{"id":"https://openalex.org/W4401175489","doi":"https://doi.org/10.1145/3685235.3685242","title":"Information Security Research in the Information Systems Discipline: A Thematic Review and Future Research Directions","display_name":"Information Security Research in the Information Systems Discipline: A Thematic Review and Future Research Directions","publication_year":2024,"publication_date":"2024-07-31","ids":{"openalex":"https://openalex.org/W4401175489","doi":"https://doi.org/10.1145/3685235.3685242"},"language":"en","primary_location":{"id":"doi:10.1145/3685235.3685242","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3685235.3685242","pdf_url":null,"source":{"id":"https://openalex.org/S4210234096","display_name":"ACM SIGMIS Database the DATABASE for Advances in Information Systems","issn_l":"1532-0936","issn":["1532-0936","2331-1622"],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM SIGMIS Database: the DATABASE for Advances in Information Systems","raw_type":"journal-article"},"type":"review","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5042014280","display_name":"Stephanie Totty","orcid":"https://orcid.org/0000-0001-9309-551X"},"institutions":[{"id":"https://openalex.org/I169615421","display_name":"Middle Tennessee State University","ror":"https://ror.org/02n1hzn07","country_code":"US","type":"education","lineage":["https://openalex.org/I169615421"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stephanie Totty","raw_affiliation_strings":["Department of Information Systems and Analytics, Middle Tennessee State University, Murfreesboro, TN, USA"],"raw_orcid":"https://orcid.org/0000-0001-9309-551X","affiliations":[{"raw_affiliation_string":"Department of Information Systems and Analytics, Middle Tennessee State University, Murfreesboro, TN, USA","institution_ids":["https://openalex.org/I169615421"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101856148","display_name":"He Li","orcid":"https://orcid.org/0000-0002-9882-3341"},"institutions":[{"id":"https://openalex.org/I8078737","display_name":"Clemson University","ror":"https://ror.org/037s24f05","country_code":"US","type":"education","lineage":["https://openalex.org/I8078737"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"He Li","raw_affiliation_strings":["Department of Management, Clemson University, Clemson, SC, USA"],"raw_orcid":"https://orcid.org/0000-0002-9882-3341","affiliations":[{"raw_affiliation_string":"Department of Management, Clemson University, Clemson, SC, USA","institution_ids":["https://openalex.org/I8078737"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046327607","display_name":"Chen Zhang","orcid":"https://orcid.org/0009-0001-5061-3580"},"institutions":[{"id":"https://openalex.org/I173911158","display_name":"Iowa State University","ror":"https://ror.org/04rswrd78","country_code":"US","type":"education","lineage":["https://openalex.org/I173911158"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chen Zhang","raw_affiliation_strings":["Department of Information Systems and Business Analytics, Iowa State University, Ames, IA, USA"],"raw_orcid":"https://orcid.org/0009-0001-5061-3580","affiliations":[{"raw_affiliation_string":"Department of Information Systems and Business Analytics, Iowa State University, Ames, IA, USA","institution_ids":["https://openalex.org/I173911158"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5007203501","display_name":"Brian D. Janz","orcid":null},"institutions":[{"id":"https://openalex.org/I94658018","display_name":"University of Memphis","ror":"https://ror.org/01cq23130","country_code":"US","type":"education","lineage":["https://openalex.org/I94658018"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Brian Janz","raw_affiliation_strings":["Department of Management Information Systems, University of Memphis, Memphis, TN, USA"],"raw_orcid":"https://orcid.org/0009-0004-3918-5345","affiliations":[{"raw_affiliation_string":"Department of Management Information Systems, University of Memphis, Memphis, TN, USA","institution_ids":["https://openalex.org/I94658018"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":3.4477,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.93445822,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":"55","issue":"3","first_page":"135","last_page":"169"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/thematic-map","display_name":"Thematic map","score":0.6928157210350037},{"id":"https://openalex.org/keywords/information-system","display_name":"Information system","score":0.5580708980560303},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.4839401841163635},{"id":"https://openalex.org/keywords/information-systems-security","display_name":"Information systems security","score":0.46846622228622437},{"id":"https://openalex.org/keywords/information-security-management","display_name":"Information