Paper title (Paper Title style) Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 1 Organisational Information Security Strategy: Review, Discussion and Future Research Craig A. Horne Department of Computing and Information Systems The University of Melbourne chorne@student.unimelb.edu.au Sean B. Maynard Department of Computing and Information Systems The University of Melbourne Atif Ahmad Department of Computing and Information Systems The University of Melbourne Abstract Dependence on information, including for some of the world’s largest organisations such as governments and multi-national corporations, has grown rapidly in recent years. However, reports of information security breaches and their associated consequences indicate that attacks are escalating on organisations conducting these information-based activities. Organisations need to formulate strategy to secure their information, however gaps exist in knowledge. Through a thematic review of academic security literature, (1) we analyse the antecedent conditions that motivate the adoption of a comprehensive information security strategy, (2) the conceptual elements of strategy and (3) the benefits that are enjoyed post- adoption. Our contributions include a definition of information security strategy that moves from an internally-focussed protection of information towards a strategic view that considers the organisation, its resources and capabilities, and its external environment. Our findings are then used to suggest future research directions.1 Keywords: Information security strategy; organisational strategy; security quality; strategic information systems; business management 1 Introduction Information resources play a critical role in sustaining business success by driving innovation and opportunities for the development of competitive advantage. As such, preservation of the confidentiality, integrity and availability of these information resources is a significant imperative, which begins with the development of an appropriate information security strategy in organisations (ISSiO). The aim of this paper is to identify a strategic approach to securing information resources for the benefit of those decision-makers accountable for strategic-level organisational information security and ultimately, organisational success. The scope of the research is to examine the conceptual construct of ISSiO. In particular, the authors of this paper are motivated by calls from other information systems researchers for the development of a comprehensive security strategic framework (Baskerville et al. 2014), and for future research into the role that boards of directors may play in information security practices (McFadzean et al. 2006). Significantly, some of the world’s largest organisations, including governments and multi- national corporations, have publicly suffered major information security incidents. By broadly 1 An earlier version of this article was published in proceedings at Australasian Conference on Information Systems 2015, see: Horne, C.A., Ahmad, A., and Maynard, S.B. 2015. "Information Security Strategy in Organisations: Review, Discussion and Future Research Directions," The 26th Australasian Conference on Information Systems, Adelaide, Australia. Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 2 reviewing the extant literature, a perspective is established that can support the development of a comprehensive ISSiO which might then be generalisable to all organisations. This paper is a critical literature review on the topic of ISSiO. Papers from various researchers were analysed and evaluated before being compared for depth of understanding and conclusions drawn. The paper commentary is explicative, interpretative and centres on the determination of the conceptual and theoretical nature of ISSiO. The paper continues in four major sections. Initially we introduce ISSiO, discuss its origins and existing definitions whilst expanding on some of its more central properties. Second, we review the construct space of ISSiO to understand how extant research views the way ISSiO is conceptualised, the level of analysis from which ISSiO is approached, and propositions for measuring the distinct elements of an ISSiO. Third, we review the nomological network space to assess the environmental antecedents, conceptual elements, and possible yields from an ISSiO. Finally, we draw conclusions, construct a definition, consider limitations and provide suggestions for future research to advance understanding of information security strategy. 2 Defining Information Security Strategy Definitions of ISSiO are infrequent in the information systems literature so, in an indulgent departure from convention, the discussion in this section is largely author-centric rather than concept-centric. Information security strategy is defined by Beebe and Rao (2010, pg. 330) as “the pattern or plan that integrates the organisation‘s major IS security goals, policies, and action sequences into a cohesive whole”. These authors assert ISSiO is a documented plan which matches an assessment of external cyber threats with a financially-informed set of internal countermeasures, including the required supporting policies and procedures. Strategy is seen as the means to influence an organisation’s environment through the careful selection of internal controls. Park and Ruighaver (2008, pg. 27) define information security strategy as: “an art of deciding how to best utilize what appropriate defensive information security technologies and measures, and of deploying and applying them in a coordinated way to defence organisation’s information infrastructure(s) against internal and external threats by offering confidentiality, integrity and availability at the expense of least efforts and costs while to be effective”. These authors assert ISSiO has been developed from the military literature and therefore tends to be focussed more on how to deploy strategies than focus on what goals the organisation is trying achieve. In terms of attempting to classify ISSiO, their analysis of earlier literature leads them to the conclusion that ISSiO balances three dimensions which are time, space and the decision-making process. Ahmad et al. (2014b) and Park and Ruighaver (2008) believe ISSiO can be used to incrementally improve the quality of the information security program, however there must be a strong link from the ISSiO to the organisational strategic plan to support it. ISSiO is necessary to prevent threats to an organisation’s information. ISSiO can take the form of one of a number of areas which include deterrence, prevention, surveillance, detection, response, deception, perimeter defence, compartmentalisation and layering. Senior business sponsorship of the security function is also required. Hong et al. (2003) do not define ISSiO per se but assert that it is a function of policy orientation, risk management orientation, control and auditing orientation, management systems orientation and contingency management. Contingency management is assessed by the authors as a function of the organisational environment, management and technology. Sveen et al. (2009) contend that an ISSiO is like any other business strategy: it is the process of building up resources. By simply explaining what an ISSiO is, Sveen et al. (2009) describe Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 3 the construct but have not provided a formal definition. Their insights are still useful however in