Information security management needs more holistic approach: A literature review

作者:

Highlights:

• This paper is aimed at synthesizing the existing literature to suggest that why a more holistic approach of information security management is needed in management context.

• The paper entertains article on the related context for last ten years.

• A rigorous method for literature search is used with predetermined inclusion and exclusion criteria.

• At first more than 300 articles were downloaded for further processing and finally 39 articles were deemed to be relevant to the context under study.

• The paper suggests that management role should be considered in information security management.

摘要

•This paper is aimed at synthesizing the existing literature to suggest that why a more holistic approach of information security management is needed in management context.•The paper entertains article on the related context for last ten years.•A rigorous method for literature search is used with predetermined inclusion and exclusion criteria.•At first more than 300 articles were downloaded for further processing and finally 39 articles were deemed to be relevant to the context under study.•The paper suggests that management role should be considered in information security management.

论文关键词:Information security,Management,Information security policy,Managerial practices,Business information architecture,Business IT alignment,Cloud computing,Systematic,Information architecture

论文评审过程:Received 24 September 2014, Revised 29 July 2015, Accepted 9 November 2015, Available online 26 November 2015, Version of Record 26 November 2015.

论文官网地址:https://doi.org/10.1016/j.ijinfomgt.2015.11.009