To read this content please select one of the options below:

Inter-organisational information security: a systematic literature review

Fredrik Karlsson (School of Business, Örebro University, Örebro, Sweden)
Ella Kolkowska (School of Business, Örebro University, Örebro, Sweden)
Frans Prenkert (School of Business, Örebro University, Örebro, Sweden)

Information and Computer Security

ISSN: 2056-4961

Article publication date: 14 November 2016

1534

Abstract

Purpose

The purpose of this paper is to survey existing inter-organisational information security research to scrutinise the kind of knowledge that is currently available and the way in which this knowledge has been brought about.

Design/methodology/approach

The results are based on a literature review of inter-organisational information security research published between 1990 and 2014.

Findings

The authors conclude that existing research has focused on a limited set of research topics. A majority of the research has focused management issues, while employees’/non-staffs’ actual information security work in inter-organisational settings is an understudied area. In addition, the majority of the studies have used a subjective/argumentative method, and few studies combine theoretical work and empirical data.

Research limitations/implications

The findings suggest that future research should address a broader set of research topics, focusing especially on employees/non-staff and their use of processes and technology in inter-organisational settings, as well as on cultural aspects, which are lacking currently; focus more on theory generation or theory testing to increase the maturity of this sub-field; and use a broader set of research methods.

Practical implications

The authors conclude that existing research is to a large extent descriptive, philosophical or theoretical. Thus, it is difficult for practitioners to adopt existing research results, such as governance frameworks, which have not been empirically validated.

Originality/value

Few systematic reviews have assessed the maturity of existing inter-organisational information security research. Findings of authors on research topics, maturity and research methods extend beyond the existing knowledge base, which allow for a critical discussion about existing research in this sub-field of information security.

Keywords

Acknowledgements

This research has been funded by the Swedish Civil Contingencies Agency.

Citation

Karlsson, F., Kolkowska, E. and Prenkert, F. (2016), "Inter-organisational information security: a systematic literature review", Information and Computer Security, Vol. 24 No. 5, pp. 418-451. https://doi.org/10.1108/ICS-11-2016-091

Publisher

:

Emerald Group Publishing Limited

Copyright © 2016, Emerald Group Publishing Limited

Related articles