building up our cumulative understanding. These definitions give an insight into the difficulties with achieving unanimity on defining ISSiO. Using conceptualisation of ISSiO as an example, Beebe and Rao (2010) explain it is a plan, Sveen et al. (2009) assert it is a process and conceptualisations from Park and Ruighaver (2008), Ahmad et al. (2014b) and Hong et al. (2003) do not fit within either of these. There are many other researchers who have used the term ‘information security strategy’ in their literature however they have not provided an explicit definition. These various definitions universally describe information security strategy as being an organisational-level construct, as opposed to individual, group or inter-organisational. This is in spite of there being implications for other levels, for example the role of individuals in the governance of information security strategy. This is consistent with definitions of strategy from reference disciplines such as military and business. In military literature, strategy is the highest level of planning, with the next level lower down termed operational, and tactical level below that (Bowdish 2013). The tactics, techniques and procedures at the lowest level support the achievement of operations, which then support a nation’s strategic goals at the highest level. At the strategic level, nations guide the facilitation and achievement of national goals and objectives, using critical infrastructure and other national resources to achieve them (Bowdish 2013). From the business literature, views on strategy abound (Drucker 1958; Mintzberg 1987), however in one of the most highly-cited strategic management books of the last century, three generic competitive strategies were identified: 1. differentiation, 2. overall cost leadership and 3. focus (Porter 1980). These generic competitive strategies form the basis of competitive advantage which drives profitability (widely defined as total revenue less total expenses) (Porter 1980). These strategies provide insight into how strategy is defined and used within the business domain and an explanation follows. Differentiation is achieved by creating the industry-wide perception that an organisation is unique, ideally in more than one way, which reduces buyer power due to less comparable alternatives, allowing margins to be increased (Porter 1980). Overall cost leadership is a focussed attempt to lower the cost of goods sold, relative to an organisation’s competitors, which is achieved through high market share or through favourable access to raw materials, resulting in a wider profit margin (Porter 1980). Focus concentrates sales efforts on a target market segment, rather than adopting an industry-wide approach, amplifying the effects of overall cost leadership through lower costs from servicing only a segment of the market, or differentiation by becoming known for servicing one particular market segment well (Porter 1980). These descriptions reveal strategy as an organisational-wide construct, which affects the direction and activities of the board and all staff in response to the competitive environment, in pursuit of a goal (profit). 2.1 Assumptions Underlying Strategy Strategy must take into account a complex set of internal and external conditions and so in this section, we seek to understand what assumptions are used to clarify these. Assumptions are a useful tool for mapping out causal relationships related to environmental and industry forces (Schwenk 1988). In doing so however, it must be remembered that strategists and others who engage in the strategy-setting process hold preconceived biases, built on previous experiences, which serve to expedite decision-making constrained by bounded rationality. These biases must also be identified as they affect the assumptions that are identified (Schwenk 1988). Assumptions increase our shared understanding of why organisations engage in development of strategy, orientate collective efforts made in setting a strategic direction and link the external environment to internal organisational strategy (Durand et al. 1996). Assumptions are also made explicit in order to ensure appropriate use of the resulting strategic construct and ensure its validity (Roberts et al. 2012). Assumptions are required because decisions are made without Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 4 complete certainty and so these gaps in knowledge are accounted for using assumptions (Schwenk 1988). 2.2 Information Security Strategy: Plan or Process? There are two main conceptualisations espoused by organisational scholars when describing ISSiO. These include (1) a static plan, described as an artefact to be shared amongst stakeholders (Beebe and Rao 2010; Bowen et al. 2006; Von Solms and Von Solms 2004), and (2) a dynamic process, to be followed by stakeholders concerned with protecting organisational information (Booker 2006; Brotby et al. 2006; Flores et al. 2014; McFadzean et al. 2006; Sveen et al. 2009; Van Niekerk and Von Solms 2010). A profound comprehension of these interpretations will shed light on how ISSiO should be understood. Some information systems researchers view ISSiO as a static plan: a central artefact to be developed that describes the linkages between various organisational concepts such as goals, policies and action sequences (Baskerville and Dhillon 2008; Beebe and Rao 2010). In a process orientation, ISSiO involves using a strategy-setting process, whilst incorporating the organisational information systems security goals, such as regulatory compliance, as input. This strategy-setting process can group actions taken according to either the end product ultimately derived such as a strategic security plan, or the processes required such as aligning ISSiO with organisational strategy (Baskerville and Dhillon 2008). Finally some information systems scholars do not conceptualise ISSiO at all or characterise it in abstract terms only (Hong et al. 2003; Park and Ruighaver 2008). 3 Information Security Strategy in Information Systems Research A number of information systems researchers have made individual contributions towards understanding ISSiO from various perspectives. The focus of these researchers was to address problems including adequate support for organisational strategic vision, information systems- business cohesiveness and coordination of information security efforts. However, a complete and methodical evaluation of ISSiO within the information systems literature has not been accomplished. Therefore our research seeks to firstly examine what information systems researchers have analysed about the ISSiO construct and secondly the ISSiO nomological network describing its various elements. The ISSiO construct denotes the theoretical domain of ISSiO, specifically how it is conceptualised, at what levels of analysis it can be stratified, and measurement proposals to ensure unit specificity. The ISSiO nomological network refers to our understanding of ISSiO phenomena in the information systems domain, captured through the completion of a thematic analysis. 