کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
1025596 1483196 2016 11 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Information security management needs more holistic approach: A literature review
ترجمه فارسی عنوان
مدیریت امنیت اطلاعات مورد نیاز برای رویکرد جامع تر: مروری بر مقالات
کلمات کلیدی
امنیت اطلاعات؛ مدیریت؛ سیاست امنیت اطلاعات؛ شیوه های مدیریتی؛ معماری اطلاعات کسب و کار؛ تراز کسب و کار IT؛ پردازش ابری؛ نظام؛ معماری اطلاعات
موضوعات مرتبط
علوم انسانی و اجتماعی مدیریت، کسب و کار و حسابداری سیستم های اطلاعات مدیریت (MIS)
چکیده انگلیسی


• This paper is aimed at synthesizing the existing literature to suggest that why a more holistic approach of information security management is needed in management context.
• The paper entertains article on the related context for last ten years.
• A rigorous method for literature search is used with predetermined inclusion and exclusion criteria.
• At first more than 300 articles were downloaded for further processing and finally 39 articles were deemed to be relevant to the context under study.
• The paper suggests that management role should be considered in information security management.

Information technology has dramatically increased online business opportunities; however these opportunities have also created serious risks in relation to information security. Previously, information security issues were studied in a technological context, but growing security needs have extended researchers' attention to explore the management role in information security management. Various studies have explored different management roles and activities, but none has given a comprehensive picture of these roles and activities to manage information security effectively. So it is necessary to accumulate knowledge about various managerial roles and activities from literature to enable managers to adopt these for a more holistic approach to information security management. In this paper, using a systematic literature review approach, we synthesised literature related to management's roles in information security to explore specific managerial activities to enhance information security management. We found that numerous activities of management, particularly development and execution of information security policy, awareness, compliance training, development of effective enterprise information architecture, IT infrastructure management, business and IT alignment and human resources management, had a significant impact on the quality of management of information security. Thus, this research makes a novel contribution by arguing that a more holistic approach to information security is needed and we suggest the ways in which managers can play an effective role in information security. This research also opens up many new avenues for further research in this area.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: International Journal of Information Management - Volume 36, Issue 2, April 2016, Pages 215–225
نویسندگان
, , ,