lnu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Information security governance in the public sector: investigations, approaches, measures, and trends
Linnaeus University, Faculty of Technology, Department of Informatics.ORCID iD: 0009-0000-8265-0944
Linnaeus University, Faculty of Technology, Department of Informatics.ORCID iD: 0000-0002-4437-8297
Linnaeus University, Faculty of Technology, Department of Informatics.ORCID iD: 0000-0001-6227-0290
Linnaeus University, Faculty of Technology, Department of Informatics.ORCID iD: 0000-0001-7520-695X
2025 (English)In: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 24, article id 177Article in journal (Refereed) Published
Abstract [en]

Information security governance in the public sector involves risk management, accountability frameworks, network security, e-government systems infrastructure, mitigation plans, and alignment with corporate strategy. It equips organizations with the ability to deal with the security of their vital information assets systematically. However, several recent hacking incidents reveal the fact that substandard governance processes are among the common causes of weak security measures in most organizations. This study has been conducted following the established protocol outlined in the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) guidelines. Systematic Mapping Review (SMR) initially identified 1496 papers, and this reviews and reports on 41 papers. The reviewed literature emphasizes the adherence to recognized governance standard frameworks such as ISO/IEC 27,001, EU General Data Protection Regulations (GDPR), and EU Network and Information Security Act (NIS) for providing effective information security guidance frameworks in the public sector. However, a general scarcity is found regarding the best practices followed in the area of information security compliance. There is a lack of employing key performance indicators, risk assessment measures, security maturity models in organizations, and compliance audits. Additionally, the study suggests that, to some extent, the adoption of appropriate information security governance procedures is linked with available budgeted resources for individual organizations. The study results can serve as a starting point for the research and practitioners’ community in the area of information security governance.

Place, publisher, year, edition, pages
Springer Nature , 2025. Vol. 24, article id 177
Keywords [en]
e-Governance, Governance and Government, Principles and Models of Security, Public Management, Public Sector Studies, Science and Technology Governance, Information security, Security frameworks, Risks, Governance, Management, Public sector, Systematic mapping review
National Category
Information Systems
Research subject
Computer and Information Sciences Computer Science, Information Systems
Identifiers
URN: urn:nbn:se:lnu:diva-140852DOI: 10.1007/s10207-025-01097-xISI: 001529910900001Scopus ID: 2-s2.0-105010963508OAI: oai:DiVA.org:lnu-140852DiVA, id: diva2:1985134
Funder
Linnaeus UniversityAvailable from: 2025-07-22 Created: 2025-07-22 Last updated: 2026-01-21Bibliographically approved

Open Access in DiVA

fulltext(1732 kB)227 downloads
File information
File name FULLTEXT01.pdfFile size 1732 kBChecksum SHA-512
50ce8981d7a125275bb3840bf7ce84bc866649f4aad2240e9aab522b8bd71f3ee13a81fefcc3ba32c3b2af449b4c615edf965076d34476a162b40cee5b15bece
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Magnusson, LarsIqbal, SarfrazElm, PatrikDalipi, Fisnik

Search in DiVA

By author/editor
Magnusson, LarsIqbal, SarfrazElm, PatrikDalipi, Fisnik
By organisation
Department of Informatics
In the same journal
International Journal of Information Security
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 231 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 633 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf