To Örebro University

oru.seÖrebro University Publications
Change search
Link to record
Permanent link

Direct link
Publications (10 of 119) Show all publications
Karlsson, F., Gao, S., Krogstie, J. & Aro-Sati, L. (2026). Advancing a Speech Act-Based Model to Improve Future Quality of Information Security Policies Using Large Language Models. Complex Systems Informatics and Modeling Quarterly (46), 45-66
Open this publication in new window or tab >>Advancing a Speech Act-Based Model to Improve Future Quality of Information Security Policies Using Large Language Models
2026 (English)In: Complex Systems Informatics and Modeling Quarterly, E-ISSN 2255-9922, no 46, p. 45-66Article in journal (Refereed) Published
Abstract [en]

Employee compliance with Information Security Policies (ISPs) depends on communicating clear and comprehensible content. However, existing research has shown that many ISPs are of poor communicative quality. Large Language Models (LLMs) could enhance ISPs if fine-tuned on high-quality data, but to do such fine-tuning requires a conceptual model for classifying the data and evaluating the resulting text. Therefore, as a step in this direction, the aim of this article is to develop a conceptual model of ISPs using Speech Act Theory as a theoretical lens to enable assessments of the communicative quality of ISPs. We used conceptual modeling and document analysis to develop the modelbased on 600 ISP statements from ten British National Health Service ISPs. We used selected parts from the SEQUAL framework to evaluate the model. The evaluation pointed to potential areas for improving the model’s semantic, empirical, physical, and deontic qualities. By incorporating these improvements, the final class diagram contains 21 classes, six of which address ISP statement quality as speech acts.

Place, publisher, year, edition, pages
Riga Technical University, 2026
Keywords
Information Security Policy, Cybersecurity Policy, Speech Act, Large Language Model
National Category
Information Systems
Identifiers
urn:nbn:se:oru:diva-129008 (URN)10.7250/csimq.2026-46.03 (DOI)2-s2.0-105044184260 (Scopus ID)
Available from: 2026-05-23 Created: 2026-05-23 Last updated: 2026-08-12Bibliographically approved
Karlsson, F., Rostami, E., Gao, S. & Hanif, M. (2026). Artificial intelligence in information security policy management research: a scoping review. Information and Computer Security
Open this publication in new window or tab >>Artificial intelligence in information security policy management research: a scoping review
2026 (English)In: Information and Computer Security, E-ISSN 2056-4961Article, review/survey (Refereed) Epub ahead of print
Abstract [en]

Purpose: Although existing literature has advanced the understanding of information security policy (ISP) management, it has not examined how artificial intelligence (AI) can support ISP activities across management phases. Moreover, no study has yet mapped the empirical domains studied. The purpose of this paper is to systematically map existing ISP management research to assess to what extent AI has been addressed or used.

Design/methodology/approach: This study follows the five-step scoping review framework proposed by Arksey and O'Malley (2005): identifying the research questions, finding relevant studies, selecting studies, charting the data and reporting the results.

Findings: The review reveals that very few ISP management papers address or use AI. These few papers focused mostly on operational ISPs and addressed different ISP phases and empirical domains. Most existing work focuses on construction or compliance, while no studies have addressed the technical level. Research methods dominated by experiments, with a notable absence of organizational fieldwork. Research on ethical aspects such as fairness, transparency, accountability and data sensitivity is rare in this area.

Research limitations/implications: Given the limited research in this area, there are significant opportunities to explore AI in ISP management and to use AI in studying ISP management. The authors suggest a research agenda divided into three-time horizons: short, medium and long term.

Originality/value: This paper provides the first scoping review of AI in ISP management research, offering a systematic mapping of ISP management phases, ISP levels, research methods and empirical domains. It identifies research gaps, thereby guiding future research.

