Unravelling the three lines model in cybersecurity: a systematic literature review

被引:2
|
作者
Valkenburg, Bert [1 ]
Bongiovanni, Ivano [2 ]
机构
[1] Univ Queensland, Brisbane 4072, Australia
[2] Univ Queensland, Sch Business, Brisbane 4072, Australia
关键词
Three lines model; Cybersecurity governance; Risk management; Literature Review; Grounded Theory; Compliance; CHIEF INFORMATION SECURITY; MANAGEMENT; FRAMEWORK; DEFENSE;
D O I
10.1016/j.cose.2024.103708
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise risk management frameworks have gained popularity after the Global Financial Crisis for companies to be more in control of their risks. Since then, the Three Lines of Defence model (based on defence-in-depth approaches) has become one of the primary risk management frameworks in the Western world. Yet, its application in the cybersecurity space, one of the fastest-growing areas of risk for modern organisations, has been fragmented at best. In this article, we conducted a systematic literature review on the application of the Three Lines of Defence model in cybersecurity. The model has been recently renamed the Three Lines Model. After the seminal publication by the Institute of Internal Auditors in 2013, academics and practitioners have either referenced this model as the primary governance framework for risk management or analysed it in depth in various areas. To the best of our knowledge, this is the first systematic literature review on the topic. We have performed a methodical analysis of existing research using best practices in the field and adopted the grounded theory approach as the theoretical underpinning of our investigation. This way, we unraveled details, critiques and possible alternatives to the Three Lines Model in cybersecurity. Our study expands our understanding of the Three Lines Model and its application in cybersecurity, highlighting the status quo of research in the space and offering practical recommendations for organisations interested in exploring its implementation to mitigate the impact of cyber-risks.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Crossing the lines a human approach to improving the effectiveness of the three lines model in practice
    Fenelon, Morgan
    van Doorn, Juliette
    Scholten, Wieke
    JOURNAL OF FINANCIAL REGULATION AND COMPLIANCE, 2024, 32 (05) : 620 - 632
  • [22] Educational business model: a systematic review of literature
    Duarte, Gwendole Ramos
    Behr, Ariel
    REVISTA DE GESTAO E PROJETOS, 2018, 9 (03): : 95 - 112
  • [23] Business Model Innovation: A Systematic Literature Review
    Kraus, Sascha
    Filser, Matthias
    Puumalainen, Kaisu
    Kailer, Norbert
    Thurner, Selina
    INTERNATIONAL JOURNAL OF INNOVATION AND TECHNOLOGY MANAGEMENT, 2020, 17 (06)
  • [24] Understanding Big Data Through a Systematic Literature Review: The ITMI Model
    De Mauro, Andrea
    Greco, Marco
    Grimaldi, Michele
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY & DECISION MAKING, 2019, 18 (04) : 1433 - 1461
  • [25] Sustainability Indicators for Industrial Organizations: Systematic Review of Literature
    Feil, Alexandre Andre
    Schreiber, Dusan
    Haetinger, Claus
    Strasburg, Virgilio Jose
    Barkert, Claudia Luisa
    SUSTAINABILITY, 2019, 11 (03)
  • [26] Shadow IT - A Systematic Literature Review
    Rakovic, Lazar
    Sakal, Marton
    Matkovic, Predrag
    Maric, Mirjana
    INFORMATION TECHNOLOGY AND CONTROL, 2020, 49 (01): : 144 - 160
  • [27] Two decades of cyberattack simulations: A systematic literature review
    Engstrom, Viktor
    Lagerstrom, Robert
    COMPUTERS & SECURITY, 2022, 116
  • [28] A systematic literature review of sociotechnical systems in systems engineering
    Polojaervi, Dana
    Palmer, Erika
    Dunford, Charlotte
    SYSTEMS ENGINEERING, 2023, 26 (04) : 482 - 504
  • [29] Service learning in higher education: a systematic literature review
    Salam, Maimoona
    Iskandar, Dayang Nurfatimah Awang
    Ibrahim, Dayang Hanani Abang
    Farooq, Muhammad Shoaib
    ASIA PACIFIC EDUCATION REVIEW, 2019, 20 (04) : 573 - 593
  • [30] Software Process Definition using Process Lines: A Systematic Literature Review
    Costa, Diogo Matheus
    Teixeira, Eldanae Nogueira
    Lima Werner, Claudia Maria
    2018 XLIV LATIN AMERICAN COMPUTER CONFERENCE (CLEI 2018), 2018, : 110 - 119