{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T21:11:14Z","timestamp":1760044274954,"version":"3.41.2"},"reference-count":91,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2014,7,8]],"date-time":"2014-07-08T00:00:00Z","timestamp":1404777600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,7,8]]},"abstract":"<jats:sec>\n               <jats:title content-type=\"abstract-heading\">Purpose<\/jats:title>\n               <jats:p> \u2013 The purpose of this literature review is to analyze current trends in information security and suggest future directions for research. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title>\n               <jats:p> \u2013 The authors used literature review to analyze 1,588 papers from 23 journals and 5 conferences. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Findings<\/jats:title>\n               <jats:p> \u2013 The authors identified 164 different theories used in 684 publications. Distribution of research methods showed that the subjective-argumentative category accounted for 81 per cent, whereas other methods got very low focus. This research offers implications for future research directions on information security. They also identified existing knowledge gaps and how the existing themes are studied in academia. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title>\n               <jats:p> \u2013 The literature review did not include some dedicated security journals (i.e. <jats:italic>Cryptography<\/jats:italic>). <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title>\n               <jats:p> \u2013 The study reveals future directions and trend that the academia should consider. <\/jats:p>\n            <\/jats:sec>\n            <jats:sec>\n               <jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title>\n               <jats:p> \u2013 Information security is top concern for organizations, and this research analyzed how academia dealt with the topic since 1977. Also, the authors suggest future directions for research suggesting new research streams.<\/jats:p>\n            <\/jats:sec>","DOI":"10.1108\/imcs-05-2013-0041","type":"journal-article","created":{"date-parts":[[2014,7,31]],"date-time":"2014-07-31T09:13:17Z","timestamp":1406797997000},"page":"279-308","source":"Crossref","is-referenced-by-count":25,"title":["Information security"],"prefix":"10.1108","volume":"22","author":[{"given":"Mario","family":"Silic","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Back","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2020123003560978000_b1","doi-asserted-by":"crossref","unstructured":"Agrawal, R.\n                and \n                  Srikant, R.\n                (2000), \u201cPrivacy-preserving data mining\u201d, ACM Sigmod Record, Vol. 29 No. 2, pp. 439-450.","DOI":"10.1145\/335191.335438"},{"key":"key2020123003560978000_b3","doi-asserted-by":"crossref","unstructured":"Avison, D.\n                and \n                  Fitzgerald, G.\n                (1991), \u201cInformation systems practice, education and research\u201d, Information Systems Journal, Vol. 1 No. 1, pp. 5-17.","DOI":"10.1111\/j.1365-2575.1991.tb00023.x"},{"key":"key2020123003560978000_b84","doi-asserted-by":"crossref","unstructured":"Bagchi, K.\n                and \n                  Udo, G.\n                (2003), \u201cAn analysis of the growth of computer and internet security breaches\u201d, Communications of AIS, Vol. 12, pp. 684-700.","DOI":"10.17705\/1CAIS.01246"},{"key":"key2020123003560978000_b5","doi-asserted-by":"crossref","unstructured":"Barki, H.\n               , \n                  Rivard, S.\n                and \n                  Talbot, J.\n                (1993a), \u201cA keyword classification scheme for IS research literature: an update\u201d, Mis Quarterly, Vol. 17 No. 2, pp. 209-226.","DOI":"10.2307\/249802"},{"key":"key2020123003560978000_b6","doi-asserted-by":"crossref","unstructured":"Barki, H.\n               , \n                  Rivard, S.\n                and \n                  Talbot, J.