3.1 Literature Review Our initial search for information security strategy was for manifestations of it in peer- reviewed information systems journals and selected conference proceedings, found through searching institutional repositories, Google Scholar and A* information systems journals. Our search consisted of articles that included the complete search string “information security strategy” in English. We searched backwards to discover prior articles and forwards for articles that cited seminal articles (Webster and Watson 2002). We did not restrict the search based on article age or grade of journal, preferring instead to examine each artefact found for nuances, no matter how small, which could shed light on our evolving understanding of the concept. We also included papers that referred to “information security” but included the word strategies (plural) instead, to facilitate an investigation for example into whether use of the singular ‘strategy’ or plural ‘strategies’ could indicate a shift in level of analysis within an organisation. Finally, we included papers that centred on information security but discussed an implicit aspect of strategy. Note that ‘organisation’ is a term used to denote private companies, public governments, not-for-profit societies and educational institutions. We included an international standard on information security (ISO/IEC 2013a), as we thought this could have important implications for motivating the use of an ISSiO. However we did not include any practice-oriented literature such as vendor white papers due to issues Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 5 with accessibility and peer-review process. In total, our literature review consisted of 45 papers. We then examined each paper to explore how ISSiO relates to the article’s core paradigm. The following four classifications stratify how central ISSiO is to each paper and is adapted from Roberts et al. (2012): 1. Implicit use of the term. Information security forms the paper’s central theme and strategy is implicit only. Information security strategy does not form the central argument of the paper, e.g. (Van Niekerk and Von Solms 2010). 2. Provides conceptual support. Papers use information security strategy to support the development of their concepts, e.g. (Flores et al. 2014). 3. Used in the research question or hypothesis. Papers use information security strategy explicitly in their findings or analysis, e.g. (Posthumus and von Solms 2004). 4. Forms the conceptual base for the paper. These papers are entirely consumed with the discussion of information security strategy, e.g. (Baskerville and Dhillon 2008). In summary, thirty five percent of articles (16 papers) that were collected implied some aspect of ISSiO when discussing information security. Twenty seven percent (12 articles) provided theoretical or conceptual support for developing the logic of ISSiO. Eighteen percent (8 articles) used ISSiO in some part of their hypothesis, research question or proposition. One fifth of articles (9 papers) were focussed purely on discovery of aspects relating to ISSiO. In the next section, we discuss the role of ISSiO in information systems research in more detail. 3.2 The Information Security Strategy Construct From the previous sections, it could be perceived that ISSiO has not been widely developed in the information systems literature so a more profound analysis is warranted. The following sections discuss in more detail ISSiO’s (1) conceptualisation, (2) levels of analysis and (3) measurement domain. 3.2.1 Conceptualisation We examined the distinctions that academics have made in their conceptualisation of the ISSiO construct. The three conceptualisations used for this construct are firstly plan, secondly process, and thirdly neither of these. Table 1 presents some conceptualisations (i.e. plans, processes, or neither conceptualisation) and the role of ISSiO in the information systems literature. Out of the forty five articles that were examined, twenty percent (9 papers) used ISSiO as the core of the entire article. Seventy eight percent (35 papers) gave neither explicit conceptualisation of ISSiO. In terms of patterns, when ISSiO is used in the research question (row 3) or forms the theoretical basis for the paper (row4), it becomes apparent that ISSiO is largely viewed by information systems authors as neither plan nor process. Plan Process Neither Plan nor Process Total 1. Implicit use of the term 1 1 14 16 2. Provides conceptual support 1 3 8 12 3. Used in research question or hypothesis 0 1 7 8 4. Forms theoretical basis for paper 1 2 6 9 Total 3 7 35 45 Table 1. Information Security Strategy Conceptualisations and Role in Information Systems Research Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 6 3.2.2 Levels of analysis For the purposes of clarification, in this paper a group is a set of individuals who are responsible for some aspect of security within an organisation. Also, in this section where a paper discusses aspects of responsibility for the application of ISSiO at two different levels, the higher of the two was recorded for the purpose of this analysis. This is because the higher level is seen to be more complex, with greater relationship interdependencies. Table 2 shows that while ISSiO is acknowledged to be a multilevel construct, researchers (with only 3 from 45 papers, or 7 percent) do not typically characterise ISSiO from an individual perspective. A significant 60 percent (27 from 45 papers) of the information systems literature examined contend that ISSiO belongs at an organisational level. At an organisational or inter- organisational level, it is apparent (with 35 from 45 papers, or 78 percent) that scholars believe ISSiO is neither plan nor process. Plan Process Neither Plan nor Process Total 1. Individual 0 0 3 3 2. Group 0 1 7 8 3. Organisation 3 5 19 27 4. Inter-organisational 0 1 6 7 Total 3 7 35 45 Table 2. Information Security Strategy Conceptualisations and Levels of Analysis 3.2.3 Measurement domain When operationalising ISSiO, if conceptual elements cannot be measured, then their reliability cannot be known. There are eight papers in the information systems literature that use the term 'information security strategy’ and expand the theoretical base of ISSiO. Of these, seventy five percent (6 from 8 papers) contend that ISSiO exists at an organisational level. Half of these (4 from 8) papers hold that ISSiO is neither a plan nor a process. A number of these papers confusingly use the word ‘measure’ as an abbreviation for ‘countermeasure’, which is a control installed to mitigate the risk arising from a threat to an asset (Ahmad et al. 2014b; Beebe and Rao 2009; Park and Ruighaver 2008). Two papers contained no mention of ‘measure’ at all (Hong et al. 2003; Kayworth and Whitten 2010). Of the three papers that addressed the measurement of some aspect of ISSiO, the main areas which were measurable included risk management, goal achievement and quality. Risk management can be measured by efficacy, efficiency or effectiveness (Baskerville and Dhillon 2008). Time can be a primary measure of risk (Baskerville et al. 2014) or alternatively an examination of a finite set of risk-reducing countermeasures can be measured (Beebe and Rao 2010). Goal achievement is measured by the activities undertaken to achieve those goals (Baskerville and Dhillon 2008). Quality improvement can be gained through the measuring of routine security tasks (Baskerville et al. 2014). 