Systematic Literature Review: Information Security Culture
    Mahfuth, Amjad
    Yussof, Salman
    Abu Baker, Asmidar
    Ali, Nor'ashikin
    2017 5TH INTERNATIONAL CONFERENCE ON RESEARCH AND INNOVATION IN INFORMATION SYSTEMS (ICRIIS 2017): SOCIAL TRANSFORMATION THROUGH DATA SCIENCE, 2017,