\n                (1993b), \u201cToward an assessment of software development risk\u201d, Journal of Management Information Systems, Vol. 10 No. 2, pp. 203-225.","DOI":"10.1080\/07421222.1993.11518006"},{"key":"key2020123003560978000_b7","doi-asserted-by":"crossref","unstructured":"Barth, A.\n               , \n                  Jackson, C.\n                and \n                  Mitchell, J.C.\n                (2009), \u201cSecuring frame communication in browsers\u201d, Communications of the ACM, Vol. 52 No. 6, pp. 83-91.","DOI":"10.1145\/1516046.1516066"},{"key":"key2020123003560978000_b8","doi-asserted-by":"crossref","unstructured":"Baskerville, R.\n                (1993), \u201cInformation systems security design methods: implications for information systems development\u201d, ACM Computing Surveys (CSUR), Vol. 25 No. 4, pp. 375-414.","DOI":"10.1145\/162124.162127"},{"key":"key2020123003560978000_b9","unstructured":"Bishop, M.\n                (2003), Computer Security: Art and Science, 2003, Addison Wesley Professional, Westford, MA, pp. 4-12."},{"key":"key2020123003560978000_b10","doi-asserted-by":"crossref","unstructured":"Boehm, B.W.\n                (1988), \u201cA spiral model of software development and enhancement\u201d, Computer, Vol. 21 No. 5, pp. 61-72.","DOI":"10.1109\/2.59"},{"key":"key2020123003560978000_b11","doi-asserted-by":"crossref","unstructured":"Boehm, B.W.\n                (1991), \u201cSoftware risk management: principles and practices\u201d, Software, IEEE, Vol. 8 No. 1, pp. 32-41.","DOI":"10.1109\/52.62930"},{"key":"key2020123003560978000_b12","doi-asserted-by":"crossref","unstructured":"Boockholdt, J.L.\n                (1987), \u201cSecurity and integrity controls for microcomputers: a summary analysis\u201d, Information and Management, Vol. 13 No. 1, pp. 33-41.","DOI":"10.1016\/0378-7206(87)90028-0"},{"key":"key2020123003560978000_b13","doi-asserted-by":"crossref","unstructured":"Bulgurcu, B.\n               , \n                  Cavusoglu, H.\n                and \n                  Benbasat, I.\n                (2010), \u201cInformation security policy compliance: an empirical study of rationality-based beliefs and information security awareness\u201d, Mis Quarterly, Vol. 34 No. 3, pp. 523-548.","DOI":"10.2307\/25750690"},{"key":"key2020123003560978000_b85","unstructured":"Burrell, G.\n                and \n                  Morgan, G.\n                (1979), Sociological Paradigms and Organisational Analysis, Heinemann, London."},{"key":"key2020123003560978000_b86","unstructured":"Carnap, R.\n                (1991), \u201cEmpiricism, semantics, and ontology\u201d, The philosophy of science, pp. 85-98."},{"key":"key2020123003560978000_b16","unstructured":"Cockburn A. and Humans and Technology\n                (2003), \u201cSlide 1\/22. research methods in information systems research: \u201cMatching method to researcher\u201d, Alistair, available at: cockburn.us\/images\/Researchmethodsinisresearch045.ppt"},{"key":"key2020123003560978000_b17","doi-asserted-by":"crossref","unstructured":"Culnan, M.J.\n                (1987), \u201cMapping the intellectual structure of MIS, 1980-1985: a co-citation analysis\u201d, Mis Quarterly, Vol. 11 No. 3, pp. 341-353.","DOI":"10.2307\/248680"},{"key":"key2020123003560978000_b19","doi-asserted-by":"crossref","unstructured":"Dhillon, G.\n                and \n                  Backhouse, J.\n                (2000), \u201cTechnical opinion: information system security management in the new millennium\u201d, Communications of the ACM, Vol. 43 No. 7, pp. 125-128.","DOI":"10.1145\/341852.341877"},{"key":"key2020123003560978000_b18","doi-asserted-by":"crossref","unstructured":"Dhillon, G.\n                and \n                  Torkzadeh, G.\n                (2006), \u201cValue-focused assessment of information system security in organizations\u201d, Information Systems Journal, Vol. 16 No. 3, pp. 293-314.","DOI":"10.1111\/j.1365-2575.2006.00219.x"},{"key":"key2020123003560978000_b20","unstructured":"Dinev, T.\n                and \n                  Hu, Q.