The Australasian Journal of Information Systems
Author ORCID Identifier
Craig A. Horne
https://orcid.org/0000-0001-7395-4348
Sean B. Maynard
Atif Ahmad
Document Type
Research Article
Abstract
Dependence on information, including for some of the world’s largest organisations such as governments and multi-national corporations, has grown rapidly in recent years. However, reports of information security breaches and their associated consequences indicate that attacks are escalating on organisations conducting these information-based activities. Organisations need to formulate strategy to secure their information, however gaps exist in knowledge. Through a thematic review of academic security literature, (1) we analyse the antecedent conditions that motivate the adoption of a comprehensive information security strategy, (2) the conceptual elements of strategy and (3) the benefits that are enjoyed post-adoption. Our contributions include a definition of information security strategy that moves from an internally-focussed protection of information towards a strategic view that considers the organisation, its resources and capabilities, and its external environment. Our findings are then used to suggest future research directions.
Recommended Citation
Horne, Craig A.; Maynard, Sean B.; and Ahmad, Atif
(2017)
"Organisational Information Security Strategy: Review, Discussion and Future Research,"
The Australasian Journal of Information Systems: Vol. 21:
No.
1, Article 7.
DOI: 10.3127/ajis.v21i0.1427
Available at:
https://aisel.aisnet.org/ajis/vol21/iss1/7