Information security management needs more holistic approach: A literature review

被引:233
|
作者
Soomro, Zahoor Ahmed [1 ]
Shah, Mahmood Hussain [1 ]
Ahmed, Javed [1 ]
机构
[1] Univ Cent Lancashire, Lancashire Business Sch, Preston PR1 2HE, Lancs, England
关键词
Information security; Management; Information security policy; Managerial practices; Business information architecture; Business IT alignment; Cloud computing; Systematic; Information architecture; ENTERPRISE ARCHITECTURE; STRATEGIC ALIGNMENT; SYSTEMS SECURITY; BUSINESS; TECHNOLOGY; RISK; PERSPECTIVE; AWARENESS; POLICIES; ISSUES;
D O I
10.1016/j.ijinfomgt.2015.11.009
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
Information technology has dramatically increased online business opportunities; however these opportunities have also created serious risks in relation to information security. Previously, information security issues were studied in a technological context, but growing security needs have extended researchers' attention to explore the management role in information security management. Various studies have explored different management roles and activities, but none has given a comprehensive picture of these roles and activities to manage information security effectively. So it is necessary to accumulate knowledge about various managerial roles and activities from literature to enable managers to adopt these for a more holistic approach to information security management. In this paper, using a systematic literature review approach, we synthesised literature related to management's roles in information security to explore specific managerial activities to enhance information security management. We found that numerous activities of management, particularly development and execution of information security policy, awareness, compliance training, development of effective enterprise information architecture, IT infrastructure management, business and IT alignment and human resources management, had a significant impact on the quality of management of information security. Thus, this research makes a novel contribution by arguing that a more holistic approach to information security is needed and we suggest the ways in which managers can play an effective role in information security. This research also opens up many new avenues for further research in this area. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:215 / 225
页数:11
相关论文
共 50 条
  • [41] A systematic literature review on image information needs and behaviors
    Cho, Hyerim
    Pham, Minh T. N.
    Leonard, Katherine N.
    Urban, Alex C.
    JOURNAL OF DOCUMENTATION, 2022, 78 (02) : 207 - 227
  • [42] A Holistic Approach to Postendodontic Pain Management: A Narrative Review
    Algarni, Hmoud A.
    JOURNAL OF PHARMACY AND BIOALLIED SCIENCES, 2024, 16 (SUPPL 5) : S4262 - S4270
  • [43] A Holistic Approach to Antiaging as an Adjunct to Antiaging Procedures: A Review of the Literature
    Saluja, Sandeep S.
    Fabi, Sabrina G.
    DERMATOLOGIC SURGERY, 2017, 43 (04) : 475 - 484
  • [44] Cancer patients' information needs and information sources: A systematic review of the literature
    Rutten, LJF
    Arora, NK
    Bakos, AD
    Rowland, J
    Aziz, N
    PSYCHO-ONCOLOGY, 2004, 13 (01) : S34 - S34
  • [45] Letter to the Editor: Swinging the pendulum in prehospital trauma mortality needs a more holistic approach
    Qasim, Zaffer
    Duchesne, Juan
    JOURNAL OF TRAUMA AND ACUTE CARE SURGERY, 2021, 91 (03): : E80 - E81
  • [46] Information Security Management: A System Dynamics Approach
    Nazareth, Derek L.
    Choi, Jae
    AMCIS 2012 PROCEEDINGS, 2012,
  • [47] Symptom management in the intensive care unit: Toward a more holistic approach
    Silverman, HJ
    CRITICAL CARE MEDICINE, 2002, 30 (04) : 936 - 937
  • [48] A Review on Information Security Program Development and Management
    Thangavel, M.
    Subarnaa, D. K. Sri
    Deepa, P.
    Blessie, E. Sharon
    2018 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (IEEE ICCIC 2018), 2018, : 334 - 341
  • [49] Information Security Policy Compliance: Systematic Literature Review
    Angraini
    Alias, Rose Alinda
    Okfalisa
    FIFTH INFORMATION SYSTEMS INTERNATIONAL CONFERENCE, 2019, 161 : 1216 - 1224
  • [50] Information Security Awareness: Literature Review and Integrative Framework
    Jaeger, Lennart
    PROCEEDINGS OF THE 51ST ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES (HICSS), 2018, : 4703 - 4712