首页> 外文期刊>European journal of information systems >Organizational information security policies: a review and research framework
【24h】

Organizational information security policies: a review and research framework

机译:组织信息安全政策:审查和研究框架

获取原文
获取原文并翻译 | 示例
       

摘要

A major stream of research within the field of information systems security examines the use of organizational policies that specify how users of information and technology resources should behave in order to prevent, detect, and respond to security incidents. However, this growing (and at times, conflicting) body of research has made it challenging for researchers and practitioners to comprehend the current state of knowledge on the formation, implementation, and effectiveness of security policies in organizations. Accordingly, the purpose of this paper is to synthesize what we know and what remains to be learned about organizational information security policies, with an eye toward a holistic understanding of this research stream and the identification of promising paths for future study. We review 114 influential security policy-related journal articles and identify five core relationships examined in the literature. Based on these relationships, we outline a research framework that synthesizes the construct linkages within the current literature. Building on our analysis of these results, we identify a series of gaps and draw on additional theoretical perspectives to propose a revised framework that can be used as a basis for future research.
机译:信息系统安全领域的大量研究都研究了组织策略的使用,这些策略指定了信息和技术资源用户应如何行为以预防,检测和响应安全事件。但是,这种不断增长的(有时是相互矛盾的)研究体系使研究人员和从业人员很难理解组织中安全策略的形成,实施和有效性的当前知识状态。因此,本文的目的是综合了解组织信息安全策略的知识和尚需学习的知识,以期全面了解这一研究流,并确定未来研究的有前途的道路。我们审阅了114篇与安全政策有关的有影响力的期刊文章,并确定了文献中研究的五个核心关系。基于这些关系,我们概述了一个研究框架,该框架综合了当前文献中的构建联系。在对这些结果进行分析的基础上,我们确定了一系列差距,并利用其他理论观点提出了修订后的框架,该框架可作为未来研究的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号