Computer ScienceBusiness

Cheuk Hang Au, Walter S. L. Fung

2019.1.1International Journal of Knowledge Management

DOI: 10.4018/ijkm.2019010103

tlooto Summary

The authors integrated the concepts of knowledge-centric information security and IT Governance into an ITG-driven knowledge framework (ITGKF) for reinforcing InfoSec maturity and auditability of enterprises and assessed whether ITG can embrace proper knowledge circulation within the InfoSec community.

Abstract

Repeated information security (InfoSec) incidents have harmed the confidence of people on enterprises' InfoSec capability. While most organisations adopt control frameworks such as ISO27001 and COBIT, the role and contribution of knowledge management on InfoSec was inadequately considered. The authors integrated the concepts of knowledge-centric information security and IT Governance (ITG) into an ITG-driven knowledge framework (ITGKF) for reinforcing InfoSec maturity and auditability of enterprises. The authors also tried to assess whether ITG can embrace proper knowledge circulation within the InfoSec community. The authors confirmed the positive influence of IT governance on knowledge-centric information security (KCIS) and information security maturity and audit result (ISMAR), the positive influence of KCIS on ISMAR, and the mediating role of KCIS between ITG and ISMAR. These indicated the significance of KM in InfoSec area. Based on the findings, they proposed possible changes of integrating KM in different InfoSec practices and audit standard.

Citation format

AU, Cheuk Hang; FUNG, Walter S. L. Integrating knowledge management into information security. International Journal of Knowledge Management, 2019, 15: 37–52.