Unravelling the three lines model in cybersecurity: a systematic literature review

被引:2
|
作者
Valkenburg, Bert [1 ]
Bongiovanni, Ivano [2 ]
机构
[1] Univ Queensland, Brisbane 4072, Australia
[2] Univ Queensland, Sch Business, Brisbane 4072, Australia
关键词
Three lines model; Cybersecurity governance; Risk management; Literature Review; Grounded Theory; Compliance; CHIEF INFORMATION SECURITY; MANAGEMENT; FRAMEWORK; DEFENSE;
D O I
10.1016/j.cose.2024.103708
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise risk management frameworks have gained popularity after the Global Financial Crisis for companies to be more in control of their risks. Since then, the Three Lines of Defence model (based on defence-in-depth approaches) has become one of the primary risk management frameworks in the Western world. Yet, its application in the cybersecurity space, one of the fastest-growing areas of risk for modern organisations, has been fragmented at best. In this article, we conducted a systematic literature review on the application of the Three Lines of Defence model in cybersecurity. The model has been recently renamed the Three Lines Model. After the seminal publication by the Institute of Internal Auditors in 2013, academics and practitioners have either referenced this model as the primary governance framework for risk management or analysed it in depth in various areas. To the best of our knowledge, this is the first systematic literature review on the topic. We have performed a methodical analysis of existing research using best practices in the field and adopted the grounded theory approach as the theoretical underpinning of our investigation. This way, we unraveled details, critiques and possible alternatives to the Three Lines Model in cybersecurity. Our study expands our understanding of the Three Lines Model and its application in cybersecurity, highlighting the status quo of research in the space and offering practical recommendations for organisations interested in exploring its implementation to mitigate the impact of cyber-risks.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] A pathway model to five lines of accountability in cybersecurity governance
    Slapnicar, Sergeja
    Axelsen, Micheal
    Bongiovanni, Ivano
    Stockdale, David
    INTERNATIONAL JOURNAL OF ACCOUNTING INFORMATION SYSTEMS, 2023, 51
  • [32] INNOVATION CHAMPIONS AND SUSTAINABLE DEVELOPMENT PROJECTS: SYSTEMATIC LITERATURE REVIEW AND INTEGRATIVE MODEL
    Hassan, Afaf kamal mahadi
    INTERNATIONAL JOURNAL OF INNOVATION MANAGEMENT, 2024, 28 (01N02)
  • [33] The Consideration of Diversity in the Accounting Literature: A Systematic Literature Review
    Ghio, Alessandro
    Occhipinti, Zeila
    Verona, Roberto
    EUROPEAN ACCOUNTING REVIEW, 2024, 33 (05) : 1667 - 1691
  • [34] Construction supply chain: a systematic literature review with bibliometric analysis
    Singh, Navdeep
    Ashish, Deepankar Kumar
    Dixit, Anuj
    JOURNAL OF GLOBAL OPERATIONS AND STRATEGIC SOURCING, 2024,
  • [35] Towards a Comprehensive Systematic Innovation Model: A Literature review
    Kruger, Louis L. S. J.
    Pretorius, Jan Harm C.
    Erasmus, Louwrence D.
    SAIEE AFRICA RESEARCH JOURNAL, 2019, 110 (01): : 39 - 45
  • [36] Artificial intelligence maturity model: a systematic literature review
    Sadiq, Raghad Baker
    Safie, Nurhizam
    Rahman, Abdul Hadi Abd
    Goudarzi, Shidrokh
    PEERJ COMPUTER SCIENCE, 2021, 7 : 1 - 27
  • [37] FOOD WASTE AND PERFORMANCE MEASUREMENT SYSTEMS: A SYSTEMATIC REVIEW OF THE LITERATURE
    Amorim Santos, Paulo Henrique
    Martins, Roberto Antonio
    RAE-REVISTA DE ADMINISTRACAO DE EMPRESAS, 2021, 61 (05):
  • [38] Women Entrepreneurship: A Systematic Review to Outline the Boundaries of Scientific Literature
    Cardella, Giuseppina Maria
    Hernandez-Sanchez, Brizeida Raquel
    Sanchez-Garcia, Jose Carlos
    FRONTIERS IN PSYCHOLOGY, 2020, 11
  • [39] Business Model Archetypes. A Systematic Literature Review
    Madsen, Rita
    Lindgren, Peter
    Durst, Susanne
    2022 25TH INTERNATIONAL SYMPOSIUM ON WIRELESS PERSONAL MULTIMEDIA COMMUNICATIONS (WPMC), 2022,
  • [40] Intelligent Warehouse in Industry 4.0-Systematic Literature Review
    Tubis, Agnieszka A.
    Rohman, Juni
    SENSORS, 2023, 23 (08)