3.3 The Information Security Strategy Nomological Network In this section we undertake a thematic analysis within the information systems literature to conceptualise ISSiO at various levels within an organisation and develop a nomological network map to explain the construct and its interrelationships. Thematic analysis is a common technique that has been used by other researchers to examine large bodies of work within the information systems literature (Leidner and Kayworth 2006; Roberts et al. 2012). Thematic analysis is the process of conducting a qualitative content analysis on the literature of interest then listing meritorious ideas from each article before organising them into related groups (Cline and Jensen 2004). To conduct the thematic analysis, we first analysed forty five papers for their interpretation of ISSiO and then grouped key constructs according to similarities of themes. This resulted in three distinct theme groups emerging from the analysis, which were antecedents, constituents and yields. Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 7 Antecedents are the precursor conditions that might prompt an organisation to consider the use of an ISSiO. Examples include governments with top secret files, pharmaceutical companies conducting extended clinical new drug trials and banks facilitating online trading. Constituents are the elements that make up the core of an ISSiO, to be adopted by an organisation seeking to protect its information. Examples include risk management process to understand persistent common threats, security auditing to satisfy external regulators and governance activities to align organisational efforts. Yields are the benefits that can be enjoyed after successfully adopting ISSiO. Examples include the confidentiality, integrity and availability of information, and protection of competitive advantage, reputation, and customer trust. Based on the thematic analysis and discussion in preceding sections, a logical grouping of the conceptual elements of ISSiO can be elicited from the literature and is shown in Figure 1. Figure 1. Thematic Map of Information Security Strategy in Organisations in IS Research The sections below discuss these themes in more detail, based on conceptual elements and an overall understanding of what each paper purports ISSiO to be. 3.3.1 Antecedents Antecedents are the precursor conditions necessary to prompt the use of ISSiO and emerged as a theme in the information systems literature after conducting a thematic analysis, as described in the previous section. At an individual level, there did not seem to be any antecedents apparent in the literature. It is impossible to make an exhaustive claim about this but perhaps this is an area that warrants further attention from researchers. At a group level, one ISSiO antecedent is the requirement for global ubiquitous information availability and the necessity to distil incomprehensible threat intelligence complexity and volume in a timely fashion to management (Booker 2006). At an organisational level, antecedents for ISSiO apparent in the literature included gathering intelligence about the external environment. An organisation’s information security strategic posture involves a dependence on the external threat environment, not the continued successful achievement of organisational goals. The increasing complexity and sophistication of dynamic, targeted attacks over time naturally causes a general shift in posture balance from preventative towards a more response-oriented approach (Baskerville et al. 2014). Organisational ownership of valuable information assets is also a key driver towards the adoption of ISSiO (Kelly 1999). At the inter-organisational level, an ISSiO must take into consideration an organisation’s regulatory compliance burden (Banker et al. 2010; Kayworth and Whitten 2010; Tutton 2010). This regulatory compliance-driven approach however only forms part of a holistic approach to security (Anderson and Choobineh 2008). Regulatory and legal compliance along with Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 8 adoption of standards and best practices is also required (ISO/IEC 2013a; Posthumus and von Solms 2004). Examination of the industry in which the organisation competes and sufficient knowledge of industrial and economic considerations of an organisation’s competitive landscape are also required (Baets 1992). The existence of a strategic information systems plan is notable, as it dictates the formulation of the information security policy by providing essential details of the business context or competitive landscape (Doherty and Fulford 2006). Failure of political pressure and economic sanctions are important preconditions that may motivate the commencement of information warfare (Baskerville 2010). ISSiO is primarily based on prevention of incidents arising from advanced persistent threats (APT) using technical controls against external threats that are seen to be increasingly more frequent, novel and costly (Beebe and Rao 2009). Environmental and organisational conditions, managerial understanding and actions, quality improvement initiatives and organisational achievement lead to use of ISSiO (Cline and Jensen 2004). Regulatory, political and legal compliance plus adoption of standards and best practices motivate the use of ISSiO (Kim et al. 2012; Posthumus and von Solms 2004). Standards exist which detail management of information security which in turn could assist with ISSiO development (Brotby et al. 2006; ISO/IEC 2013b). 3.3.2 Constituents Constituents are the central conceptual elements of ISSiO and emerged as a theme in the information systems literature after conducting a thematic analysis. Individual level This section seeks to explore what role an individual has in contributing towards the overall success of the strategic use of information security. At an individual level, there were no constituent elements of ISSiO however this seems unusual because it is widely accepted that overall security depends on the weakest link which is typically the individual. This may represent an opportunity for further research. Group level This section examines the IS literature to discover the dynamics of groups working to support the strategic use of information security. At a group level, the constituent components of the ISSiO construct are varied and numerous. One is the identification and protection of knowledge assets, which can be resources forming a competitive advantage and can be either held in the human brain or in organisational documents, routines, procedures and practices. Knowledge leakage is a security incident which can temporarily affect an organisation’s competitive advantage and affect its reputation, revenue streams, remediation costs and productivity. Mitigation or protection of knowledge is achieved through initial classification of information assets, then compartmentalisation, development of technical solutions, policies, procedures, culture and legal support (Ahmad et al. 2014a). ISSiO should guide the overall security budget for an organisation, to enable the security staff group and their management to fund and implement security resources that optimise security outcomes based on expense versus benefits (Anderson and Choobineh 2008). ISSiO includes the examination of stratified responsibility within an organisation that cohesively achieves overall information systems security. Decisions made by one layer of responsible agents affect decisions made by agents in other layers and their communication is vital. ISSiO success depends on action taken by responsible agents rather than technological controls. Achievement of ISSiO allows alignment with policies and regulatory compliance efforts (Backhouse and Dhillon 1996). An essential element of ISSiO is a mix of technical, formal and informal controls to ensure regulatory compliance, protect