[论文解读] Information Security Strategy in Organisations: Review, Discussion and Future Research Directions
本文提出了一项战略转变:从组织内部的全面信息安全防护,转向更广泛、跨组织的安全战略框架。通过学术文献的主题综述,本文定义了信息安全战略,识别了采纳的驱动因素与收益,并提出了未来研究方向,强调跨越组织边界的系统性、协作性安全方法。
Dependence on information, including for some of the world's largest organisations such as governments and multi-national corporations, has grown rapidly in recent years. However, reports of information security breaches and their associated consequences continue to indicate that attacks are still escalating on organisations when conducting these information-based activities. Clearly, more research is needed to better understand how organisations should formulate strategy to secure their information. Through a thematic review of academic security literature, we (1) analyse the antecedent conditions that motivate the potential adoption of a comprehensive information security strategy, (2) the current perspectives of strategy and (3) the yields and benefits that could be enjoyed post-adoption. Our contributions include a definition of information security strategy. We argue for a paradigm shift to extend from internally-focussed protection of organisation-wide information towards a strategic view that considers the inter-organisational level. Our findings are then used to suggest future research directions.
研究动机与目标
- 探讨推动现代组织采用全面信息安全战略的前置条件。
- 分析学术文献中当前对信息安全战略的视角。
- 识别组织在采纳正式信息安全战略后所获得的可衡量收益与战略回报。
- 提出向跨组织安全战略范式转变,超越内部控制。
- 概述推动组织信息安全战略领域发展的可操作未来研究方向。
提出的方法
- 在计算机与社会(cs.CY)和密码学与安全(cs.CR)领域,对学术文献进行了主题综述。
- 综合同行评审研究的发现,识别出战略制定、实施与结果方面的重复主题。
- 基于综合文献定义‘信息安全战略’,强调战略意图与组织对齐。
- 评估安全战略从被动技术控制向主动战略规划的演变。
- 基于系统性与协作性原则,提出跨组织安全战略的概念框架。
- 利用研究发现推导出未来研究方向,重点关注战略整合与跨组织协作。
实验结果
研究问题
- RQ1推动组织采纳全面信息安全战略的关键驱动因素与条件是什么?
- RQ2当前学术与组织文献中,信息安全战略是如何概念化与实施的?
- RQ3采纳正式信息安全战略后,可衡量的收益与战略回报有哪些?
- RQ4信息安全战略如何超越组织内部边界,实现跨组织协作?
- RQ5哪些未来研究方向对推进信息安全在组织中的战略作用最为关键?
主要发现
- 正式的信息安全战略被定义为一种结构化、全组织范围的方法,将安全目标与业务目标对齐。
- 信息安全战略的采纳受到数字依赖度提升、网络威胁增加以及监管压力的驱动。
- 实施战略安全框架的组织报告称其风险管理水平、合规性与运营韧性均得到改善。
- 当前文献显示战略思维存在缺口,多数方法仍集中于技术控制,而非整体性、企业级规划。
- 为应对供应链与合作伙伴关系中的系统性风险,必须推动向跨组织安全战略的范式转变。
- 未来研究应探索战略协作模式、治理框架以及跨组织安全的绩效指标。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。