Place, publisher, year, edition, pages
Emerald Group Publishing Limited, 2026
Keywords
Information security policy, Artificial intelligence, Scoping review, ISP management
National Category
Information Systems, Social aspects
Identifiers
urn:nbn:se:oru:diva-127977 (URN)10.1108/ICS-09-2025-0357 (DOI)001710984500001 ()
Available from: 2026-03-16 Created: 2026-03-16 Last updated: 2026-03-16Bibliographically approved
Aro-Sati, L., Karlsson, F. & Gao, S. (2026). Towards Digital Sovereignty – How Reliable is LLAMA3. 3-70b in Classifying Information Security Policy Content as Speech Acts?. In: Sanjay Misra; Petter Kvalvik; Kai Kjølerbakken; Per-Arne Jørgensen (Ed.), 2nd International Conference on Digital Sovereignty: ICDS 2025. Conference proceedings. Paper presented at 2nd International Conference on Digital Sovereignty (ICDS 2025), Oslo, Norway, October 27-31, 2025 (pp. 229-239). Springer
Open this publication in new window or tab >>Towards Digital Sovereignty – How Reliable is LLAMA3. 3-70b in Classifying Information Security Policy Content as Speech Acts?
2026 (English)In: 2nd International Conference on Digital Sovereignty: ICDS 2025. Conference proceedings / [ed] Sanjay Misra; Petter Kvalvik; Kai Kjølerbakken; Per-Arne Jørgensen, Springer, 2026, p. 229-239Conference paper, Published paper (Refereed)
Abstract [en]

Employees need clear guidance in order to contribute to their organ-isation’s digital sovereignty. Information security policies (ISPs) should provide employees with this guidance, but existing research show that this is not always the case. Large language models (LLMs) could enhance ISPs if finetuned on high-quality data, but such fine-tuning requires a robust way to distinguish between statements in ISPs. Therefore, and as a first step in this direction, the aim of this paper is to investigate the consistency when a Generative pre-trained transformer-like model classifies information security policy (ISP) statements into speech acts using a zero-shot learning (ZSL) approach. We investigate the consistency of LLAMA3.3-70B when applying ZSL to classify 600 selected ISP statements into speech act classes derived from Speech Act Theory. The findings show that LLAMA3.3-70B achieves high similarity to human classification and demonstrates strong consistency across multiple runs per different temperature settings. Furthermore, changes in the temper-ature setting had a minimal effect, which means that the model produces stable clas-sifications. We conclude that LLAMA3.3-70B is a useful starting point for continued work on improving ISP content using LLMs. 

Place, publisher, year, edition, pages
Springer, 2026
Series
Springer Proceedings in Complexity, ISSN 2213-8684, E-ISSN 2213-8692
National Category
Artificial Intelligence
Research subject
Informatics
Identifiers
urn:nbn:se:oru:diva-130365 (URN)10.1007/978-3-032-21524-6_20 (DOI)001836292900020 ()2-s2.0-105046333956 (Scopus ID)9783032215239 (ISBN)9783032215246 (ISBN)
Conference
2nd International Conference on Digital Sovereignty (ICDS 2025), Oslo, Norway, October 27-31, 2025
Available from: 2026-07-28 Created: 2026-07-28 Last updated: 2026-09-03Bibliographically approved
Wedlund, A., Shekany, S., Karlsson, F. & Gao, S. (2026). When words lose their edge: a comparative analysis of information security policy keywords in the UK and Sweden. Information and Computer Security
Open this publication in new window or tab >>When words lose their edge: a comparative analysis of information security policy keywords in the UK and Sweden
2026 (English)In: Information and Computer Security, E-ISSN 2056-4961Article in journal (Refereed) Epub ahead of print
Abstract [en]

Purpose: The purpose of this paper is to analyse and compare how congruent keywords are used to convey actionable advice in UK and Swedish information security policies (ISPs).

Design/methodology/approach: The authors conducted a qualitative content analysis of 30 ISPs from higher education institutions, 15 from each country. To support analysis, the authors developed the ISP Keyword Analyzer software, which extracted 2,314 sentences containing analysed keywords. Each sentence was classified as actionable advice or other information. For comparison, the authors used the Keyword Loss of Specificity and Total Keyword Loss of Specificity metrics to measure how congruently keywords were used within each ISP.

