Information and cyber security maturity models: a systematic literature review

2020 ◽  
Vol 28 (4) ◽  
pp. 627-644 ◽  
Author(s):  
Anass Rabii ◽  
Saliha Assoul ◽  
Khadija Ouazzani Touhami ◽  
Ounsa Roudies

Purpose This paper aims to clarify the uncertainty reflected in the current state of information security maturity evaluation where it has not enough matured and converged so that a generic approach or many specfics approaches become the go-to choice. In fact, in the past decade, many secruity maturity models are still being produced and remain unproven regardless of the existence of ISO 21827. Design/methodology/approach The authors have used the systematic literature review to summarize existing research, help identify gaps in the existing literature and provide background for positioning new research studies. Findings The authors highlighted the prevalent influence of the ISO/IEC 27001/27002 standard but raised the necessity for an in-depth investigation of ISO 21827. The authors also made the implementation facet a central topic of our review. The authors found out that, compared to the number of proposed models, implementation experiments are lacking. This could be due to the arduous task of validation and it could also be the reason why specific models are dominant. Originality/value While the research literature contains many experience reports and a few case studies on information security maturity evaluation, a systematic review and synthesis of this growing field of research is unavailable as far as the authors know. In fact, the authors only picked-up one bodywork [Maturity models in cyber security A systematic review (2017)] carrying out a literature review on security maturity models between 2012 and 2017, written in Spanish.

2021 ◽  
Vol ahead-of-print (ahead-of-print) ◽  
Author(s):  
Kamrul Ahsan ◽  
Shams Rahman

PurposeThis study conducts a systematic literature review of e-tail product returns research. E-tail product returns are essentially acquisition of products that have been sold through purely online or brick-and-click channels and then returned by consumer to business.Design/methodology/approachUsing a systematic literature review protocol, we identified 75 peer-reviewed articles on e-tail product returns, conducted bibliometric analysis and content analysis of the articles and summarised our findings.FindingsThe findings reveal that the subject of e-tail returns is a new research area; academics have started to investigate several aspects of e-tail returns through different research methodologies and theoretical foundations. Further research is required in leading e-commerce countries and on key areas such as omni-channel returns management, customer satisfaction and service, the impact of resources such as people skills, the benefits of technology and IT systems in managing e-tail returns.Practical implicationsThe study offers a summative account of current e-tail knowledge areas, which can serve as a reference guide for e-tailers to develop strategies for more efficient and competitive product returns.Originality/valueThis study contributes theoretically by developing clusters of key themes or knowledge areas about e-tail returns. It also provides a conceptual framework for e-tail returns management, which can be used as a springboard for further empirical research.


2021 ◽  
Vol ahead-of-print (ahead-of-print) ◽  
Author(s):  
Rola Imad Fanousse ◽  
Dilupa Nakandala ◽  
Yi-Chen Lan

PurposeThis article provides the first systematic review of literature on effective organisational practices for reducing innovation project uncertainties to promote project performance. Innovation is the lifeblood of organisations, while simultaneously being one of the most challenging processes to manage. This systematic review seeks to examine best practice for reducing uncertainties and thus mitigate the high failure rates in innovation projects.Design/methodology/approachThis paper provides a systematic review of the literature on innovation project management and encourages an understanding of how intra-organisational collaboration reduces uncertainty and thus increases project performance.FindingsBased on an analysis of the systematic literature review findings, the impact of intra-organisational collaboration in reducing uncertainties in innovation projects is uncovered. Three types of project uncertainties were found to be dominant in the context of innovation project management: task, technological and market uncertainties. Five dimensions of intra-organisational collaboration are also identified, namely collaborative relationship, collaborative leadership, communicating and sharing information, trust formation and joint decision-making.Originality/valueThe authors situate five intra-organisational collaboration dimensions as key mechanisms that yield organisational learning as an outcome. On the other hand, they also uncovered that organisational learning is a key enabler in the relationship between intra-organisational collaboration and task, market and technological uncertainties reduction. Therefore, intra-organisational collaboration is identified as a critical practice in enhancing the performance of innovation projects. The study proposes a multi-dimensional conceptual model, providing a mechanism for furthering a research agenda for improving the performance of innovation projects.


