{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T16:47:26Z","timestamp":1780764446992,"version":"3.54.1"},"reference-count":45,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2014,7,8]],"date-time":"2014-07-08T00:00:00Z","timestamp":1404777600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,7,8]]},"abstract":"<jats:sec>\n               <jats:title content-type=\"abstract-heading\">Purpose<\/jats:title>\n               <jats:p> \u2013 The purpose of this paper is to propose a holistic cyber security implementation framework (HCS-IF) that lays out the ground for a conceptual, coherent, systematic, overarching and consolidated approach to implement cyber security strategies (CSSs). <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title>\n               <jats:p> \u2013 The HCS-IF is conceptually proposed to address the actual needs that are extracted from literature review. The HCS-IF uses and integrates a set of high-level conceptual security controls, solutions, processes, entities, tools, techniques or mechanisms that are already known in the domains of information security management, software engineering and project management to address the identified needs. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Findings<\/jats:title>\n               <jats:p> \u2013 The HCS-IF components and controls collectively interact and cooperate to implement CSSs. The proposed framework is compared with other related frameworks, and the results show that the HCS-IF outperforms other frameworks on most of the suggested comparison criteria. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title>\n               <jats:p> \u2013 From a practical standpoint, governments and practitioners alike stand to gain from the findings of this research. Governments who want to implement CSSs on a national level will find the proposed framework useful in overseeing cyber security implementation. Practitioners will be prepared to address the anticipated cyber security implementation challenges and the required controls needed to facilitate cyber-security implementation in a holistic overarching manner.<\/jats:p>\n            <\/jats:sec>","DOI":"10.1108\/imcs-02-2013-0014","type":"journal-article","created":{"date-parts":[[2014,7,31]],"date-time":"2014-07-31T09:20:21Z","timestamp":1406798421000},"page":"251-264","source":"Crossref","is-referenced-by-count":30,"title":["A holistic cyber security implementation framework"],"prefix":"10.1108","volume":"22","author":[{"given":"Issa","family":"Atoum","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed","family":"Otoom","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amer","family":"Abu Ali","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"key":"key2020123022171671000_b1","unstructured":"Barnat, R.\n                (2005), \u201cStrategic management: the nature of strategy implementation\u201d, available at: www.strategy-implementation.24xls.com\/en100 (accessed 3 February 2012)."},{"key":"key2020123022171671000_b2","doi-asserted-by":"crossref","unstructured":"Broom, A.\n                (2009), \u201cSecurity consolidation and optimisation: gaining the most from your IT assets\u201d, Computer Fraud and Security, Vol. 2009 No. 5, pp. 15-17, available at: http:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1361372309700612 (accessed 25 February 2012).","DOI":"10.1016\/S1361-3723(09)70061-2"},{"key":"key2020123022171671000_b3","unstructured":"Buecker, A.\n               , \n                  Borrett, M.\n               , \n                  Lorenz, C.\n                and \n                  Powers, C.\n                (2010), \u201cIntroducing the IBM security framework and IBM security blueprint to realize business-driven security\u201d, IBM Redpaper, Vol. 4528 No. 1, pp. 1-96."},{"key":"key2020123022171671000_b4","doi-asserted-by":"crossref","unstructured":"Dasgupta, D.\n                and \n                  Rahman, M.\n                (2011), \u201cA framework for estimating security coverage for cloud service insurance\u201d. In Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence Research, ACM Press,  New York, New York, USA, p. -, available at: http:\/\/dl.acm.org\/citation.cfm?doid=2179298.2179342 (accessed 20 April 2012).","DOI":"10.1145\/2179298.2179342"},{"key":"key2020123022171671000_b5","unstructured":"David, F.\n                (2011), \n                  Strategic Management: Concepts and Cases, 13th ed, Prentice Hall, available at: www.malone.edu\/media\/1\/39\/480\/MMP405_Online_Corporate_Strategy.pdf (accessed 12 February 2012)."},{"key":"key2020123022171671000_b6","unstructured":"Doran, G.T.\n                (1981), \u201cThere\u2019s a SMART way to write management\u2019s goals and objectives\u201d, Management Review, Vol. 70 No. 11, pp. 35-36."