security management","score":0.4355087876319885},{"id":"https://openalex.org/keywords/engineering-ethics","display_name":"Engineering ethics","score":0.4284459054470062},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.41750362515449524},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.3857496976852417},{"id":"https://openalex.org/keywords/knowledge-management","display_name":"Knowledge management","score":0.3727051615715027},{"id":"https://openalex.org/keywords/management-science","display_name":"Management science","score":0.35536104440689087},{"id":"https://openalex.org/keywords/sociology","display_name":"Sociology","score":0.35452908277511597},{"id":"https://openalex.org/keywords/political-science","display_name":"Political science","score":0.32446491718292236},{"id":"https://openalex.org/keywords/management-information-systems","display_name":"Management information systems","score":0.2078036069869995},{"id":"https://openalex.org/keywords/geography","display_name":"Geography","score":0.19901975989341736},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.19296535849571228},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.17084723711013794},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.11939108371734619},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.11832126975059509},{"id":"https://openalex.org/keywords/cartography","display_name":"Cartography","score":0.08631366491317749},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.08562883734703064}],"concepts":[{"id":"https://openalex.org/C93692415","wikidata":"https://www.wikidata.org/wiki/Q1502030","display_name":"Thematic map","level":2,"score":0.6928157210350037},{"id":"https://openalex.org/C180198813","wikidata":"https://www.wikidata.org/wiki/Q121182","display_name":"Information system","level":2,"score":0.5580708980560303},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.4839401841163635},{"id":"https://openalex.org/C2988319471","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information systems security","level":4,"score":0.46846622228622437},{"id":"https://openalex.org/C148976360","wikidata":"https://www.wikidata.org/wiki/Q1662500","display_name":"Information security management","level":5,"score":0.4355087876319885},{"id":"https://openalex.org/C55587333","wikidata":"https://www.wikidata.org/wiki/Q1133029","display_name":"Engineering ethics","level":1,"score":0.4284459054470062},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.41750362515449524},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.3857496976852417},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.3727051615715027},{"id":"https://openalex.org/C539667460","wikidata":"https://www.wikidata.org/wiki/Q2414942","display_name":"Management science","level":1,"score":0.35536104440689087},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.35452908277511597},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.32446491718292236},{"id":"https://openalex.org/C29848774","wikidata":"https://www.wikidata.org/wiki/Q61905","display_name":"Management information systems","level":3,"score":0.2078036069869995},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.19901975989341736},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.19296535849571228},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.17084723711013794},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.11939108371734619},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.11832126975059509},{"id":"https://openalex.org/C58640448","wikidata":"https://www.wikidata.org/wiki/Q42515","display_name":"Cartography","level":1,"score":0.08631366491317749},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.08562883734703064},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3685235.3685242","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3685235.3685242","pdf_url":null,"source":{"id":"https://openalex.org/S4210234096","display_name":"ACM SIGMIS Database the DATABASE for Advances in Information Systems","issn_l":"1532-0936","issn":["1532-0936","2331-1622"],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM SIGMIS Database: the DATABASE for Advances in Information