Understanding the Human, Managerial and Organizational Aspects of Information Security Management: A Literature Review
Anupriya Khan, M P Sebastian · RePEc: Research Papers in Economics · 2018
This study on human, managerial and organizational aspects of information security management has three parts. First, it identifies the articles that focus on effective management of information security, employee attitude intention behaviour, and information security policy compliance. The second part identifies the theoretical frameworks commonly used in IS security research. The third part is about analyzing and synthesizing the identified literature. This study summarizes the theories used in IS security management research with non-technical considerations. The theoretical frameworks used in IS security literature generally show a tendency towards explaining the driving factors towards information security compliance and most of them perceive employees to be the key threats to information security. The study shows that noncompliance behaviour is associated with the human factors which cannot be reduced if effective management is not in place.