Information Security Risk Management: A Systematic Literature Review



Full text

Journal of Information System Security
Volume 15, Number 3 (2019)
Pages 161184
ISSN 1551-0123
Sérgio Nunes — ISEG, Universidade de Lisboa, Portugal
Information Institute Publishing, Washington DC, USA




Risk management can be the solution to minimize the communication gap between top management and information security specialists. There is a need to translate the technical jargon of information security into a language that top management is able to understand and take action. This research presents a systematic literature review of information security risk management. It consolidates and classifies the body of knowledge of information security risk management across multiple dimensions and finds gaps for further research.




Information Security, Risk Management, Cyber Risk