},{"key":"key2020123022171671000_b7","unstructured":"EAdirections\n                (2013), EA Frameworks: Pros and Cons \u2013 Inventory and Insights. Report EA-7004, available at: www.eadirections.com\/uploads\/EA_Frameworks_Pros_and_Cons.pdf"},{"key":"key2020123022171671000_b8","unstructured":"Erol, O.\n               , \n                  Sauser, B.J.\n                and \n                  Mansouri, M.\n                (2010), \u201cA framework for investigation into extended enterprise resilience\u201d, Enterprise Information Systems, Vol. 4 No. 2, pp. 111-136, available at: www.tandfonline.com\/doi\/abs\/10.1080\/17517570903474304"},{"key":"key2020123022171671000_b9","unstructured":"Estonia Department of Defence\n                (2008), \n                  Cyber Security Strategy-Estonia\n               , available at: www.mod.gov.ee\/files\/kmin\/img\/files\/Kuberjulgeoleku_strateegia_2008-2013_ENG.pdf (accessed 1 February 2012)."},{"key":"key2020123022171671000_b10","doi-asserted-by":"crossref","unstructured":"Fielden, K.\n                (2011), \u201cAn holistic view of information security: a proposed framework\u201d, International Journal, Vol. 4 No. 1, pp. 427-434.","DOI":"10.20533\/iji.1742.4712.2011.0047"},{"key":"key2020123022171671000_b11","unstructured":"Government of Australia\n                (2009), \u201cCyber SeCurity Strategy\u201d, available at: www.ag.gov.au\/RightsAndProtections\/CyberSecurity\/Documents\/AG Cyber Security Strategy - for website.pdf (accessed 2 July 2014)."},{"key":"key2020123022171671000_b12","doi-asserted-by":"crossref","unstructured":"Haley, C.B.\n               , \n                  Moffett, J.D.\n                and \n                  Laney, R.\n                (2006), \u201cA framework for security requirements engineering\u201d, in Proceedings of the 2006 International Workshop on Software Engineering for Secure Systems, ACM, pp. 35-42, available at: http:\/\/dl.acm.org\/citation.cfm?id=1137634 (accessed 21 February 2012).","DOI":"10.1145\/1137627.1137634"},{"key":"key2020123022171671000_b14","unstructured":"HM Government\n                (2010), \n                  A Strong Britain in an Age of Uncertainty: The National Security Strategy\n               , The Stationery Office, available at: www.official-documents.gov.uk\/ (accessed 23 December 2011)."},{"key":"key2020123022171671000_b16","unstructured":"International Telecommunication Union (ITU)\n                (2011a), \u201cICT and telecommunications in least developed countries: review of progress made during the decade 2000-2010\u201d, In Fourth United Nations Conference on the Least Developed Countries (UNLDC-IV), Istanbul."},{"key":"key2020123022171671000_b17","unstructured":"International Telecommunication Union (ITU)\n                (2011b), ICT Facts and Figures, available at: www.itu.int\/ITU-D\/ict\/facts\/2011\/material\/ICTFactsFigures2011.pdf (accessed 1 December 2013)."},{"key":"key2020123022171671000_b18","unstructured":"IsecT Ltd\n                (2011), \u201cInformation security compliance\u201d, Information Security Awareness Service (NoticeBored), pp. 1-10, available at: www.isect.com\/html\/white_papers.html"},{"key":"key2020123022171671000_b19","unstructured":"Jalaliniya, S.\n                (2011), Enterprise Architecture and Security Architecture Development, Lund University, Lund, Scania."},{"key":"key2020123022171671000_b20","unstructured":"Janssen, M.\n                and \n                  Hjort-Madsen, K.\n                (2007), \u201cAnalyzing enterprise architecture in national governments: the cases of Denmark and the Netherlands\u201d, in System Sciences, 2007. HICSS 2007, 40th Annual Hawaii International Conference on IEEE, p. -, available at: http:\/\/ieeexplore.ieee.org\/xpls\/abs_all.jsp?arnumber=4076820 (accessed 27 February, 2012)."},{"key":"key2020123022171671000_b21","doi-asserted-by":"crossref","unstructured":"Jo, H.\n               , \n                  Kim, S.\n                and \n                  Won, D.\n                (2011), \u201cAdvanced information security management evaluation system\u201d, KSII Transactions on Internet and Information Systems, Vol. 5 No. 6, pp. 1192-1213, available at: www.itiis.org\/tiis\/download.jsp?filename=TIIS_Vol5No6P6June2011.pdf (accessed 23 August 2011).","DOI":"10.3837\/tiis.2011.06.006"},{"key":"key2020123022171671000_b24","doi-asserted-by":"crossref","unstructured":"Ku, C.-Y.\n               , \n                  Chang, Y.-W.\n                and \n                  Yen, D.C.