Systems","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.5400000214576721,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":212,"referenced_works":["https://openalex.org/W74666179","https://openalex.org/W110993677","https://openalex.org/W133780958","https://openalex.org/W177610582","https://openalex.org/W599737683","https://openalex.org/W875938751","https://openalex.org/W1482734477","https://openalex.org/W1489771250","https://openalex.org/W1501655979","https://openalex.org/W1511284091","https://openalex.org/W1533444565","https://openalex.org/W1536398137","https://openalex.org/W1538043169","https://openalex.org/W1570388338","https://openalex.org/W1585601131","https://openalex.org/W1602619638","https://openalex.org/W1603962791","https://openalex.org/W1605781414","https://openalex.org/W1863383349","https://openalex.org/W1901676853","https://openalex.org/W1964044985","https://openalex.org/W1966884856","https://openalex.org/W1967352763","https://openalex.org/W1969641949","https://openalex.org/W1979767694","https://openalex.org/W1982847337","https://openalex.org/W1983315518","https://openalex.org/W1984381799","https://openalex.org/W1990282415","https://openalex.org/W1993328537","https://openalex.org/W2000406585","https://openalex.org/W2006553501","https://openalex.org/W2007776423","https://openalex.org/W2010902645","https://openalex.org/W2014538726","https://openalex.org/W2016484055","https://openalex.org/W2019833576","https://openalex.org/W2021464460","https://openalex.org/W2024419606","https://openalex.org/W2024465817","https://openalex.org/W2026754641","https://openalex.org/W2030959655","https://openalex.org/W2035304801","https://openalex.org/W2036883724","https://openalex.org/W2039314714","https://openalex.org/W2039649206","https://openalex.org/W2040806443","https://openalex.org/W2043607013","https://openalex.org/W2050091520","https://openalex.org/W2051761983","https://openalex.org/W2058012887","https://openalex.org/W2068193594","https://openalex.org/W2071051189","https://openalex.org/W2072047708","https://openalex.org/W2072770274","https://openalex.org/W2073242082","https://openalex.org/W2076850787","https://openalex.org/W2089981770","https://openalex.org/W2090265800","https://openalex.org/W2094130901","https://openalex.org/W2096830520","https://openalex.org/W2097749188","https://openalex.org/W2099647042","https://openalex.org/W2101179869","https://openalex.org/W2105707339","https://openalex.org/W2105731959","https://openalex.org/W2105992541","https://openalex.org/W2111628838","https://openalex.org/W2115904533","https://openalex.org/W2118692224","https://openalex.org/W2118965472","https://openalex.org/W2119350371","https://openalex.org/W2119587968","https://openalex.org/W2120197657","https://openalex.org/W2122193960","https://openalex.org/W2125326971","https://openalex.org/W2128854054","https://openalex.org/W2129100925","https://openalex.org/W2129205437","https://openalex.org/W2130885408","https://openalex.org/W2131951904","https://openalex.org/W2131997083","https://openalex.org/W2132568829","https://openalex.org/W2139828324","https://openalex.org/W2147142066","https://openalex.org/W2148514199","https://openalex.org/W2153535865","https://openalex.org/W2156132896","https://openalex.org/W2156358707","https://openalex.org/W2157635163","https://openalex.org/W2159119446","https://openalex.org/W2164422986","https://openalex.org/W2170899042","https://openalex.org/W2177986285","https://openalex.org/W2201134306","https://openalex.org/W2204032447","https://openalex.org/W2276368824","https://openalex.org/W2277478358","https://openalex.org/W2280059995","https://openalex.org/W2287179647","https://openalex.org/W2329431965","https://openalex.org/W2407226211","https://openalex.org/W2408546867","https://openalex.org/W2486645354","https://openalex.org/W2512279548","https://openalex.org/W2518306363","https://openalex.org/W2531864566","https://openalex.org/W2545327224","https://openalex.org/W2551675031","https://openalex.org/W2559395125","https://openalex.org/W2560034573","https://openalex.org/W2560077776","https://openalex.org/W2560808744","https://openalex.org/W2561909538","https://openalex.org/W2562909420","https://openalex.org/W2563531746","https://openalex.org/W2568486860","https://openalex.org/W2572178036","https://openalex.org/W2576128768","https://openalex.org/W2585385159","https://openalex.org/W2593649556","https://openalex.org/W2606850380","https://openalex.org/W2607808856","https://openalex.org/W2610527038","https://openalex.org/W2683619959","https://openalex.org/W2736747074","https://openalex.org/W2740175867","https://openalex.org/W2745971308","https://openalex.org/W2746228346","https://openalex.org/W2752025338","https://openalex.org/W2767985696","https://openalex.org/W2774443158","https://openalex.org/W2782101021","https://openalex.org/W2782393250","https://openalex.org/W2782420259","https://openalex.org/W2783320327","https://openalex.org/W2783763960","https://openalex.org/W2794533486","https://openalex.org/W2804871695","https://openalex.org/W2890022979","https://openalex.org/W2892702881","https://openalex.org/W2895269299","https://openalex.org/W2902621595","https://openalex.org/W2938830984","https://openalex.org/W2948030712","https://openalex.org/W2951098948","https://openalex.org/W2963785508","https://openalex.org/W2967897234","https://openalex.org/W2978