{"id":"https://openalex.org/W2170731494","doi":"https://doi.org/10.1108/09685221111143060","title":"The 14\u2010layered framework for including social and organizational aspects in security management","display_name":"The 14\u2010layered framework for including social and organizational aspects in security management","publication_year":2011,"publication_date":"2011-06-07","ids":{"openalex":"https://openalex.org/W2170731494","doi":"https://doi.org/10.1108/09685221111143060","mag":"2170731494"},"language":"en","primary_location":{"id":"doi:10.1108/09685221111143060","is_oa":false,"landing_page_url":"https://doi.org/10.1108/09685221111143060","pdf_url":null,"source":{"id":"https://openalex.org/S204075876","display_name":"Information Management & Computer Security","issn_l":"0968-5227","issn":["0968-5227","1758-5805"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319811","host_organization_name":"Emerald Publishing Limited","host_organization_lineage":["https://openalex.org/P4310319811"],"host_organization_lineage_names":["Emerald Publishing Limited"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information Management &amp; Computer Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5033423230","display_name":"Yvgne Monfelt","orcid":null},"institutions":[{"id":"https://openalex.org/I161593684","display_name":"Stockholm University","ror":"https://ror.org/05f0yaq80","country_code":"SE","type":"education","lineage":["https://openalex.org/I161593684"]}],"countries":["SE"],"is_corresponding":true,"raw_author_name":"Yvgne Monfelt","raw_affiliation_strings":["Department of Computer and Systems Sciences, Stockholm University, Stockholm, Sweden"],"affiliations":[{"raw_affiliation_string":"Department of Computer and Systems Sciences, Stockholm University, Stockholm, Sweden","institution_ids":["https://openalex.org/I161593684"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023759100","display_name":"Sofie Pilemalm","orcid":"https://orcid.org/0000-0002-4677-1949"},"institutions":[{"id":"https://openalex.org/I1291458624","display_name":"Swedish Defence Research Agency","ror":"https://ror.org/0470cgs30","country_code":"SE","type":"funder","lineage":["https://openalex.org/I1291458624"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Sofie Pilemalm","raw_affiliation_strings":["Division of Information Systems, Swedish Defence Research Agency, Link\u00f6ping, Sweden"],"affiliations":[{"raw_affiliation_string":"Division of Information Systems, Swedish Defence Research Agency, Link\u00f6ping, Sweden","institution_ids":["https://openalex.org/I1291458624"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079919068","display_name":"Jonas Hallberg","orcid":null},"institutions":[{"id":"https://openalex.org/I1291458624","display_name":"Swedish Defence Research Agency","ror":"https://ror.org/0470cgs30","country_code":"SE","type":"funder","lineage":["https://openalex.org/I1291458624"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Jonas Hallberg","raw_affiliation_strings":["Division of Information Systems, Swedish Defence Research Agency, Link\u00f6ping, Sweden"],"affiliations":[{"raw_affiliation_string":"Division of Information Systems, Swedish Defence Research Agency, Link\u00f6ping, Sweden","institution_ids":["https://openalex.org/I1291458624"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046808650","display_name":"Louise Yngstr\u00f6m","orcid":null},"institutions":[{"id":"https://openalex.org/I161593684","display_name":"Stockholm University","ror":"https://ror.org/05f0yaq80","country_code":"SE","type":"education","lineage":["https://openalex.org/I161593684"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Louise Yngstr\u00f6m","raw_affiliation_strings":["Department of Computer and Systems Sciences, Stockholm University, Stockholm, Sweden"],"affiliations":[{"raw_affiliation_string":"Department of Computer and Systems Sciences, Stockholm University, Stockholm, Sweden","institution_ids":["https://openalex.org/I161593684"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5033423230"],"corresponding_institution_ids":["https://openalex.org/I161593684"],"apc_list":null,"apc_paid":null,"fwci":6.6506,"has_fulltext":false,"cited_by_count":20,"citation_normalized_percentile":{"value":0.96540264,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"19","issue":"2","first_page":"124","last_page":"133"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9882000088691711,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11195","display_name":"Simulation Techniques and Applications","score":0.9204999804496765,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/information-security-management","display_name":"Information security management","score":0.6395254731178284},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.6128367781639099},{"id":"https://openalex.org/keywords/information-security-standards","display_name":"Information security standards","score":0.6109910011291504},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6055252552032471},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.5739172101020813},{"id":"https://openalex.org/keywords/knowledge-management","display_name":"Knowledge management","score":0.5410363674163818},{"id":"https://openalex.org/keywords/security-convergence","display_name":"Security convergence","score":0.4655383825302124},{"id":"https://openalex.org/keywords/security-management","display_name":"Security management","score":0.45569318532943726},{"id":"https://openalex.org/keywords/standard-of-good-practice","display_name":"Standard of Good Practice","score":0.4514561593532562},{"id":"https://openalex.org/keywords/variety","display_name":"Variety (cybernetics)","score":0.43580162525177},{"id":"https://openalex.org/keywords/security-service","display_name":"Security service","score":0.3827016055583954},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.38240450620651245},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.34599965810775757},{"id":"https://openalex.org/keywords/network-security-policy","display_name":"Network security policy","score":0.14090684056282043}],"concepts":[{"id":"https://openalex.org/C148976360","wikidata":"https://www.wikidata.org/wiki/Q1662500","display_name":"Information