Findings: The authors found two main patterns in keyword use. First, certain keywords are more prominent in ISPs from one country than the other, indicating differing importance across languages and national contexts. Second, the congruence in how keywords are used to convey actionable advice also varies. Swedish ISPs use keywords more congruently to guide employees towards action, whereas UK ISPs more often use them to convey other information than actionable advice.

Research limitations/implications: Differences in how ISPs are formulated across countries suggest that previous studies on ISP content and design are contextually bound.

Practical implications: The identified differences highlight how language and national context influence the clarity of ISPs, with implications for organisations operating in multilingual or international environments.

Originality/value: To the best of the authors' knowledge, this is the first study to compare how keywords are used in ISPs in different countries to express actionable advice.

Place, publisher, year, edition, pages
Emerald Group Publishing Limited, 2026
Keywords
Information security policy, Cybersecurity policy, Actionable advice, Policy design, Content analysis, Text analysis
National Category
Information Systems, Social aspects
Identifiers
urn:nbn:se:oru:diva-127975 (URN)10.1108/ICS-11-2025-0455 (DOI)001706908000001 ()2-s2.0-105039303468 (Scopus ID)
Available from: 2026-03-16 Created: 2026-03-16 Last updated: 2026-08-12Bibliographically approved
Havstorm, T. E., Karlsson, F. & Gao, S. (2025). Agile Software Development Method Cargo Cult - Devising an Analytical Tool. Information and Software Technology, 187, 1-13, Article ID 107851.
Open this publication in new window or tab >>Agile Software Development Method Cargo Cult - Devising an Analytical Tool
2025 (English)In: Information and Software Technology, ISSN 0950-5849, E-ISSN 1873-6025, Vol. 187, p. 1-13, article id 107851Article in journal (Refereed) Published
Abstract [en]

Context: Despite the widespread adoption of agile software development methods (ASDMs) today, many organizations struggle with effective implementation. One reason for this is that some organizations claim to use an ASDM without fully understanding its core principles, or they adhere to old practices while professing to follow a contemporary software development method. This phenomenon is sometimes referred to by practitioners as “cargo cult” (CC) behavior. However, simply labeling something as CC lacks analytical depth.

Objective: This paper aims to conceptualize and validate an analytical tool for diagnosing CC and non-CC behavior in software development teams’ use of ASDMs.

Method: This study uses a longitudinal ethnographic approach to conceptualize and validate the analytical tool by analyzing four agile practices used by a global industrial manufacturing company.

Results: The analytical tool features eight stereotypes—three representing non-CC behaviors and five representing CC behaviors—designed to aid in the analysis of ASDM usage. The tool draws on Social Action Theory and Work Motivation Theory to capture and interpret the CC phenomenon in ASDM use. Using the stereotypes, 36 actions were categorized as CC behavior deviating from documented ASDM practices, and 23 actions as non-CC behavior because they aligned with the documented ASDM and reflected agile goals and values. The tool thus can help both researchers and practitioners gain a deeper understanding of ASDM use in organizations.

Conclusion: This study advances understanding of ASDM use by moving beyond the simplistic use of the term “cargo cult”. The developed tool enables structured identification and classification of CC behaviors. The stereotypes provide a way of classifying recurring software development actions against the intended ASDM, allowing the identification of specific types of CC behaviors. The analytical tool enables managers to gain deeper insights into the underlying reasons for deviations, thereby supporting more grounded and effective agile practices within organizations.

Place, publisher, year, edition, pages
Elsevier, 2025
Keywords
Agile, Cargo cult, Deviations, Software development, Social action theory, Work motivation theory, Empirical study
National Category
Information Systems, Social aspects
Research subject
Informatics
Identifiers
urn:nbn:se:oru:diva-122454 (URN)10.1016/j.infsof.2025.107851 (DOI)001543133000002 ()2-s2.0-105011614848 (Scopus ID)
Available from: 2025-08-10 Created: 2025-08-10 Last updated: 2026-01-23Bibliographically approved
Rostami, E., Hanif, M., Karlsson, F. & Gao, S. (2025). Defining Actionable Advice in Information Security Policies - Guiding Employees to Strengthen Digital Sovereignty of Organizations. Procedia Computer Science, 254, 30-38
Open this publication in new window or tab >>Defining Actionable Advice in Information Security Policies - Guiding Employees to Strengthen Digital Sovereignty of Organizations
2025 (English)In: Procedia Computer Science, E-ISSN 1877-0509, Vol. 254, p. 30-38Article in journal (Refereed) Published
Abstract [en]