773184","https://openalex.org/W2986881936","https://openalex.org/W2990465956","https://openalex.org/W2991610326","https://openalex.org/W2992175917","https://openalex.org/W2998601404","https://openalex.org/W3000903963","https://openalex.org/W3005189649","https://openalex.org/W3005887648","https://openalex.org/W3007177564","https://openalex.org/W3009544789","https://openalex.org/W3014157822","https://openalex.org/W3021400980","https://openalex.org/W3023244448","https://openalex.org/W3028939512","https://openalex.org/W3034090456","https://openalex.org/W3044562222","https://openalex.org/W3067255367","https://openalex.org/W3085353310","https://openalex.org/W3098277899","https://openalex.org/W3111991419","https://openalex.org/W3112535516","https://openalex.org/W3122329707","https://openalex.org/W3122335909","https://openalex.org/W3122424966","https://openalex.org/W3123753262","https://openalex.org/W3124497104","https://openalex.org/W3124884502","https://openalex.org/W3125210271","https://openalex.org/W3125265168","https://openalex.org/W3125322783","https://openalex.org/W3129519361","https://openalex.org/W3133958860","https://openalex.org/W3139650183","https://openalex.org/W3141119712","https://openalex.org/W3142415544","https://openalex.org/W3145342109","https://openalex.org/W3146559281","https://openalex.org/W3148408272","https://openalex.org/W3149232036","https://openalex.org/W3164172021","https://openalex.org/W3165300127","https://openalex.org/W3170967076","https://openalex.org/W3172730869","https://openalex.org/W3193772061","https://openalex.org/W3198921854","https://openalex.org/W3199887894","https://openalex.org/W3203763999","https://openalex.org/W3205142248","https://openalex.org/W3206261414","https://openalex.org/W4205472611","https://openalex.org/W4205809757","https://openalex.org/W4206105075","https://openalex.org/W4231826647","https://openalex.org/W4239904347","https://openalex.org/W4256256652","https://openalex.org/W4280615448","https://openalex.org/W4281732158","https://openalex.org/W4285018249","https://openalex.org/W4285155372","https://openalex.org/W4285495264","https://openalex.org/W4286716377","https://openalex.org/W4293178048","https://openalex.org/W4293312847"],"related_works":["https://openalex.org/W2508914475","https://openalex.org/W2120971814","https://openalex.org/W2777401565","https://openalex.org/W4310892428","https://openalex.org/W1974991139","https://openalex.org/W4308535653","https://openalex.org/W3018580283","https://openalex.org/W2474818065","https://openalex.org/W1208953748","https://openalex.org/W2960304630"],"abstract_inverted_index":{"Information":[0],"security":[1,55,78,86,90,98,111,130],"continues":[2],"to":[3,29,57,119,172],"grow":[4],"in":[5,7,99,102,133],"importance":[6],"all":[8],"aspects":[9],"of":[10,33,53,67,97,109,128,137],"society":[11],"and":[12,63,83,88,112,158,167,177],"therefore":[13],"evolves":[14],"as":[15,150],"a":[16,26,37,50,95,146,180],"prevalent":[17],"research":[18,131,162,175],"area.":[19],"The":[20],"information":[21,54,68,77,110,129],"systems":[22],"(IS)":[23],"discipline":[24],"offers":[25],"unique":[27],"perspective":[28],"move":[30],"this":[31],"stream":[32],"literature":[34,56,121],"forward.":[35],"Using":[36],"semiautomated":[38,181],"thematic":[39],"analysis":[40,71],"approach":[41,184],"based":[42],"on":[43,145],"the":[44,106,125,134,138],"topic":[45,182],"modeling":[46,183],"technique,":[47],"we":[48,60],"review":[49,117],"broad":[51,126],"range":[52,127],"investigate":[58],"how":[59],"may":[61],"integrate":[62],"advance":[64],"our":[65],"understanding":[66],"security.":[69],"Our":[70],"reveals":[72],"four":[73],"major":[74,156],"themes,":[75],"including":[76],"policy":[79],"(ISP)":[80],"compliance,":[81],"motivations":[82],"susceptibility,":[84],"software":[85],"decisions,":[87],"firm":[89],"strategy.":[91],"We":[92],"also":[93],"identify":[94],"theme":[96],"broader":[100],"contexts,":[101],"which":[103],"studies":[104],"consider":[105],"societal":[107],"impacts":[108],"online":[113],"hacker":[114],"behavior.":[115],"This":[116],"contributes":[118],"IS":[120],"by":[122],"1)":[123],"synthesizing":[124],"published":[132],"top":[135],"journals":[136],"field,":[139],"moving":[140],"beyond":[141],"prior":[142],"reviews":[143],"focusing":[144],"narrower":[147],"scope":[148],"such":[149],"individual":[151],"ISP":[152],"compliance;":[153],"2)":[154],"identifying":[155],"themes":[157,166],"proposing":[159],"an":[160],"overarching":[161],"framework":[163],"encompassing":[164],"these":[165],"their":[168],"interconnections,":[169],"allowing":[170],"us":[171],"envision":[173],"future":[174],"directions;":[176],"3)":[178],"enumerating":[179],"that":[185],"other":[186],"researchers":[187],"can":[188],"employ.":[189]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