\n                (2009), \u201cNational information security policy and its implementation: a case study in Taiwan\u201d, Telecommunications Policy, Vol. 33 No. 7, pp. 371-384, available at: http:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0308596109000263 (accessed 17 August 2011).","DOI":"10.1016\/j.telpol.2009.03.002"},{"key":"key2020123022171671000_b25","unstructured":"MoICT\n                (2011), \u201cNational information assurance and cyber security strategy (NIACSS)\u201d, Ministry of Information and Communications Technology, available at: www.moict.gov.jo\/pdf_files\/NIACSS Draft-Public Consultation.pdf."},{"key":"key2020123022171671000_b26","unstructured":"Nnolim, A.L.\n                (2007), A Framework and Methodology for Information Security Management, Lawrence Technological University, Southfield, MI."},{"key":"key2020123022171671000_b28","unstructured":"Otoom, A.\n                and \n                  Atoum, I.\n                (2013), \u201cAn implementation framework (IF) for the national information assurance and cyber security strategy (NIACSS) of Jordan\u201d, The International Arab Journal of Information Technology, Vol. 10 No. 4."},{"key":"key2020123022171671000_b29","unstructured":"Phahlamohlaka, L.\n               , \n                  Jansen van Vuuren, J.\n                and \n                  Coetzee, A.\n                (2011), \u201cCyber security awareness toolkit for national security: an approach to South Africa\u2019s cyber security policy implementation\u201d, in Proceedings of the first IFIP TC9\/TC11 South African Cyber Security Awareness Workshop (SACSAW), Gaborone, Botswana, pp. 1-14, available at: http:\/\/hdl.handle.net\/10204\/5162 (accessed 28 January 2012)."},{"key":"key2020123022171671000_b30","unstructured":"Schwalbe, K.\n                (2010), Information Technology Project Management, 6th ed, Course Technology PTR."},{"key":"key2020123022171671000_b31","unstructured":"Sommerville, I.\n                (2011), \u201cRequirements engineering\u201d, in \n                  Horton, \n               , \n                  M.\n               , \n                  Hirsch, \n               , \n                  M.\n               , \n                  Goldstein, \n                and \n                  M.\n                (Eds), Software Engineering, Addison Wesley, Boston, MA, pp. 82-118."},{"key":"key2020123022171671000_b32","unstructured":"Suid-afrika, R.V.A.N.\n                (2010), \n                  South African National Cybersecurity Policy\n               , available at: South African National Cybersecurity Policy."},{"key":"key2020123022171671000_b33","unstructured":"Tagert, A.\n                (2010), \n                  Cybersecurity Challenges in Developing Nations\n               , Carnegie Mellon University, available at: http:\/\/repository.cmu.edu\/dissertations\/22\/ (accessed 25 February 2012)."},{"key":"key2020123022171671000_b35","unstructured":"The Insight Research Cooperation\n                (2012), Worldwide Telecommunications Industry Revenue, available at: www.insight-corp.com\/pr\/1_2_12.asp (accessed 1 May 2012)."},{"key":"key2020123022171671000_b36","unstructured":"The White House\n                (2009), \n                  The Comprehensive National Cybersecurity Initiative\n               , available at: www.whitehouse.gov\/sites\/default\/files\/cybersecurity.pdf"},{"key":"key2020123022171671000_b37","unstructured":"The White House\n                (2011), \n                  Cyberspace Policy Review, Assuring a Trusted and Resilient Information\n               , available at: www.whitehouse.gov\/assets\/documents\/Cyberspace_Policy_Review_final.pdf"},{"key":"key2020123022171671000_b38","unstructured":"Oracle\u00ae\n                (2011), \u201cInformation Security: A Conceptual Architecture Approach [White Paper]\u201d, retrieved from www.oracle.com\/technetwork\/articles\/entarch\/arch-approach-inf-sec-360705.pdf"},{"key":"key2020123022171671000_b39","doi-asserted-by":"crossref","unstructured":"Trim, P.R.J.\n                and \n                  Lee, Y.-I.\n                (2010a), \u201cA security framework for protecting business, government and society from cyber attacks\u201d, in 2010 5th International Conference on System of Systems Engineering, Loughborough, pp. 1-6.","DOI":"10.1109\/SYSOSE.2010.5544085"},{"key":"key2020123022171671000_b40","doi-asserted-by":"crossref","unstructured":"Trim, P.R.J.\n                and \n                  Lee, Y.-I.\n                (2010b), \u201cA security framework for protecting business, government and society from cyber attacks\u201d, in 2010 5th International Conference on System of Systems Engineering, pp. 1-6, available at: http:\/\/ieeexplore.ieee.org\/lpdocs\/epic03\/wrapper.htm?arnumber=5544085","DOI":"10.1109\/SYSOSE.2010.5544085"},{"key":"key2020123022171671000_b41","unstructured":"Unified Compliance FrameworkTM (UCF)\n                (2012), The Unified Compliance FrameworkTM. available at: www.unifiedcompliance.com\/ (accessed 2 April 2012)."