\n                (2007), \u201cThe centrality of awareness in the formation of user behavioral intention toward protective information technologies\u201d, Journal of the Association for Information Systems, Vol. 8 No. 23."},{"key":"key2020123003560978000_b21","doi-asserted-by":"crossref","unstructured":"Doddrell, G.\n                (1996), \u201cExtinguishing halons\u201d, Information Management and Computer Security, Vol. 4 No. 1, pp. 38-42.","DOI":"10.1108\/09685229610114196"},{"key":"key2020123003560978000_b22","doi-asserted-by":"crossref","unstructured":"Eloff, J.H.\n               , \n                  Holbein, R.\n                and \n                  Teufel, S.\n                (1996), \u201cSecurity classification for documents\u201d, Computers and Security, Vol. 15 No. 1, pp. 55-71.","DOI":"10.1016\/0167-4048(95)00023-2"},{"key":"key2020123003560978000_b23","unstructured":"Endnote X6\n                (2013), \u201cEssential EndNote Web\u201d Retrieved on March January 2013, available at: http:\/\/endnote.com\/support\/helpdocs\/EndNoteX6WinHelp.pdf"},{"key":"key2020123003560978000_b24","unstructured":"Ernst & Young LLP\n                (2002), Global Information Security Survey, Presentation Services, London."},{"key":"key2020123003560978000_b25","doi-asserted-by":"crossref","unstructured":"Ferraiolo, D.F.\n               , \n                  Sandhu, R.\n               , \n                  Gavrila, S.\n               , \n                  Kuhn, D.R.\n                and \n                  Chandramouli, R.\n                (2001), \u201cProposed NIST standard for role-based access control\u201d, ACM Transactions on Information and System Security (TISSEC), Vol. 4 No. 3, pp. 224-274.","DOI":"10.1145\/501978.501980"},{"key":"key2020123003560978000_b26","unstructured":"Galliers, R.D.\n                (1992), \u201cChoosing information systems research approaches\u201d, In \n                  Galliers, R.D.\n                (Ed), Information Systems Research: Issues, Methods and Practical Guidelines, Blackwell Scientific, Oxford, p. -."},{"key":"key2020123003560978000_b27","doi-asserted-by":"crossref","unstructured":"Gibson, G.\n                (1996), \u201cAn introduction to seismology\u201d, Information Management and Computer Security, Vol. 4 No. 3, pp. 20-25.","DOI":"10.1108\/09685229610126959"},{"key":"key2020123003560978000_b28","doi-asserted-by":"crossref","unstructured":"Gordon, L. A.\n               , \n                  Loeb, M.P.\n                and \n                  Sohail, T.\n                (2010), \u201cMarket value of voluntary disclosures concerning information security\u201d, Mis Quarterly, Vol. 34 No. 3, pp. 567-594.","DOI":"10.2307\/25750692"},{"key":"key2020123003560978000_b29","doi-asserted-by":"crossref","unstructured":"Gupta, A.\n                and \n                  Zhdanov, D.\n                (2012), \u201cGrowth and sustainability of managed security services networks: an economic perspective\u201d, Mis Quarterly, Vol. 36 No. 4, pp. 1109-1130.","DOI":"10.2307\/41703500"},{"key":"key2020123003560978000_b30","doi-asserted-by":"crossref","unstructured":"Harrington, S.J.\n                (1996), \u201cThe effect of codes of ethics and personal denial of responsibility on computer abuse judgments and intentions\u201d, Mis Quarterly, Vol. 20 No. 3, pp. 257-278.","DOI":"10.2307\/249656"},{"key":"key2020123003560978000_b31","unstructured":"Harzing, A.W.\n                (2007), \u201cPublish or perish\u201d, available at: www.harzing.com\/pop.htm"},{"key":"key2020123003560978000_b32","unstructured":"Hempe\u00ee, C.G.\n                (1965), Aspects of scientific explanation: and other essays in the philosophy of science, Free Press."},{"key":"key2020123003560978000_b33","doi-asserted-by":"crossref","unstructured":"Henderson, J.\n                (2005), \u201cGoogle scholar: a source for clinicians?\u201d, Canadian Medical Association Journal, Vol. 172 No. 12, pp. 1549-1550.","DOI":"10.1503\/cmaj.050404"},{"key":"key2020123003560978000_b34","doi-asserted-by":"crossref","unstructured":"Herath, T.\n                and \n                  Rao, H.R.