2020 ◽  
Vol ahead-of-print (ahead-of-print) ◽  
Author(s):  
Qian Chen ◽  
Daniel Mark Hall ◽  
Bryan Tyrone Adey ◽  
Carl Thomas Haas

PurposeManaging stakeholders' reciprocal interdependencies is always a challenging issue. Stakeholders need to find out different ways to communicate information and coordinate material flows during the supply chain processes. Many recent studies have advanced construction supply chain coordination from multiple perspectives. However, the field still lacks a comprehensive analysis to summarize existing research, to explicitly identify all the possible enablers for coordination and to investigate how the enablers can be carried out at the supply chain interfaces. To fill the gap, this study aims to conduct a systematic review in order to examine the relevant literature.Design/methodology/approachA systematic literature review process was conducted to identify and synthesize relevant publications (published in the past 20 years) concerning the coordination of construction supply chain functions. These publications were coded to link main research findings with specific enabler categories. In addition, how these enablers can be used at the interfaces across supply chain processes was reviewed with an in-depth analysis of reciprocal communications between stakeholders at design-to-production, production-to-logistics and production-to-site-assembly phases.FindingsThe coordination enablers were classified into three categories: (1) contractual enablers (including subtopics on relational contracts and incentive models), (2) procedural enablers (including subtopics on multiagent knowledge sharing systems and the last planner system) and (3) technological enablers (including subtopics on linked databases for design coordination, design for manufacturing software platforms and automated monitoring technologies). It was found that interfacing different functions requires a certain level of integration of stakeholders for quick response and feedback processes. The integration of novel contractual forms with digital technologies, such as smart contracts, however, was not adequately addressed in the state of the art.Research limitations/implicationsThe scope of the systematic review is limited to the static analysis of selected publications. Longitudinal studies should be further included to sharpen the inductions of enablers considering organizational changes and process dynamics in construction projects.Practical implicationsDifferent enablers for coordination were summarized in a concise manner, which provides researchers and project stakeholders with a reinforced understanding of various ways to manage reciprocal interdependencies at different supply chain interfaces.Originality/valueThis study constitutes an important input for research on the construction supply chain by illuminating the thematic topic of coordination from inductively developed review processes, which included a holistic framing of the emerging coordination enablers and their use across supply chain functions. Consequently, it closes some identified knowledge gaps and offers additional insights to improve the supply chain performance of construction projects.


2018 ◽  
Vol 7 (3) ◽  
pp. 217-229 ◽  
Author(s):  
Sarah Seleznyov

Purpose The purpose of this paper is to explore the popularity of Japanese lesson study (JLS) beyond Japan and the challenges this translation might pose. It notes that there is not a universally accepted definition of lesson study (LS) and seeks to identify the “critical components” of JLS through a review of the literature. It then uses a systematic literature review of recent studies of the implementation of LS with in-service teachers beyond Japan to analyse the models of LS used against these seven critical components in order to explore the degree of fidelity to the Japanese model. Design/methodology/approach A broad review of the literature on JLS available in the English language identifies seven “critical components”. A systematic literature review of 200 recent English language studies of the implementation of LS with in-service teachers beyond Japan is then carried out. Articles published between 2005 and 2015 are explored, including peer reviewed articles, scientific journals, book chapters and PhD dissertations. This systematic review enables an analysis of the models of LS used in studies from beyond Japan against the “seven critical components” of JLS. Findings The analysis shows that there is not an internationally shared understanding of Japanese lesson study (JLS) and that many of the missing components are those which distinguish LS as a research process, not simply a collaborative professional development approach. It also reveals that UK LS models seem particularly far from the Japanese model in those critical components which connect teachers’ knowledge and understanding within groups, to knowledge and understanding that exists beyond it. The study discusses whether these differences could be attributed to structural or cultural differences between Japan and other nations. Research limitations/implications The search for descriptions of the JLS is limited to articles available in the English language, which, therefore, represent a quite limited body of authority on the “critical components” of LS. The systematic review is similarly limited to English language articles, and there is a clear bias towards the USA, with the Far East and the UK making up the majority of the remaining studies. The study suggests that future research on LS beyond Japan should consider teachers’ attitudes towards the research elements of the process as well as their skills and confidence in carrying out research into practice. Practical implications The study strikes a note of caution for schools wishing to implement JLS as an approach to teacher professional development in the UK and beyond. Japan’s systemic approach has embedded LS experience and expertise into the education system, meaning a uniform approach to LS is much more likely. In addition, other systemic challenges may arise, for example, UK professional development time and resources is not designed with JLS in mind and may therefore require a significant reworking. Originality/value Whilst several systematic reviews of LS have explored its growth, geographical spread, impact and key features, this study provides a different perspective. It analyses whether and to what degree the “lesson study” models these studies describe align with the literature on JLS, and the implications of this for researchers and practitioners.