security management","level":5,"score":0.6395254731178284},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.6128367781639099},{"id":"https://openalex.org/C139547956","wikidata":"https://www.wikidata.org/wiki/Q6031202","display_name":"Information security standards","level":5,"score":0.6109910011291504},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6055252552032471},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.5739172101020813},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.5410363674163818},{"id":"https://openalex.org/C52420254","wikidata":"https://www.wikidata.org/wiki/Q7445028","display_name":"Security convergence","level":5,"score":0.4655383825302124},{"id":"https://openalex.org/C83163435","wikidata":"https://www.wikidata.org/wiki/Q3954104","display_name":"Security management","level":2,"score":0.45569318532943726},{"id":"https://openalex.org/C47309137","wikidata":"https://www.wikidata.org/wiki/Q7598357","display_name":"Standard of Good Practice","level":5,"score":0.4514561593532562},{"id":"https://openalex.org/C136197465","wikidata":"https://www.wikidata.org/wiki/Q1729295","display_name":"Variety (cybernetics)","level":2,"score":0.43580162525177},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.3827016055583954},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.38240450620651245},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.34599965810775757},{"id":"https://openalex.org/C117110713","wikidata":"https://www.wikidata.org/wiki/Q3394676","display_name":"Network security policy","level":4,"score":0.14090684056282043},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1108/09685221111143060","is_oa":false,"landing_page_url":"https://doi.org/10.1108/09685221111143060","pdf_url":null,"source":{"id":"https://openalex.org/S204075876","display_name":"Information Management & Computer Security","issn_l":"0968-5227","issn":["0968-5227","1758-5805"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319811","host_organization_name":"Emerald Publishing Limited","host_organization_lineage":["https://openalex.org/P4310319811"],"host_organization_lineage_names":["Emerald Publishing Limited"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information Management &amp; Computer Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6100000143051147}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":20,"referenced_works":["https://openalex.org/W359382321","https://openalex.org/W587461618","https://openalex.org/W657731981","https://openalex.org/W1217720250","https://openalex.org/W1503984168","https://openalex.org/W1527571715","https://openalex.org/W1543426176","https://openalex.org/W1557136789","https://openalex.org/W2013140629","https://openalex.org/W2111030512","https://openalex.org/W2123755784","https://openalex.org/W2131374564","https://openalex.org/W2136451344","https://openalex.org/W2159016629","https://openalex.org/W2591213470","https://openalex.org/W2768298729","https://openalex.org/W2952753488","https://openalex.org/W3151685851","https://openalex.org/W4285719527","https://openalex.org/W6634236835"],"related_works":["https://openalex.org/W40842196","https://openalex.org/W2049188895","https://openalex.org/W2483557577","https://openalex.org/W2362334938","https://openalex.org/W2153290653","https://openalex.org/W2149739119","https://openalex.org/W2741061559","https://openalex.org/W2482158950","https://openalex.org/W2379320583","https://openalex.org/W585485619"],"abstract_inverted_index":{"Purpose":[0],"The":[1,63,79,150,209,224],"purpose":[2],"of":[3,87,116,158],"this":[4],"paper":[5,225],"is":[6,15,43,56,81,155],"to":[7,17,23,89,101,108,113,124,132,140,144,165,199,229,235],"describe":[8],"the":[9,25,41,110,128,138,153,169,182,203,206,218],"controlled":[10],"information":[11,26,45,96,117,134,159,175,219],"security":[12,27,46,97,118,135,160,176,190,220],"project":[13,42,80],"which":[14,180],"designed":[16],"investigate,":[18],"assess":[19,133],"and":[20,93,143,168,174,186,201,233],"provide":[21],"tools":[22],"improve":[24],"status":[28],"in":[29,58,84,99,119,130,137,188,205],"organizations":[30,120,163],"with":[31,76],"a":[32,59,85],"focus":[33],"on":[34,127,196,217,227],"public":[35],"agencies.":[36],"A":[37],"central":[38],"question":[39],"for":[40,95,147,152],"how":[44,234],"issues":[47,98,161],"are":[48,178],"communicated":[49],"within":[50,162],"organizations,":[51],"specifically":[52],"underlining":[53],"that":[54,156],"communication":[55,115,157,231],"control":[57,200,211],"cybernetic":[60],"sense.":[61],"Design/methodology/approach":[62],"research":[64,154],"method":[65],"applied":[66,71],"can":[67],"be":[68,166],"expressed":[69],"as":[70],"general":[72,210],"systems":[73],"theory":[74],"combined":[75],"design":[77,90],"science.":[78],"carried":[82],"out":[83],"number":[86],"steps:":[88],"modelling":[91,111],"techniques":[92,112],"metrics":[94,126],"organizations;":[100],"collect":[102],"data":[103,129],"from":[104,121,184],"Swedish":[105],"governmental":[106],"agencies;":[107,139],"use":[109],"model":[114],"different":[122],"perspectives;":[123],"apply":[125],"order":[131],"levels":[136],"identify":[141,145],"gaps;":[142],"needs":[146],"improvement.":[148],"Findings":[149],"motivation":[151],"tend":[164],"insufficient":[167],"mental":[170],"connections":[171],"between":[172],"IT\u2010security":[173],"work":[177],"weak,":[179],"prohibits":[181],"organization":[183],"learning":[185],"adapting":[187],"its":[189,197],"work.":[191],"An":[192],"entity's":[193],"authority":[194],"depends":[195],"ability":[198],"manage":[202],"variety":[204],"14":[207],"layers.":[208],"objectives":[212],"needed":[213],"were":[214],"implied":[215],"based":[216],"management":[221],"standard.":[222],"Originality/value":[223],"focuses":[226],"mind":[228,230],"conditions":[232],"adapt":[236],"mechanistic":[237],"systems.":[238]},"counts_by_year":[{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":2},{"year":2017,"cited_by_count":3},{"year":2015,"cited_by_count":5},{"year":2014,"cited_by_count":3},{"year":2013,"cited_by_count":1},{"year":2012,"cited_by_count":4}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