\n                (2009), \u201cProtection motivation and deterrence: a framework for security policy compliance in organisations\u201d, European Journal of Information Systems, Vol. 18 No. 2, pp. 106-125.","DOI":"10.1057\/ejis.2009.6"},{"key":"key2020123003560978000_b87","doi-asserted-by":"crossref","unstructured":"Hinde, S.\n                (2002), \u201cThe perils of privacy\u201d, Computers & Security, Vol. 21, pp. 424-432.","DOI":"10.1016\/S0167-4048(02)00508-4"},{"key":"key2020123003560978000_b35","doi-asserted-by":"crossref","unstructured":"Hirschheim, R.\n                and \n                  Klein, H.K.\n                (1989), \u201cFour paradigms of information systems development\u201d, Communications of the ACM, Vol. 32 No. 10, pp. 1199-1216.","DOI":"10.1145\/67933.67937"},{"key":"key2020123003560978000_b36","doi-asserted-by":"crossref","unstructured":"Hirschheim, R.\n               , \n                  Klein, H.K.\n                and \n                  Lyytinen, K.\n                (1995), Information Systems Development and Data Modeling: Conceptual and Philosophical Foundations, Cambridge University Press, New York, NY.","DOI":"10.1017\/CBO9780511895425"},{"key":"key2020123003560978000_b37","doi-asserted-by":"crossref","unstructured":"Hirschheim, R.\n               , \n                  Klein, H.K.\n                and \n                  Lyytinen, K.\n                (1996), \u201cExploring the intellectual structures of information systems development: a social action theoretic analysis\u201d, Accounting, Management and Information Technologies, Vol. 6 Nos 1\/2, pp. 1-64.","DOI":"10.1016\/0959-8022(96)00004-5"},{"key":"key2020123003560978000_b38","doi-asserted-by":"crossref","unstructured":"Horn, R.L.V.\n                (1973), \u201cEmpirical studies of management information systems\u201d, Data Base, Vol. 5 No. 4, pp. 172-182.","DOI":"10.1145\/2579442.2579457"},{"key":"key2020123003560978000_b39","doi-asserted-by":"crossref","unstructured":"Hsu, C.\n               , \n                  Lee, J.-N.\n                and \n                  Straub, D.W.\n                (2012), \u201cInstitutional influences on information systems security innovations\u201d, Information Systems Research, Vol. 23 Nos 3\/2, pp. 918-939.","DOI":"10.1287\/isre.1110.0393"},{"key":"key2020123003560978000_b40","doi-asserted-by":"crossref","unstructured":"Hui, W.\n                (2010), \u201cBrand, knowledge, and false sense of security\u201d, Information Management and Computer Security, Vol. 18 No. 3, pp. 162-172.","DOI":"10.1108\/09685221011064690"},{"key":"key2020123003560978000_b41","doi-asserted-by":"crossref","unstructured":"Iivari, J.\n               , \n                  Hirschheim, R.\n                and \n                  Klein, H.K.\n                (1998), \u201cA paradigmatic analysis contrasting information systems development approaches and methodologies\u201d, Information Systems Research, Vol. 9 No. 2, pp. 164-193.","DOI":"10.1287\/isre.9.2.164"},{"key":"key2020123003560978000_b42","doi-asserted-by":"crossref","unstructured":"Iivari, J.\n               , \n                  Hirschheim, R.\n                and \n                  Klein, H.K.\n                (2001), \u201cA dynamic framework for classifying information systems development methodologies and approaches\u201d, Journals of Management Information Systems, Vol. 17 No. 3, pp. 179-218.","DOI":"10.1080\/07421222.2000.11045656"},{"key":"key2020123003560978000_b43","doi-asserted-by":"crossref","unstructured":"Iivari, J.\n               , \n                  Hirschheim, R.\n                and \n                  Klein, H.K.\n                (2004), \u201cTowards a distinctive body of knowledge for information systems experts: coding ISD process knowledge in two IS journals\u201d, Information Systems Journal, Vol. 14 No. 4, pp. 313-342.","DOI":"10.1111\/j.1365-2575.2004.00177.x"},{"key":"key2020123003560978000_b44","doi-asserted-by":"crossref","unstructured":"Koh, C.E.\n                and \n                  Watson, H.J.