},{"key":"key2020123022171671000_b42","doi-asserted-by":"crossref","unstructured":"US DoD\n                (2011), Department of Defense Strategy for Operating in Cyberspace, available at: www.defense.gov\/news\/d20110714cyber.pdf (accessed 1 April 2012).","DOI":"10.21236\/ADA545385"},{"key":"key2020123022171671000_b43","doi-asserted-by":"crossref","unstructured":"Von Solms, R.\n               , \n                  Thomson, K.L.\n                and \n                  Maninjwa, P.M.\n                (2011), \u201cInformation security governance control through comprehensive policy architectures\u201d, in Information Security South Africa (ISSA), 2011, IEEE, Johannesburg, pp. 1-6, available at: http:\/\/ieeexplore.ieee.org\/xpls\/abs_all.jsp?arnumber=6027522 (accessed 28 January 2012).","DOI":"10.1109\/ISSA.2011.6027522"},{"key":"key2020123022171671000_b44","unstructured":"Whitman, M.E.\n                and \n                  Mattord, H.J.\n                (2011), Principles of information security, Course Technology PTR."},{"key":"key2020123022171671000_b45","doi-asserted-by":"crossref","unstructured":"Zuccato, A.\n                (2007), \u201cHolistic security management framework applied in electronic commerce\u201d, Computers and Security, Vol. 26 No. 3, pp. 256-265, available at: http:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S016740480600188X (accessed 29 February 2012).","DOI":"10.1016\/j.cose.2006.11.003"},{"key":"key2020123022171671000_frd1","doi-asserted-by":"crossref","unstructured":"Herath, T.\n               , \n                  Herath, H.\n                and \n                  Bremser, W.G.\n                (2010), \u201cBalanced scorecard implementation of security strategies: a framework for IT security performance management\u201d, Information Systems Management, Vol. 27 No. 1, pp. 72-81, available at: www.tandfonline.com\/doi\/abs\/10.1080\/10580530903455247 (accessed 11 August 2011).","DOI":"10.1080\/10580530903455247"},{"key":"key2020123022171671000_frd2","unstructured":"IGRC\n                (2011), \u201cThe integrated governance, risk and compliance (iGRC) Consortium\u201d, available at: http:\/\/www.informationsecurityprotection.com\/ (accessed 1 April 2012)."},{"key":"key2020123022171671000_frd3","unstructured":"Kaplan, R.S.\n                and \n                  Norton, D.P.\n                (2004), \u201cMeasuring the strategic readiness of intangible assets\u201d, Harvard Business Review, Vol. 82 No. 2, pp. 52-63."},{"key":"key2020123022171671000_frd4","unstructured":"Klein, N.\n                \n               et al. (1999), Chemical Bank: Implementing the Balanced Scorecard, Harvard Business School."},{"key":"key2020123022171671000_frd5","doi-asserted-by":"crossref","unstructured":"Nudurupati, S.S.\n               , \n                  Bititci, U.S.\n               , \n                  Kumar, V.,\n                and \n                  Chan, F.T.S.\n                (2011), \u201cState of the art literature review on performance measurement\u201d, Computers and Industrial Engineering, Vol. 60 No. 2, pp. 279-290, available at: http:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0360835210002937 (accessed 1 March 2012).","DOI":"10.1016\/j.cie.2010.11.010"},{"key":"key2020123022171671000_frd6","doi-asserted-by":"crossref","unstructured":"Taticchi, P.\n               , \n                  Tonelli, F.\n                and \n                  Cagnazzo, L.\n                (2010), \u201cPerformance measurement and management: a literature review and a research agenda\u201d, Measuring Business Excellence, Vol. 14 No. 1, pp. 4-18, available at: www.emeraldinsight.com\/10.1108\/13683041011027418 (accessed 19 March 2012).","DOI":"10.1108\/13683041011027418"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/IMCS-02-2013-0014","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMCS-02-2013-0014\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMCS-02-2013-0014\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:50:44Z","timestamp":1753393844000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/22\/3\/251-264\/183813"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,7,8]]},"references-count":45,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2014,7,8]]}},"alternative-id":["10.1108\/IMCS-02-2013-0014"],"URL":"https:\/\/doi.org\/10.1108\/imcs-02-2013-0014","relation":{},"ISSN":["0968-5227"],"issn-type":[{"value":"0968-5227","type":"print"}],"subject":[],"published":{"date-parts":[[2014,7,8]]}}}