the IT infrastructure that the information resides on and deliver confidentiality, integrity and availability (CIA) to users (Beebe and Rao 2009; Posthumus and von Solms 2004; Sveen et al. 2009). Security education, training, awareness and constant monitoring are required to ensure employees can use controls (Taylor and Robinson 2014; Van Niekerk and Von Solms 2010). ISSiO includes the capability to respond to attacks effectively, which stems from supplementary forces creating a time buffer through the employment of defence-in-depth design to allow the responding forces enough to time to deploy to the breach Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 9 from the central holding point (Burnburg 2003). Information systems solutions underpin business products and services and are therefore critical in maintaining an organisation’s competitive advantage. An ISSiO must focus on how to maintain competitive advantage in the face of rapidly changing ICT infrastructures (Cegielski et al. 2013). Organisational level The organisational level is where most influence can be exerted internally to achieve success in supporting an externally-focussed strategic application of information security and deserves special attention in our examination of the IS literature. At an organisational level, ISSiO can be used to incrementally improve the quality of the information security program. There must be a strong link from the ISSiO to the business strategic plan to support it. ISSiO is necessary to prevent threats to an organisation’s information (Ahmad et al. 2014b). It supports incremental quality improvement, alignment with agency mission, and awareness and monitoring of external threats (Bowen et al. 2006; Johnson and Goetz 2007). ISSiO protects only the more valuable information assets in order to reduce expenditure. This is achieved through policies and communication structures, director-level sponsorship of security initiatives, measuring success and administering sanctions for security policy violations. Identity and access management is important to overall success as is security incident detection and response activities (Ahmad et al. 2012; Kelly 1999). Corporate knowledge assets can then be inventoried and values defined (Baets 1992). If the labour involved with security functions is outsourced to other companies or individual contractors, then they need to equally adhere to the security policies and strategy adopted by the parent organisation (Baskerville et al. 2014). ISSiO can use situational crime prevention (SCP) to introduce a deterrent option within the risk management section (Beebe and Rao 2010). It is centred in risk management, identifying controls to mitigate known threats (Da Veiga and Eloff 2007). Reducing risk lowers anticipated loss, which changes an organisation’s security posture. Quantifying risk of anticipated loss requires recording of previous loss from security incidents (Ryan and Ryan 2006). Conceptual constituents also include regulatory compliance, teleworkers, organisational agility, business justification requirements, reactive quality improvement and community cloud initiatives (Booker 2006). The external environment places various demands on the organisation which changes in order to continue the achievement of the organisational objectives. The ISSiO is contingent on the environment when changing to maintain focus on the organisational objectives (Hong et al. 2003). ISSiO uses governance to provide boundaries and procedures for employees along with their roles and responsibilities and considers the organisation’s risks and culture, performance and assurance, SETA, suppliers and customers (Brotby et al. 2006; Hinde 2002). Information security strategy is built on IT products and solutions but extends to include the employees in the business. Specifically ISSiO integrates director-level security sponsorship and hierarchical structures that provide security governance (Kayworth and Whitten 2010). ISSiO requires the attention and support of the board of directors and CEO because they are accountable for its outcomes. They affect ISSiO by using corporate governance, specifically a corporate information security policy, as a tool to communicate with and direct management in the organisation. Two-way communication is then required back from management to the board and executive in the form of regular progress reports (ISO/IEC 2013b; McFadzean et al. 2006; Posthumus and von Solms 2004; Vroom and Von Solms 2004). ISSiO must consider corporate governance and provide those responsible for security with autonomy (Von Solms and Von Solms 2004). ISSiO constituents include risk management components such as disaster recovery and business continuity, insurance, audits and new business units and groups (Cline and Jensen 2004). Without a focus on business continuity, it is entirely possible that in the event of an ICT infrastructure disaster a lack of business continuity translates directly into quantifiable revenue loss (Van Der Haar and Von Solms 2003). Information security strategy needs to focus on people and process not tools, as these are the main causes of security failure (Da Veiga and Eloff 2010). ISSiO is preventative in nature and Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 10 seeks to protect against rational individuals perpetrating attacks rather than automated technical attacks. The preventative approach relies heavily on deterrence and advocates that effectiveness is derived from sanctions being believed to be swift, severe and certain (D'Arcy and Herath 2011). Inter-organisational level The inter-organisational level of information security is where organisational benefits can potentially be mutually shared by contributing organisations for their individual success and factors that influence this are examined in the following section. At an inter-organisational level, compliance must be audited and a firm’s auditing costs, incurred through engagement with an external auditor, can be lowered through a focus on IT assurance. This IT assurance includes high-quality IT documentation and an emphasis on systems security which lowers the cost because it makes the work of an auditor easier and quicker, therefore considerably lowering the time and materials auditing cost (Banker et al. 2010). ISSiO facilitates information warfare, which forms just one layer of a conflict with an adversary. The four layers of a nation attack are political, which then escalates to economic sanctions, then information warfare and finally full kinetic warfare (Baskerville 2010). Some information assets may be resources that create strategic competitive advantage for organisations. If these lose their confidentiality through a security incident, then their integrity may be lost forever, along with the value of the advantage. When a security incident of this nature is disclosed to the market, there are implications for the organisation’s share price (Campbell et al. 2003). ISSiO is the process of dynamically assessing customer perceptions of the organisation’s online transactions, with a view to increasing the security of transactions in order to prevent a decrease in brand trust in the marketplace. Regulatory pressures have increased the requirement for this defensive process (Datta and Chatterjee 2008). ISSiO must include an organisation’s business and policy cyber considerations and depends on the political environment in an organisation’s country of origin, which must synchronise with that of governments from other countries. The legal frameworks in various countries must harmonise globally to allow prosecution in the event of an attack. Shouldering the responsibility for lowering attacks will involve constitutional examination for potential conflicts, a willingness to collaborate and a system for measuring attacks however the benefits are that the world will be a safer place (Kim et al. 2012). 