Information security management needs more holistic approach: A literature review

被引:233
|
作者
Soomro, Zahoor Ahmed [1 ]
Shah, Mahmood Hussain [1 ]
Ahmed, Javed [1 ]
机构
[1] Univ Cent Lancashire, Lancashire Business Sch, Preston PR1 2HE, Lancs, England
关键词
Information security; Management; Information security policy; Managerial practices; Business information architecture; Business IT alignment; Cloud computing; Systematic; Information architecture; ENTERPRISE ARCHITECTURE; STRATEGIC ALIGNMENT; SYSTEMS SECURITY; BUSINESS; TECHNOLOGY; RISK; PERSPECTIVE; AWARENESS; POLICIES; ISSUES;
D O I
10.1016/j.ijinfomgt.2015.11.009
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information technology has dramatically increased online business opportunities; however these opportunities have also created serious risks in relation to information security. Previously, information security issues were studied in a technological context, but growing security needs have extended researchers' attention to explore the management role in information security management. Various studies have explored different management roles and activities, but none has given a comprehensive picture of these roles and activities to manage information security effectively. So it is necessary to accumulate knowledge about various managerial roles and activities from literature to enable managers to adopt these for a more holistic approach to information security management. In this paper, using a systematic literature review approach, we synthesised literature related to management's roles in information security to explore specific managerial activities to enhance information security management. We found that numerous activities of management, particularly development and execution of information security policy, awareness, compliance training, development of effective enterprise information architecture, IT infrastructure management, business and IT alignment and human resources management, had a significant impact on the quality of management of information security. Thus, this research makes a novel contribution by arguing that a more holistic approach to information security is needed and we suggest the ways in which managers can play an effective role in information security. This research also opens up many new avenues for further research in this area. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:215 / 225
页数:11
相关论文
共 50 条
  • [31] Information Security Culture: A Definition and A Literature Review
    AlHogail, Areej
    Mirza, Abdulrahman
    2014 WORLD CONGRESS ON COMPUTER APPLICATIONS AND INFORMATION SYSTEMS (WCCAIS), 2014,
  • [32] A Systematic Literature Review of Information Security in Chatbots
    Yang, Jing
    Chen, Yen-Lin
    Por, Lip Yee
    Ku, Chin Soon
    APPLIED SCIENCES-BASEL, 2023, 13 (11):
  • [33] Reply to Swinging the pendulum in prehospital trauma mortality needs a more holistic approach
    Yamamoto, Ryo
    Suzuki, Masaru
    Sasaki, Junichi
    JOURNAL OF TRAUMA AND ACUTE CARE SURGERY, 2021, 91 (03): : E81 - E82
  • [34] INFORMATION SECURITY CULTURE: A SYSTEMATIC LITERATURE REVIEW
    Hassan, Noor Hafizah
    Ismail, Zuraini
    Maarop, Nurazean
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON COMPUTING & INFORMATICS, 2015, : 456 - 463
  • [35] Information Security Risk Management in IT Outsourcing - A Quarter-century Systematic Literature Review
    Bhatti, Baber Majid
    Mubarak, Sameera
    Nagalingam, Sev
    JOURNAL OF GLOBAL INFORMATION TECHNOLOGY MANAGEMENT, 2021, 24 (04) : 259 - 298
  • [36] Implementation of Information Security Management Systems for Data Protection in Organizations: A systematic literature review
    Marhad, Siti Suhaida
    Abd Goni, Siti Zaleha
    Sani, Mad Khir Johari Abdullah
    ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2024, 9 : 197 - 203
  • [37] Implementation of Information Security Management Systems for Data Protection in Organizations: A systematic literature review
    Marhad, Siti Suhaida
    Goni, Siti Zaleha Abd
    Sani, Mad Khir Johari Abdullah
    ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2024, 9 : 197 - 203
  • [38] Information Security Concerns in Digital Services: Literature Review and a Multi-Stakeholder Approach
    Singhal, Himanshu
    Kar, Arpan Kumar
    2015 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2015, : 901 - 906
  • [39] Information needs of rural health professionals: a review of the literature
    Dorsch, JL
    BULLETIN OF THE MEDICAL LIBRARY ASSOCIATION, 2000, 88 (04): : 346 - 354
  • [40] Information needs of public health practitioners: a review of the literature
    Ford, Jennifer
    Korjonen, Helena
    HEALTH INFORMATION AND LIBRARIES JOURNAL, 2012, 29 (04): : 260 - 273