\n                (1998), \u201cData management in executive information systems\u201d, Information and Management, Vol. 33 No. 6, pp. 301-312.","DOI":"10.1016\/S0378-7206(98)00035-4"},{"key":"key2020123003560978000_b88","unstructured":"Kuhn, T.S.\n                (1962), The structure of Scientific Revolutions, University of Chicago Press, Chicago."},{"key":"key2020123003560978000_b45","unstructured":"Kuhn, T.S.\n                (1970), The Structure of Scientific Revolutions, 2nd ed., University of Chicago Press, Chicago."},{"key":"key2020123003560978000_b46","doi-asserted-by":"crossref","unstructured":"Lakatos, I.\n               , \n                  Worrall, J.\n                and \n                  Currie, G.\n                (1978), The Methodology of Scientific Research Programmes, Cambridge University Press, Cambridge.","DOI":"10.1017\/CBO9780511621123"},{"key":"key2020123003560978000_b47","doi-asserted-by":"crossref","unstructured":"Larson, K.D.\n                (1998), \u201cThe role of service level agreements in IT service delivery\u201d, Information Management and Computer Security, Vol. 6 No. 3, pp. 128-132.","DOI":"10.1108\/09685229810225029"},{"key":"key2020123003560978000_b48","unstructured":"Laudan, L.\n                (1984), Science and Values, Cambridge University Press, Cambridge."},{"key":"key2020123003560978000_b49","doi-asserted-by":"crossref","unstructured":"Levy, Y.\n                and \n                  Ellis, T.J.\n                (2006), \u201cA systems approach to conduct an effective literature review in support of information systems research\u201d, Informing Science: International Journal of an Emerging Transdiscipline, Vol. 9 No. 1, pp. 181-212.","DOI":"10.28945\/479"},{"key":"key2020123003560978000_b50","doi-asserted-by":"crossref","unstructured":"Li, H.\n               , \n                  Zhang, J.\n                and \n                  Sarathy, R.\n                (2010), \u201cUnderstanding compliance with internet use policy from the perspective of rational choice theory\u201d, Decision Support Systems, Vol. 48 No. 4, pp. 635-645.","DOI":"10.1016\/j.dss.2009.12.005"},{"key":"key2020123003560978000_b52","doi-asserted-by":"crossref","unstructured":"Mahmood, M.A.\n               , \n                  Siponen, M.\n               , \n                  Straub, D.\n               , \n                  Rao, H.R.\n                and \n                  Raghu, T.\n                (2010), \u201cMoving toward black hat research in information systems security: an editorial introduction to the special issue\u201d, Mis Quarterly, Vol. 34 No. 3, pp. 431-433.","DOI":"10.2307\/25750685"},{"key":"key2020123003560978000_b53","doi-asserted-by":"crossref","unstructured":"Malhotra, N.K.\n               , \n                  Kim, S.S.\n                and \n                  Agarwal, J.\n                (2004), \u201cInternet users\u2019 information privacy concerns (IUIPC): the construct, the scale, and a causal model\u201d, Information Systems Research, Vol. 15 No. 4, pp. 336-355.","DOI":"10.1287\/isre.1040.0032"},{"key":"key2020123003560978000_b89","unstructured":"McAfee\n               . (2012), available at: www.mcafee.com\/us\/resources\/reports\/rp-quarterly-threat-q2-2012.pdf (accessed June 2013)."},{"key":"key2020123003560978000_b54","doi-asserted-by":"crossref","unstructured":"Moore, D.\n               , \n                  Shannon, C.\n               , \n                  Brown, D.J.\n               , \n                  Voelker, G.M.\n                and \n                  Savage, S.\n                (2006), \u201cInferring internet denial-of-service activity\u201d, ACM Transactions on Computer Systems (TOCS), Vol. 24 No. 2, pp. 115-139.","DOI":"10.1145\/1132026.1132027"},{"key":"key2020123003560978000_b55","doi-asserted-by":"crossref","unstructured":"Nunamaker, J.F.Jr.\n                and \n                  Chen, M.\n                (1990), \u201cSystems development in information systems research\u201d,  Proceedings of the Twenty-Third Annual Hawaii International Conference on System Sciences, IEEE, pp. 631-640.","DOI":"10.1109\/HICSS.1990.205401"},{"key":"key2020123003560978000_b56","unstructured":"Peffers, K.