In today's digital age, protecting information assets is critical to maintain organizations’ digital sovereignty. Yet existing research offers limited guidance on creating effective, actionable advice in information security policies (ISPs) that instructs employees on how to carry out their tasks and contribute to protecting information assets. Addressing this gap, the aim of this paper is to propose a definition of actionable advice. A clear definition can aid in designing ISPs and enhance communication with employees, guiding them in the expected behavior to protect the organization’s information assets. The research question guiding this work is: how can actionable advice be defined in information security policies? To achieve this aim, the definition is informed by a literature review and analysis of 47 ISPs from public agencies in Sweden. The proposed definition of actionable advice is: a demarcated part of an ISP, that instructs someone on a task to execute or not to execute regarding information security, and, in case of execution, how to carry out the task. The definition of actionable advice provides researchers with a starting point to understand this term, helping advancing future studies on ISPs. This work also has practical implications for ISP developers, offering guidance on writing pieces of actionable advice that are concrete and directly applicable in employees' daily tasks to protect their organizations.

Place, publisher, year, edition, pages
Elsevier, 2025
Keywords
Actionable advice, information security policy, operational policy, compliance, cyber security policy
National Category
Security, Privacy and Cryptography
Identifiers
urn:nbn:se:oru:diva-122091 (URN)10.1016/j.procs.2025.02.061 (DOI)2-s2.0-105006422715 (Scopus ID)
Funder
Swedish Civil Contingencies Agency
Available from: 2025-06-29 Created: 2025-06-29 Last updated: 2026-08-12Bibliographically approved
Karlsson, F., Chatzipetrou, P., Gao, S. & Havstorm, T. E. (2025). Exploring Classification Consistency of Natural Language Requirements Using GPT-4o. In: Efi Papatheocharous; Siamak Farshidi; Slinger Jansen; Sonja Hyrynsalmi (Ed.), Software Business: 15th International Conference, ICSOB 2024, Utrecht, The Netherlands, November 18–20, 2024, Proceedings. Paper presented at 15th International Conference (ICSOB 2024), Utrecht, The Netherlands, November 18–20, 2024 (pp. 44-50). Springer, 539
Open this publication in new window or tab >>Exploring Classification Consistency of Natural Language Requirements Using GPT-4o
2025 (English)In: Software Business: 15th International Conference, ICSOB 2024, Utrecht, The Netherlands, November 18–20, 2024, Proceedings / [ed] Efi Papatheocharous; Siamak Farshidi; Slinger Jansen; Sonja Hyrynsalmi, Springer, 2025, Vol. 539, p. 44-50Conference paper, Published paper (Refereed)
Abstract [en]

Classifying natural language requirements (NLRs) is challenging, especially with large volumes. Research shows that Large Language Models can assist by categorizing NLRs into functional requirements (FR) and non-functional requirements (NFRs). However, Generative Pretrained Transformer (GPT) models are not typically favored for this task due to concerns about consistency. This paper investigates the consistency when a GPT model classifies NLRs into FRs and NFRs using a zero-shot learning approach. Results show that ChatGPT-4o performs better for FRs, a temperature parameter set to 1 yields the highest consistency, while NFR classification improves with higher temperatures.

