首页> 外文期刊>Information management & computer security >Information security culture - state-of-the-art review between 2000 and 2013
【24h】

Information security culture - state-of-the-art review between 2000 and 2013

机译:信息安全文化-2000年至2013年的最新回顾

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - The aim of this paper is to survey existing information security culture research to scrutinise the kind of knowledge that has been developed and the way in which this knowledge has been brought about. Design/methodology/approach - Results are based on a literature review of information security culture research published between 2000 and 2013 (December). Findings - This paper can conclude that existing research has focused on a broad set of research topics, but with limited depth. It is striking that the effects of different information security cultures have not been part of that focus. Moreover, existing research has used a small repertoire of research methods, a repertoire that is more limited than in information systems research in general. Furthermore, an extensive part of the research is descriptive, philosophical or theoretical - lacking a structured use of empirical data - which means that it is quite immature. Research limitations/implications - Findings call for future research that: addresses the effects of different information security cultures; addresses the identified research topics with greater depth; focuses more on generating theories or testing theories to increase the maturity of this subfield of information security research; and uses a broader set of research methods. It would be particularly interesting to see future studies that use intervening or ethnographic approaches because, to date, these have been completely lacking in existing research. Practical implications - Findings show that existing research is, to a large extent, descriptive, philosophical or theoretical. Hence, it is difficult for practitioners to adopt these research results, such as frameworks for cultivating or assessment tools, which have not been empirically validated. Originality/value - Few state-of-the-art reviews have sought to assess the maturity of existing research on information security culture. Findings on types of research methods used in information security culture research extend beyond the existing knowledge base, which allows for a critical discussion about existing research in this sub-discipline of information security.
机译:目的-本文的目的是调查现有的信息安全文化研究,以检查已开发的知识的种类以及该知识的产生方式。设计/方法/方法-结果基于对2000年至2013年(12月)发布的信息安全文化研究的文献综述。调查结果-本文可以得出结论,现有研究集中在广泛的研究主题上,但是深度有限。令人惊讶的是,不同的信息安全文化的影响还没有成为该重点的一部分。此外,现有研究仅使用了少量的研究方法,该方法比一般的信息系统研究更受限制。此外,该研究的大部分内容是描述性,哲学性或理论性的-缺乏对经验数据的结构化使用-这意味着该研究还很不成熟。研究的局限性/意义-研究结果需要进行进一步的研究,以解决不同信息安全文化的影响;更深入地解决已确定的研究主题;更多地侧重于产生理论或检验理论以增加信息安全研究这一子领域的成熟度;并使用了更广泛的研究方法。看到将来使用干预方法或人种学方法的研究会特别有趣,因为迄今为止,这些研究已完全不存在于现有研究中。实际意义-研究结果表明,现有研究在很大程度上是描述性,哲学性或理论性的。因此,从业人员很难采用尚未经过经验验证的这些研究结果,例如用于培养或评估的框架。原创性/价值-很少有最新的评论寻求评估现有信息安全文化研究的成熟度。关于信息安全文化研究中使用的研究方法类型的发现超出了现有的知识库,这使我们可以对该信息安全子学科中的现有研究进行严格的讨论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号