3.3.3 Yields Yields are the goals achieved from the successful use of ISSiO and emerged as a theme in the information systems literature after conducting the thematic analysis described in Section 3.3. At an individual level, there were no apparent benefits arising from ISSiO, nor were there any apparent at a group level of analysis. At an organisational level, the security goals are to ensure knowledge assets’ confidentiality, integrity and availability (Ahmad et al. 2014a). Another yield is that high quality information is made readily available to managers as they require it (Doherty and Fulford 2006). Prevention of potential losses is an objective but depends on the volume of organisational information assets, business continuity capabilities, profitability, threat intelligence and risk appetite. Security budgets to achieve this prevention should be bounded by expected probable losses (Anderson and Choobineh 2008). Loss prevention efforts should also guard against revenue loss (Van Der Haar and Von Solms 2003). Performance reporting is another goal but requires tracking of key KPIs including systems, assigned assets, people, processes, compliance and auditing and customer service (Booker 2006). Finally, the protection of competitive advantage is an obvious goal (Cegielski et al. 2013). At an inter-organisational level, ISSiO yields can include the misdirection of an adversary’s attack assets, even from other nation-states, to protect information assets and physical critical infrastructure assets. Yields can also include the disablement of adversary critical infrastructure, reduce foreign military abilities and impair foreign government operations Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 11 (Baskerville 2010). ISSiO can also lower the risk of adverse litigation outcomes and achieve information confidentiality, integrity, availability, authenticity and non-repudiation (Brotby et al. 2006). An important benefit is share price protection (Campbell et al. 2003). Regulatory compliance avoids adverse sanctions by ensuring external agencies are kept fully informed (Banker et al. 2010). ISSiO yields also include retaining customers, security incident prevention, improved business processes and public reputation (Cline and Jensen 2004). Failure to implement an ISSiO sensibly may result in estranged customers and tarnished reputation (Datta and Chatterjee 2008; Oshri et al. 2007). 3.3.4 Key findings of thematic analysis A number of gaps in knowledge have appeared through the conduct of this research. At an individual level of analysis, there appears to be very little research conducted into the role of an individual when supporting ISSiO. There appear to be many contributors to various aspects of ISSiO but there does not seem to be any one unified conceptualisation or theory. Information security is managed at an organisational level but must include an assessment of inter-organisational level factors to take advantage of the potential yields. Table 3 presents a thematic map of ISSiO derived from the results of the literature review, as described in the previous sections, and summarises the key themes found. Antecedents ISSiO Constituents Yields Inter-organisational Regulatory compliance Industrial and economic factors Political and economic factors Political and legal factors External threat environment Standards Inter-organisational Regulatory compliance Information warfare Information asset protection Environment scanning Inter-organisational Foreign adversary impairment Litigation risk management Share price protection Regulatory compliance Public reputation Customer trust Organisational Valuable information Intelligence Organisational Boardroom accountability Quality improvement Information asset management Labour source Risk management Organisational agility Governance Business continuity People and process Incident prevention Policy Organisational Confidentiality, integrity and availability Probable loss mitigation Performance reporting Competitive advantage protection Group Ubiquitous information availability Group Knowledge leakage prevention Security budget Responsibility Controls Incident response ICT infrastructure Group None Individual None Individual None Individual None Table 3. Thematic Map of Results from Literature Review of ISSiO The antecedent column can clustered into two main groups, which are internal and external to the organisation. Internal antecedents include valuable information and its ubiquitous availability to management for use in daily operations. External antecedents at the inter- Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 12 organisational level include all the constraints being placed on the organisation, such as regulatory compliance and the external threat environment. In the constituent column, there are a number of variables that can be altered to operationalise ISSiO according to an organisation’s unique requirements. Internal activities such as applying controls to protect information assets from threats are conducted from the board down, even including the activities that have external requirements at the inter-organisational level such as environment scanning. It is important to note that all activities in the constituent column are internally controlled, even the inter-organisation level ones. In the yields column, external benefits are largely intangible, such as the enhancement of customer trust, and internal benefits are largely tangible, such as protection of competitive advantage. This analysis is summarised in Table 4: Antecedents ISSiO Constituents Yields External constraints Internal information Threats / Information / Resources / Controls External intangible Internal tangible Table 4. Analysis of Results from Literature Review of ISSiO 4 Conclusion This literature review illustrates various aspects of ISSiO and key themes were explored and grouped. Yet, there is no single, well-developed conceptualisation apparent in the literature that comprehensively explains the ISSiO construct and its relationships. Additionally, information security is ostensibly lacking to a large extent from the strategic organisational literature and even from strategic information systems literature. A paradigm shift is required to move from internally-focussed protection of organisation-wide information towards a strategic view that considers an organisation’s environment. The following section offers suggestions to address these gaps through the conduct of future research, which could include positing a framework or model to allow information systems researchers to understand ISSiO more fully. 4.1 Contribution Based on our review and a cumulative research tradition, we now construct a definition proposing the meaning of information security strategy in organisations: “Information security strategy is an organisational-level model of conceptual elements, which is motivated by antecedent conditions that balance internal information needs and external environmental factors, to yield information security benefits to the organisation.” 