2020 ◽  
Vol 27 (8) ◽  
pp. 2435-2457 ◽  
Author(s):  
Ricardo Belinski ◽  
Adriana M.M. Peixe ◽  
Guilherme F. Frederico ◽  
Jose Arturo Garza-Reyes

PurposeIndustry 4.0 has been one of the most topics of interest by researches and practitioners in recent years. Then, researches which bring new insights related to the subjects linked to the Industry 4.0 become relevant to support Industry 4.0's initiatives as well as for the deployment of new research works. Considering “organizational learning” as one of the most crucial subjects in this new context, this article aims to identify dimensions present in the literature regarding the relation between organizational learning and Industry 4.0 seeking to clarify how learning can be understood into the context of the fourth industrial revolution. In addition, future research directions are presented as well.Design/methodology/approachThis study is based on a systematic literature review that covers Industry 4.0 and organizational learning based on publications made from 2012, when the topic of Industry 4.0 was coined in Germany, using data basis Web of Science and Google Scholar. Also, NVivo software was used in order to identify keywords and the respective dimensions and constructs found out on this research.FindingsNine dimensions were identified between organizational learning and Industry 4.0. These include management, Industry 4.0, general industry, technology, sustainability, application, interaction between industry and the academia, education and training and competency and skills. These dimensions may be viewed in three main constructs which are essentially in order to understand and manage learning in Industry 4.0's programs. They are: learning development, Industry 4.0 structure and technology Adoption.Research limitations/implicationsEven though there are relatively few publications that have studied the relationship between organizational learning and Industry 4.0, this article makes a material contribution to both the theory in relation to Industry 4.0 and the theory of learning - for its unprecedented nature, introducing the dimensions comprising this relation as well as possible future research directions encouraging empirical researches.Practical implicationsThis article identifies the thematic dimensions relative to Industry 4.0 and organizational learning. The understanding of this relation has a relevant contribution to professionals acting in the field of organizational learning and Industry 4.0 in the sense of affording an adequate deployment of these elements by organizations.Originality/valueThis article is unique for filling a gap in the academic literature in terms of understanding the relation between organizational learning and Industry 4.0. The article also provides future research directions on learning within the context of Industry 4.0.


2017 ◽  
Vol 29 (1) ◽  
pp. 184-213 ◽  
Author(s):  
Barbara Aquilani ◽  
Cecilia Silvestri ◽  
Alessandro Ruggieri ◽  
Corrado Gatti

Purpose The purpose of this paper is to present a systematic literature review to identify new avenues of research in line with the ongoing changes in quality and management required to firms, especially regarding customers. Design/methodology/approach This study uses a systematic review of the literature contained in the three databases Ebsco, JSTOR, and Springerlink and on the search engine Google Scholar. Findings An analysis of the literature identifies three different clusters of papers: “identification” papers, which show that customer focus has gained importance in recent times; “implementation” papers, which highlight that a general or shared model or scale to successfully implement total quality management (TQM) does not yet exist; and “impact-on-performance” papers, which show that few studies have considered the relationship between TQM and the issues of both marketing and performance, underlining the most significant gap in the TQM literature. Research limitations/implications This study is limited by the small number of databases and search engines used and by the restricted number of keywords used in searching these sources. Practical implications This work highlights a gap in the existing research and thus an incomplete consideration of the interplay between management, marketing, and quality issues, all centered on customers and other stakeholders. Researchers and firms are thus advised to adopt a wider view that considers the role of the quality process to support the firm’s engagement of customers in activities that enhance both the customer role and customer satisfaction. Originality/value This study uses a systematic literature review to review all critical factors of TQM and identifies new research avenues and different approaches to implementing TQM, focusing on the central role that customers play in achieving firm success.


2019 ◽  
Vol 25 (2) ◽  
pp. 223-240 ◽  
Author(s):  
Abhijeet Ghadge ◽  
Maximilian Weiß ◽  
Nigel D. Caldwell ◽  
Richard Wilding

Purpose In spite of growing research interest in cyber security, inter-firm based cyber risk studies are rare. Therefore, this study aims to investigate cyber risk management in supply chain contexts. Design/methodology/approach Adapting a systematic literature review process, papers from interdisciplinary areas published between 1990 and 2017 were selected. Different typologies, developed for conducting descriptive and thematic analysis, were established using data mining techniques to conduct a comprehensive, replicable and transparent review. Findings The review identifies multiple future research directions for cyber security/resilience in supply chains. A conceptual model is developed, which indicates a strong link between information technology, organisational and supply chain security systems. The human/behavioural elements within cyber security risk are found to be critical; however, behavioural risks have attracted less attention because of a perceived bias towards technical (data, application and network) risks. There is a need for raising risk awareness, standardised policies, collaborative strategies and empirical models for creating supply chain cyber-resilience. Research limitations/implications Different types of cyber risks and their points of penetration, propagation levels, consequences and mitigation measures are identified. The conceptual model developed in this study drives an agenda for future research on supply chain cyber security/resilience. Practical implications A multi-perspective, systematic study provides a holistic guide for practitioners in understanding cyber-physical systems. The cyber risk challenges and the mitigation strategies identified support supply chain managers in making informed decisions. Originality/value To the best of the authors’ knowledge, this is the first systematic literature review on managing cyber risks in supply chains. The review defines supply chain cyber risk and develops a conceptual model for supply chain cyber security systems and an agenda for future studies.