\n                and \n                  Ya, T.\n                (2003), \u201cIdentifying and evaluating the universe of outlets for information systems research: ranking the journals\u201d, Journal of Information Technology Theory and Application, Vol. 5 No. 1, pp. 63-84."},{"key":"key2020123003560978000_b57","doi-asserted-by":"crossref","unstructured":"Peltier, T.R.\n                (2005), Information Security Risk Analysis, CRC press, United States.","DOI":"10.1201\/9781420031195"},{"key":"key2020123003560978000_b58","unstructured":"Popper, K.\n                (2002), The Logic of Scientific Discovery, Routledge, United Kingdom."},{"key":"key2020123003560978000_b59","doi-asserted-by":"crossref","unstructured":"Puhakainen, P.\n                and \n                  Siponen, M.\n                (2010), \u201cImproving employees\u2019 compliance through information systems security training: an action research study\u201d, Mis Quarterly, Vol. 34 No. 4, pp. 757-778.","DOI":"10.2307\/25750704"},{"key":"key2020123003560978000_b60","doi-asserted-by":"crossref","unstructured":"Ranganathan, C.\n                and \n                  Ganapathy, S.\n                (2002), \u201cKey dimensions of business-to-consumer web sites\u201d, Information and Management, Vol. 39 No. 6, pp. 457-465.","DOI":"10.1016\/S0378-7206(01)00112-4"},{"key":"key2020123003560978000_b61","unstructured":"Reichenbach, H.\n                (1938), Experience and Prediction: An Analysis of the Foundations and the Structure of Knowledge, University of Chicago Press, United States."},{"key":"key2020123003560978000_b62","doi-asserted-by":"crossref","unstructured":"Sandhu, R.S.\n               , \n                  Coyne, E.J.\n               , \n                  Feinstein, H.L.\n                and \n                  Youman, C.E.\n                (1996), \u201cRole-based access control models\u201d, Computer, Vol. 29 No. 2, pp. 38-47.","DOI":"10.1109\/2.485845"},{"key":"key2020123003560978000_b63","unstructured":"Shanks, G.\n               , \n                  Arnott, D.\n                and \n                  Rouse, A.\n                (1993), A Review of Approaches to Research and Scholarship in Information Systems, Department of Information Systems, Faculty of Computing and Information Technology, Monash University."},{"key":"key2020123003560978000_b64","doi-asserted-by":"crossref","unstructured":"Siponen, M.\n                and \n                  Vance, A.\n                (2010), \u201cNeutralization: new insights into the problem of employee information systems security policy violations\u201d, Mis Quarterly, Vol. 34 No. 3, pp. 487-502.","DOI":"10.2307\/25750688"},{"key":"key2020123003560978000_b80","unstructured":"Siponen, M.\n                and \n                  Willison, R.\n                (2007), \u201cA critical assessment of IS security research between 1990- 2004\u201d, Proceedings of 15th European Conference on ISs, St. Gallen, pp. 1551-1559."},{"key":"key2020123003560978000_b67","doi-asserted-by":"crossref","unstructured":"Straub, D.W.\n                (1990), \u201cEffective IS security: an empirical study\u201d, Information Systems Research, Vol. 1 No. 3, pp. 255-276.","DOI":"10.1287\/isre.1.3.255"},{"key":"key2020123003560978000_b66","doi-asserted-by":"crossref","unstructured":"Straub, D.W.Jr.\n                and \n                  Nance, W.D.\n                (1990), \u201cDiscovering and disciplining computer abuse in organizations: a field study\u201d, Mis Quarterly, Vol. 14 No. 1, pp. 45-60.","DOI":"10.2307\/249307"},{"key":"key2020123003560978000_b68","doi-asserted-by":"crossref","unstructured":"Straub, D.W.\n                and \n                  Welke, R.J.\n                (1998), \u201cCoping with systems risk: security planning models for management decision making\u201d, Mis Quarterly, Vol. 4, pp. 441-469.","DOI":"10.2307\/249551"},{"key":"key2020123003560978000_b69","doi-asserted-by":"crossref","unstructured":"Suki, N.M.