Three lines model;
Cybersecurity governance;
Risk management;
Literature Review;
Grounded Theory;
Compliance;
CHIEF INFORMATION SECURITY;
MANAGEMENT;
FRAMEWORK;
DEFENSE;
D O I:
10.1016/j.cose.2024.103708
中图分类号:
TP [自动化技术、计算机技术];
学科分类号:
0812 ;
摘要:
Enterprise risk management frameworks have gained popularity after the Global Financial Crisis for companies to be more in control of their risks. Since then, the Three Lines of Defence model (based on defence-in-depth approaches) has become one of the primary risk management frameworks in the Western world. Yet, its application in the cybersecurity space, one of the fastest-growing areas of risk for modern organisations, has been fragmented at best. In this article, we conducted a systematic literature review on the application of the Three Lines of Defence model in cybersecurity. The model has been recently renamed the Three Lines Model. After the seminal publication by the Institute of Internal Auditors in 2013, academics and practitioners have either referenced this model as the primary governance framework for risk management or analysed it in depth in various areas. To the best of our knowledge, this is the first systematic literature review on the topic. We have performed a methodical analysis of existing research using best practices in the field and adopted the grounded theory approach as the theoretical underpinning of our investigation. This way, we unraveled details, critiques and possible alternatives to the Three Lines Model in cybersecurity. Our study expands our understanding of the Three Lines Model and its application in cybersecurity, highlighting the status quo of research in the space and offering practical recommendations for organisations interested in exploring its implementation to mitigate the impact of cyber-risks.
机构:
Galatasaray Univ, Ind Engn Dept, Ciragan Cd 36, TR-34349 Ortakoy Istanbul, TurkiyeGalatasaray Univ, Ind Engn Dept, Ciragan Cd 36, TR-34349 Ortakoy Istanbul, Turkiye
Buyukozkan, Gulcin
Guler, Merve
论文数: 0引用数: 0
h-index: 0
机构:
Galatasaray Univ, Ind Engn Dept, Ciragan Cd 36, TR-34349 Ortakoy Istanbul, TurkiyeGalatasaray Univ, Ind Engn Dept, Ciragan Cd 36, TR-34349 Ortakoy Istanbul, Turkiye
机构:
Corvinus Univ Budapest, Dept Business & Management, Budapest, HungaryCorvinus Univ Budapest, Dept Business & Management, Budapest, Hungary
Qerimi, Detrin
Demeter, Krisztina
论文数: 0引用数: 0
h-index: 0
机构:
Corvinus Univ Budapest, Dept Logist & Supply Chain Management, Budapest, Hungary
Babes Bolyai Univ, Fac Econ & Business Adm, Cluj Napoca, RomaniaCorvinus Univ Budapest, Dept Business & Management, Budapest, Hungary
Demeter, Krisztina
Losonci, David
论文数: 0引用数: 0
h-index: 0
机构:
Corvinus Univ Budapest, Dept Operat & Dec Sci, Budapest, HungaryCorvinus Univ Budapest, Dept Business & Management, Budapest, Hungary
机构:
Fundacao Getulio Vargas FGV EAESP, Sao Paulo Business Sch, Ave 9 Julho,2029 Bela Vista, BR-01313902 Sao Paulo, SP, BrazilFundacao Getulio Vargas FGV EAESP, Sao Paulo Business Sch, Ave 9 Julho,2029 Bela Vista, BR-01313902 Sao Paulo, SP, Brazil
Pigola, Angelica
Meirelles, Fernando de Souza
论文数: 0引用数: 0
h-index: 0
机构:
Fundacao Getulio Vargas FGV EAESP, Sao Paulo Business Sch, Ave 9 Julho,2029 Bela Vista, BR-01313902 Sao Paulo, SP, BrazilFundacao Getulio Vargas FGV EAESP, Sao Paulo Business Sch, Ave 9 Julho,2029 Bela Vista, BR-01313902 Sao Paulo, SP, Brazil