2020 ◽  
Vol 24 (6) ◽  
pp. 1315-1342
Author(s):  
Peter Heisig ◽  
Selvi Kannan

Purpose This paper aims to review for the first time existing research literature about the role of gender in creating, sharing and using knowledge in organizations and proposes a conceptual framework to guide future research directions. Design/methodology/approach Based on the systematic literature review method this study collects, synthesizes and analyses articles related to knowledge management (KM) and gender published in online databases by following a pre-defined review protocol. The paper analyses 41 papers published in peer-reviewed journals. Findings The role of gender in KM has been rarely addressed in KM journals and journals with specific emphasis on gender. The existing literature is fragmented, but existing research suggests that knowledge sharing might be influenced by gender. Based on the analysis and synthesis, a conceptual framework is proposed to guide further research on determining if gender matters in KM. Research limitations/implications Academic researchers should aim to include gender-related variables into their KM research to further explore if gender matters in KM. Practical implications The practical implication suggests that managers and knowledge managers should raise awareness about how stereotypes and gendered expectations about role behaviour affect how knowledge and experiences are created and shared within the organization. Social implications The authors believe that a better understanding of knowledge handling and gendered role expectations at the workplace could also have an impact beyond organizational boundaries. Originality/value The paper presents the first comprehensive systematic literature review of the article published on knowledge creation, sharing and usage and gender and provides a conceptual framework for future research.


2018 ◽  
Vol 16 (2) ◽  
pp. 123-137 ◽  
Author(s):  
Masomeh Yeganehfar ◽  
Atefe Zarei ◽  
Ali Reza Isfandyari-Mogghadam ◽  
AliAkbar Famil-Rouhani

Purpose The purpose of this paper is to provide a systematic literature review of available research evidence on marginal participation of women in ICT-related jobs (ICT – information and communication technology). In this study, it has been attempted to identify gaps in these literature studies according to the Global Index of Gender dimensions and briefly has been explained guidelines for policymakers to improve the participation of women in this area. Design/methodology/approach The authors follow from the method of (Tranfield et al., 2003) for conducting a systematic literature review (a systematic review means that the research has specific and systematic steps). Then key words were searched and appropriate resources with this study were evaluated. Accidentally, 55 articles in the period 2000 to 2014 were investigated, and articles were reviewed according to the Global Index of Gender dimensions. Findings A review of previous studies indicated that despite considerable attention given to open access to information and women’s skills, role of women in ICT has been underestimated. Results indicated that to keep pace with today’s information society, we would have to reinforce knowledge and abilities of women and provide them employment grounds in jobs that require new skills in ICT. To reinforce participation of women in the jobs, we need to invest in education and design policies to increase the number of women in educational courses related to ICTs. Also, we need to promote equal educational opportunities. Libraries are suitable platforms to create bold employment of women in jobs related to ICTs. Because it seems that majority of professionals are women in these places. In current information communities, we have to raise the level of individual development for reaching total development. Thus, women’s progress at professional jobs is needed to remove barriers of creativity and entrepreneurship for women. Also, development of strategies for providing contribution of women in ICT jobs should not be neglected. Originality/value This study is the first comprehensive study on the systematic review of the literature in the field of Gender Gap to show marginal participation of women in the ICT-related jobs.


2021 ◽  
Vol ahead-of-print (ahead-of-print) ◽  
Author(s):  
Nabin Chowdhury ◽  
Vasileios Gkioulos

Purpose The purpose of this paper can be encapsulated in the following points: identify the research papers published on the topic: competencies and skills necessary for critical infrastructure (CI) cyber-security (CS) protection; determine main focus areas within the identified literature and evaluate the dependency or lack thereof between them: make recommendations for future research. Design/methodology/approach This study is based on a systematic literature review conducted to identify scientific papers discussing and evaluating competencies, skills and essential attributes needed by the CI workforce for CS and preparedness to attacks and incidents. Findings After a comparative analysis of the articles reviewed in this study, a variety of skills and competencies was found to be necessary for CS assurance in CIs. These skills have been grouped into four categories, namely, technical, managerial, implementation and soft skills. Nonetheless, there is still a lack of agreement on which skills are the most critical and further research should be conducted on the relation between specific soft skills and CS assurance. Research limitations/implications Investigation of which skills are required by industry for specific CS roles, by conducting interviews and sending questionnaire\surveys, would allow consolidating whether literature and industry requirements are equivalent. Practical implications Findings from this literature review suggest that more effort should be taken to conciliate current CS curricula in academia with the skills and competencies required for CS roles in the industry. Originality/value This study provides a previously lacking current mapping and review of literature discussing skills and competencies evidenced as critical for CS assurance for CI. The findings of this research are useful for the development of comprehensive solutions for CS awareness and training.


Sign in / Sign up

Export Citation Format

Share Document