\n               , \n                  Ramayah, T.\n                and \n                  Suki, N.M.\n                (2011), \u201cUnderstanding consumer intention with respect to purchase and use of pirated software\u201d, Information Management and Computer Security, Vol. 19 No. 3, pp. 195-210.","DOI":"10.1108\/09685221111153564"},{"key":"key2020123003560978000_b70","doi-asserted-by":"crossref","unstructured":"Sweeney, L.\n                (2002), \u201ck-anonymity: a model for protecting privacy\u201d, International Journal of Uncertainty, Fuzziness and Knowledge-Based Systems, Vol. 10 No. 5, pp. 557-570.","DOI":"10.1142\/S0218488502001648"},{"key":"key2020123003560978000_b71","doi-asserted-by":"crossref","unstructured":"Tan, M.\n                and \n                  Teo, T.S.\n                (2000), \u201cFactors influencing the adoption of Internet banking\u201d, Journal of the Association of Information System, Vol. 1, No. 5.","DOI":"10.17705\/1jais.00005"},{"key":"key2020123003560978000_b90","doi-asserted-by":"crossref","unstructured":"Thompson, D.\n                (1998), \u201c1997 computer crime and security survey\u201d, Information Management & Computer Security, Vol. 6, pp. 78-101.","DOI":"10.1108\/09685229810209414"},{"key":"key2020123003560978000_b72","doi-asserted-by":"crossref","unstructured":"Vogel, D.R.\n                and \n                  Wetherbe, J.C.\n                (1984), \u201cMIS research: a profile of leading journals and universities\u201d, ACM SIGMIS Database, Vol. 16 No. 1, pp. 3-14.","DOI":"10.1145\/1113511.1113512"},{"key":"key2020123003560978000_b73","unstructured":"Vom Brocke, J.\n               , \n                  Simons, A.\n               , \n                  Niehaves, B.\n               , \n                  Riemer, K.\n               , \n                  Plattfaut, R.\n                and \n                  Cleven, A.\n                (2009), \u201cReconstructing the giant: on the importance of rigour in documenting the literature search process\u201d, European Conference On Information Systems (ECIS), pp. 2206-2217."},{"key":"key2020123003560978000_b75","doi-asserted-by":"crossref","unstructured":"Von Krogh, G.\n               , \n                  Haefliger, S.\n               , \n                  Spaeth, S.\n                and \n                  Wallin, M.W.\n                (2012), \u201cCarrots and rainbows: motivation and social practice in open source software development\u201d, Mis Quarterly, Vol. 36 No. 2, pp. 649-676.","DOI":"10.2307\/41703471"},{"key":"key2020123003560978000_b76","doi-asserted-by":"crossref","unstructured":"Von Solms, R.\n                (1999), \u201cInformation security management: why standards are important\u201d, Information Management and Computer Security, Vol. 7 No. 1, pp. 50-58.","DOI":"10.1108\/09685229910255223"},{"key":"key2020123003560978000_b77","doi-asserted-by":"crossref","unstructured":"Von Solms, R.\n               , \n                  Van Der Haar, H.\n               , \n                  Von Solms, S.H.\n                and \n                  Caelli, W.J.\n                (1994), \u201cA framework for information security evaluation\u201d, Information and Management, Vol. 26 No. 3, pp. 143-153.","DOI":"10.1016\/0378-7206(94)90038-8"},{"key":"key2020123003560978000_b91","unstructured":"Webster, J.\n                and \n                  Watson, R.T.\n                (2002), \u201cAnalyzing the past to prepare\u201d, MIS quarterly, Vol. 26, pp. 13-23."},{"key":"key2020123003560978000_b78","doi-asserted-by":"crossref","unstructured":"Whybrow, M.\n                (1995), \u201cBridging the gaps\u201d, Information Management and Computer Security, Vol. 3 No. 1, pp. 4-6.","DOI":"10.1108\/09685229510088205"},{"key":"key2020123003560978000_b79","doi-asserted-by":"crossref","unstructured":"Wiederhold, G.\n                (1992), \u201cMediators in the architecture of future information systems\u201d, Computer, Vol. 25 No. 3, pp. 38-49.","DOI":"10.1109\/2.121508"},{"key":"key2020123003560978000_b81","doi-asserted-by":"crossref","unstructured":"Wong, P.W.