4.2 Limitations of Research into Information Security Strategy The ISSiO construct developed so far is potentially of great benefit to organisations seeking to adopt an overall strategy for their information security. We understand firstly, the precursor conditions which when met, cause organisations to consider the use of ISSiO; secondly, the constituent elements of an ISSiO for operationalisation; and thirdly, the benefits that can be enjoyed by an organisation upon successful implementation. Given that, we still have limitations impeding our understanding of ISSiO. These are described in the next section. First, a significant amount of research conceptualises ISSiO as a plan, which identifies the construct as a static document, bereft of dynamic processes to ensure its validity when responding to immediate changes in the external environment. This gives rise to construct validity issues as having a plan is important, but not a precondition for an organisation to vary its ISSiO based on persistent incident detection and response (Straub et al. 2004). Second, the information systems literature contains analysis on ISSiO from various levels within an organisation, largely focusing on the organisational perspective. This stratified perspective has its own properties and varies from an inter-organisational level, for example Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 13 in terms of complexity and focus on external factors. Therefore, the nomological network of terms will be different for each level. Third, measurement issues arose in our study when we found that information systems researchers either did not adequately explain the dimensions with which to measure the elements of the ISSiO construct at each level or defined theoretical measures for one level and then operationalised them at another (Baskerville and Dhillon 2008). Additionally, tangible aspects of ISSiO such as the use of technical controls were perceived to be very measurable through reporting but intangible aspects such as employee attitudes towards security less so. 4.3 Future Research Directions In addition to conducting further research on the gaps identified in this paper, there are several prospects for information systems researchers to develop the body of knowledge that currently exists on ISSiO. Answers to these questions have implications for practice. This study provides the impetus hopefully for future research into ISSiO, strategic information systems and organisational strategy. First, military strategy has influenced business management theory in many ways. How can military strategy contribute to our understanding of ISSiO? What aspects of warfare, including embodying any supporting theory for example possibility theory, are pertinent to ISSiO? Second, given the strong links from ISSiO to organisational strategic theory apparent in the literature, what lessons does business strategy have for ISSiO? How can ISSiO be integrated with business strategy? How does ISSiO relate to IT strategy? Is there a dependence on ISSiO to achieve organisational success, and if so, how is this success defined? What other preconditions would prompt an organisation to strategically consider the use of ISSiO? Are there avenues to generate additional competitive advantage through ISSiO? Are there differences in ISSiO between public and private sectors? When organisations write an ISSiO, do they have the capability to implement it? Third, information systems researchers could generate a framework or model to explain the phenomena that collectively form the ISSiO construct. What are the constituent elements of ISSiO and how do these relate to each other? How would ISSiO be operationalised within an organisation? To what extent will compliance culture influence the effectiveness of ISSiO operationalisation (Shedden et al. 2010; Tan et al. 2010)? How does ISSiO relate to strategic information systems? How does ISSiO relate to organisational strategy? What is the role of the individual level in ISSiO? How do levels of analysis apply in the digital realm? Finally, there are a number of information systems scholars who have researched the theory underlying ISSiO, including for example deterrence, prevention, surveillance, detection, response, deception, perimeter defence, compartmentalisation and layering (Ahmad et al. 2014b; Beebe and Rao 2009; D'Arcy and Herath 2011). What would further analysis of these theories reveal about ISSiO? What does systems theory have to offer ISSiO? Could a theory on information security be developed? What do the theory of information warfare or the theory of protection motivation offer ISSiO (Denning 1999; Rogers 1975)? References Ahmad, A., Bosua, R., & Scheepers, R. (2014). Protecting organizational competitive advantage: A knowledge leakage perspective. Computers & Security, 42, 27-39. Ahmad, A., Hadgkiss, J., & Ruighaver, A. B. (2012). Incident response teams–Challenges in supporting the organisational security function. Computers & Security, 31(5), 643-652. Ahmad, A., Maynard, S. B., & Park, S. (2014). Information security strategies: Towards an organizational multi-strategy perspective. Journal of Intelligent Manufacturing, 25(2), 357-370. Anderson, E. E., & Choobineh, J. (2008). Enterprise information security strategies. Computers & Security, 27(1), 22-29. Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 14 Backhouse, J., & Dhillon, G. (1996). Structures of responsibility and security of information systems. European Journal of Information Systems, 5(1), 2-9. Baets, W. (1992). Aligning information systems with business strategy. Journal of Strategic Information Systems, 1(4), 205-213. Banker, R., Chang, H., & Kao, Y.-C. (2010). Evaluating cross-organizational impacts of information technology – an empirical analysis. European Journal of Information Systems, 19(2), 153-167. Baskerville, R. (2010). Third-degree conflicts: Information warfare. European Journal of Information Systems, 19(1), 1-4. Baskerville, R., & Dhillon, G. (2008). Information systems security strategy: A process view. In D. W. Straub, S. E. Goodman, & R. Baskerville (Eds.), Information security: Policy, processes, and practices. Advances in Management Information Systems (pp. 15-45). Armonk, NY: M. E. Sharpe. Baskerville, R., Spagnoletti, P., & Kim, J. (2014). Incident-centered information security: Managing a strategic balance between prevention and response. Information & Management, 51(1), 138-151. Beebe, N. L., & Rao, V. S. (2009). Examination of organizational information security strategy: A pilot study. Paper presented at the AMCIS 2009 Proceedings. Beebe, N. L., & Rao, V. S. (2010). Improving organizational information security strategy via meso-level application of situational crime prevention to the risk management process. Communications of the Association for Information Systems, 26(17), 329-358. Booker, R. (2006). Re-engineering enterprise security. Computers & Security, 25(1), 13-17. Bowdish, R. G. (2013). Military strategy: Theory and concepts. (Doctor of Philosophy PhD), University of Nebraska, Lincoln, Nebraska. (26) Bowen, P., Hash, J., & Wilson, M. (2006). SP 800-100. Information Security Handbook: A Guide for Managers. Brotby, W., Bayuk, J., & Coleman, C. (2006). Information security governance: Guidance for boards of directors and executive management: Illinois, IT Governance Institute. Burnburg, M. K. (2003). A proposed framework for business information security based on the concept of defense-in-depth. (Master's Thesis), University of Illinois, Springfield. Campbell, K., Gordon, L. A., Loeb, M. P., & Zhou, L. (2003). The economic cost of publicly announced information security breaches: Empirical evidence from the stock market. Journal of Computer Security, 11(3), 431-448. Cegielski, C. G., Bourrie, D. M., & Hazen, B. T. (2013). Evaluating adoption of emerging IT for corporate IT strategy: Developing a model using a qualitative method. Information systems management, 30(3), 235-249. Cline, M., & Jensen, B. (2004). Information security: An organizational change perspective. Paper presented at the AMCIS 2004 Proceedings. D'Arcy, J., & Herath, T. (2011). A review and analysis of deterrence theory in the IS security literature: Making sense of the disparate findings. European Journal of Information Systems, 20(6), 643-658. Da Veiga, A., & Eloff, J. H. P. (2007). An information security governance framework. Information systems management, 24(4), 361-372. Da Veiga, A., & Eloff, J. H. P. (2010). A framework and assessment instrument for information security culture. Computers & Security, 29(2), 196-207. Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 15 Datta, P., & Chatterjee, S. (2008). The economics and psychology of consumer trust in intermediaries in electronic markets: The EM-Trust Framework. European Journal of Information Systems, 17(1), 12-28. Denning, D. E. R. (1999). Information warfare and security (Vol. 4): Addison-Wesley Reading MA. Doherty, N. F., & Fulford, H. (2006). Aligning the information security policy with the strategic information systems plan. Computers & Security, 25(1), 55-63. Drucker, P. F. (1958). Business objectives and survival needs: Notes on a discipline of business enterprise. the Journal of Business, 31(2), 81-90. Durand, T., Mounoud, E., & Ramanantsoa, B. (1996). Uncovering strategic assumptions: Understanding managers' ability to build representations. European Management Journal, 14(4), 389-398. Flores, W. R., Antonsen, E., & Ekstedt, M. (2014). Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture. Computers & Security, 43, 90-110. Hinde, S. (2002). Security surveys spring crop. Computers & Security, 21(4), 310-321. Hong, K.-S., Chi, Y.-P., Chao, L., & Tang, J.-H. (2003). An integrated system theory of information security management. Information Management & Computer Security, 11(5), 243-248. ISO/IEC. (2013a). ISO/IEC 27001:2013 Information technology — Security techniques — Information security management systems — Requirements. Geneva, Switzerland: International Organization for Standardization and International Electrotechnical Commission. ISO/IEC. (2013b). ISO/IEC 27014:2013 Information technology — Security techniques — Governance of information security. Geneva, Switzerland: ISO/IEC. Johnson, M. E., & Goetz, E. (2007). Embedding information security into the organization. 3, 16-24. Kayworth, T., & Whitten, D. (2010). Effective information security requires a balance of social and technology factors. MIS Quarterly Executive, 9(3), 163-175. Kelly, B. J. (1999). Preserve, protect, and defend. The Journal of Business Strategy, 20(5), 22- 25. Kim, S. H., Wang, Q.-H., & Ullrich, J. B. (2012). A comparative study of cyberattacks. Communications of the ACM, 55(3), 66-73. Leidner, D. E., & Kayworth, T. (2006). Review: a review of culture in information systems research: toward a theory of information technology culture conflict. MIS Quarterly, 30(2), 357-399. McFadzean, E., Ezingeard, J.-N., & Birchall, D. (2006). Anchoring information security governance research: Sociological groundings and future directions. Journal of Information System Security, 2(3), 3-48. Mintzberg, H. (1987). The strategy concept I: Five Ps for strategy. California Management Review, 30(1), 11-24. Oshri, I., Kotlarsky, J., & Hirsch, C. (2007). Information security in networkable Windows- based operating system devices: Challenges and solutions. Computers & Security, 26(2), 177-182. Park, S., & Ruighaver, T. (2008). Strategic approach to information security in organizations. Paper presented at the ICISS. International Conference on Information Science and Security, 2008. Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 16 Porter, M. E. (1980). Competitive strategy: techniques for analyzing industries and competitors: New York: Free Press. Posthumus, S., & von Solms, R. (2004). A framework for the governance of information security. Computers & Security, 23(8), 638-646. Roberts, N., Galluch, P. S., Dinger, M., & Grover, V. (2012). Absorptive capacity and information systems research: Review, synthesis, and directions for future research. MIS Quarterly, 36(2), 625-648. Rogers, R. W. (1975). A protection motivation theory of fear appeals and attitude change1. The journal of psychology, 91(1), 93-114. Ryan, J. J., & Ryan, D. J. (2006). Expected benefits of information security investments. Computers & Security, 25(8), 579-588. Schwenk, C. R. (1988). The cognitive perspective on strategic decision making. Journal of management studies, 25(1), 41-55. Shedden, P., Ruighaver, T., & Ahmad, A. (2010). Risk Management Standards – The Perception of Ease of Use. Journal of Information Systems Security, 6(3), 23-41. Straub, D., Boudreau, M.-C., & Gefen, D. (2004). Validation guidelines for IS positivist research. The Communications of the Association for Information Systems, 13(1), 63. Sveen, F., Torres, J., & Sarriegi, J. (2009). Blind information security strategy. International Journal of Critical Infrastructure Protection, 2(3), 95-109. Tan, T., Ruighaver, A. B., & Ahmad, A. (2010). Information security governance: When compliance becomes more important than security. Paper presented at the The IFIP TC- 11 24th International Information Security Conference, Brisbane, Australia. Taylor, R. G., & Robinson, S. L. (2014). The roles of positive and negative exemplars in information security strategy. Academy of Information and Management Sciences Journal, 17(2), 57-79. Tutton, J. (2010). Incident response and compliance: A case study of the recent attacks. Information Security Technical Report, 15(4), 145-149. Van Der Haar, H., & Von Solms, R. (2003). A model for deriving information security control attribute profiles. Computers & Security, 22(3), 233-244. Van Niekerk, J. F., & Von Solms, R. (2010). Information security culture: A management perspective. Computers & Security, 29(4), 476-486. Von Solms, B., & Von Solms, R. (2004). The 10 deadly sins of information security management. Computers & Security, 23(5), 371-376. Vroom, C., & Von Solms, R. (2004). Towards information security behavioural compliance. Computers & Security, 23(3), 191-198. Webster, J., & Watson, R. T. (2002). Analyzing the past to prepare for the future: Writing a literature review. MIS Quarterly, 26(2), xiii-xxiii. Acknowledgements The authors would like to thank the reviewers for their valuable contributions to this paper. This research received funding support from Australian Government Research Training Program Scholarship. Copyright: © 2017 Horne, Maynard & Ahmad. This is an open-access article distributed under the terms of the Creative Commons Attribution-NonCommercial 3.0 Australia License, http://creativecommons.org/licenses/by-nc/3.0/au/ Australasian Journal of Information Systems Horne, Maynard & Ahmad 2017, Vol 21, Research Article Organisational Information Security Strategy 17 which permits non-commercial use, distribution, and reproduction in any medium, provided the original author and AJIS are credited.