Bring Your Own Device Information Security Policy Compliance Framework: A Systematic Literature Review and Bibliometric Analysis (2017–2022)

Odai Ali Ali Sharfadeen AL-Azazi, Azah Anir Norman, Norjihan Binti Abdul Ghani · 2022 International Conference on Cyber Resilience (ICCR) · 2022

The latest trend of using personal devices for work productivity is Bring Your Own Device (BYOD). This rapid growth trend has excellent benefits for employees and organizations, but the security risks remain increasing, such as malware, spyware, and malicious apps on employees' devices; organizations should manage an up-to-date information security policy. This paper aims to identify the risks caused by employees' non-compliance and identify factors and behaviours toward BYOD compliance. The factors of information security policy compliance have been found to follow the organization's policies while working with employees' devices and processing data. Influencing information security culture in an organizational setting avoids risks. A systematic review was conducted to identify which journals are most influential to BYOD policy compliance based on Scopus and Web of Science databases. The PRISMA approach is used the Scopus and WoS databases to gather the most related journals by analyzing 67 journals out of 207 from the past six years. It additionally analyzes a fully bibliometric analysis from 2017 to 2022. A further analysis was done using bibliometric with VOSviewer software, version 1.6.17. This paper reviews the selected journals from the extracted literature. It tracks research routes of BYOD policy compliance in terms of risks of non-compliance, impact factors of compliance, and influential theories based on BYOD issues. The BYOD issues are divided into three main categories: technology, management, and human issues. This paper contributes new insights and guidelines for BYOD policy compliance and security issues by listing the risks and impact factors.

Read the paper · More papers on PaperTik