\n                and \n                  Memon, N.\n                (2001), \u201cSecret and public key image watermarking schemes for image authentication and ownership verification\u201d, IEEE Transactions on Image Processing, Vol. 10 No. 10, pp. 1593-1601.","DOI":"10.1109\/83.951543"},{"key":"key2020123003560978000_b82","doi-asserted-by":"crossref","unstructured":"Ye, W.\n               , \n                  Heidemann, J.\n                and \n                  Estrin, D.\n                (2004), \u201cMedium access control with coordinated adaptive sleeping for wireless sensor networks\u201d, IEEE\/ACM Transactions on Networking, Vol. 12 No. 3, pp. 493-506.","DOI":"10.1109\/TNET.2004.828953"},{"key":"key2020123003560978000_b92","doi-asserted-by":"crossref","unstructured":"Zafar, H.\n                and \n                  Clark, J.G.\n                (2009), \u201cCurrent State of Information Security Research In IS.\u201d, Communications of the Association for Information Systems, Vol. 24 No. 1, p -.","DOI":"10.17705\/1CAIS.02434"},{"key":"key2020123003560978000_b83","unstructured":"Zhang, P.\n                and \n                  Li, N.\n                (2005), \u201cThe intellectual development of Human-Computer Interaction research: a critical assessment of the MIS literature (1990-2002)\u201d, Journal of the Association for Information Systems, Vol. 6 No. 6, pp. 227-292."},{"key":"key2020123003560978000_frd1","doi-asserted-by":"crossref","unstructured":"Appari, A.\n                and \n                  Johnson, M.E.\n                (2010), \u201cInformation security and privacy in healthcare: current state of research\u201d, International Journal of Internet and Enterprise Management, Vol. 6 No. 4, pp. 279-314.","DOI":"10.1504\/IJIEM.2010.035624"},{"key":"key2020123003560978000_frd2","doi-asserted-by":"crossref","unstructured":"Banks, M.A.\n                (2005), \u201cThe excitement of Google scholar, the worry of Google print\u201d, Biomedical Digital Libraries, Vol. 2 No. 1, p. -.","DOI":"10.1186\/1742-5581-2-2"},{"key":"key2020123003560978000_frd3","unstructured":"Burrell, G.\n                and \n                  Morgan, G.\n                (1979), Sociological Paradigms and Organisational Analysis, Heinemann, United Kingdom."},{"key":"key2020123003560978000_frd4","unstructured":"Carnap, R.\n                (1991), \u201cEmpiricism, semantics, and ontology\u201d, The Philosophy of Science, pp. 85-98."},{"key":"key2020123003560978000_frd5","doi-asserted-by":"crossref","unstructured":"Loch, K.D.\n               , \n                  Carr, H.H.\n                and \n                  Warkentin, M.E.\n                (1992), \u201cThreats to information systems: today\u2019s reality, yesterday\u2019s understanding\u201d, Mis Quarterly, Vol. 16 No. 2, pp. 173-186.","DOI":"10.2307\/249574"},{"key":"key2020123003560978000_frd6","doi-asserted-by":"crossref","unstructured":"Stafford, T.F.\n                and \n                  Urbaczewski, A.\n                (2004), \u201cSpyware: the ghost in the machine\u201d, Communications of the Association for Information Systems, Vol. 14 No. 15, pp. 291-306.","DOI":"10.17705\/1CAIS.01415"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/IMCS-05-2013-0041","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMCS-05-2013-0041\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/IMCS-05-2013-0041\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T21:50:46Z","timestamp":1753393846000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/22\/3\/279-308\/183823"}},"subtitle":["Critical review and future directions for research"],"short-title":[],"issued":{"date-parts":[[2014,7,8]]},"references-count":91,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2014,7,8]]}},"alternative-id":["10.1108\/IMCS-05-2013-0041"],"URL":"https:\/\/doi.org\/10.1108\/imcs-05-2013-0041","relation":{},"ISSN":["0968-5227"],"issn-type":[{"type":"print","value":"0968-5227"}],"subject":[],"published":{"date-parts":[[2014,7,8]]}}}