Place, publisher, year, edition, pages
Springer, 2025
Series
Lecture Notes in Business Information Processing, ISSN 1865-1348, E-ISSN 1865-1356
Keywords
Requirements, Classification, Large Language Model, Zero-Shot Learning
National Category
Information Systems, Social aspects
Identifiers
urn:nbn:se:oru:diva-121182 (URN)10.1007/978-3-031-85849-9_4 (DOI)001476891400004 ()2-s2.0-105001270180 (Scopus ID)9783031858482 (ISBN)9783031858499 (ISBN)
Conference
15th International Conference (ICSOB 2024), Utrecht, The Netherlands, November 18–20, 2024
Available from: 2025-05-21 Created: 2025-05-21 Last updated: 2025-05-21Bibliographically approved
Karlsson, F. & Gao, S. (2025). Guest editorial: New frontiers in information security management. Information and Computer Security, 33(1), 1-4
Open this publication in new window or tab >>Guest editorial: New frontiers in information security management
2025 (English)In: Information and Computer Security, E-ISSN 2056-4961, Vol. 33, no 1, p. 1-4Article in journal, Editorial material (Other academic) Published
Place, publisher, year, edition, pages
Emerald Group Publishing Limited, 2025
National Category
Information Systems, Social aspects
Identifiers
urn:nbn:se:oru:diva-118853 (URN)10.1108/ICS-03-2025-265 (DOI)001398399300002 ()2-s2.0-85216242094 (Scopus ID)
Available from: 2025-01-28 Created: 2025-01-28 Last updated: 2025-02-11Bibliographically approved
Karlsson, F. & Gao, S. (2025). Guidelines for Longitudinal Information Security Policy Compliance Research. In: AMCIS 2025 Proceedings: . Paper presented at Americas Conference on Information Systems (AMCIS 2025), Montreal, Canada, August 14-16, 2025. Association for Information Systems, Article ID 1585.
Open this publication in new window or tab >>Guidelines for Longitudinal Information Security Policy Compliance Research
2025 (English)In: AMCIS 2025 Proceedings, Association for Information Systems, 2025, article id 1585Conference paper, Published paper (Refereed)
Abstract [en]

Over the years, numerous studies on employee compliance with information security policies (ISPs) have been conducted, contributing valuable insights to enhance information security in organisations. However, our literature review reveals that few ISP compliance studies adopt a longitudinal approach. It is well known that cross-sectional research often provides limited insight into how constructs such as ISP compliance evolve over time. While researchers have called for more longitudinal ISP compliance studies, there is little guidance on how to conduct them. To address this gap, we propose a set of seven guidelines to support both quantitative and qualitative longitudinal ISP compliance research.

Place, publisher, year, edition, pages
Association for Information Systems, 2025
Series
Proceedings of the Americas Conference on Information Systems, ISSN 3066-8743, E-ISSN 3066-876X
National Category
Information Systems, Social aspects
Research subject
Informatics
Identifiers
urn:nbn:se:oru:diva-124466 (URN)2-s2.0-105025197263 (Scopus ID)
Conference
Americas Conference on Information Systems (AMCIS 2025), Montreal, Canada, August 14-16, 2025
Available from: 2025-10-17 Created: 2025-10-17 Last updated: 2026-08-27Bibliographically approved
Karlsson, F., Chatzipetrou, P., Gao, S. & Havstorm, T. E. (2025). How Reliable Are GPT-4o and LLAMA3.3-70B in Classifying Natural Language Requirements? The Impact of the Temperature Setting. IEEE Software, 42(6), 97-104
Open this publication in new window or tab >>How Reliable Are GPT-4o and LLAMA3.3-70B in Classifying Natural Language Requirements? The Impact of the Temperature Setting
2025 (English)In: IEEE Software, ISSN 0740-7459, E-ISSN 1937-4194, Vol. 42, no 6, p. 97-104Article in journal (Refereed) Published
Abstract [en]

Classifying natural language requirements (NLRs) plays a crucial role in software engineering, helping us distinguish between functional and non-functional requirements. While large language models offer automation potential, we should address concerns about their consistency, meaning their ability to produce the same results over time. In this work, we share experiences from experimenting with how well GPT-4o and LLAMA3.3-70B classify NLRs using a zero-shot learning approach. Moreover, we explore how the temperature parameter influences classification performance and consistency for these models. Our results show that large language models like GPT-4o and LLAMA3.3- 70B can support automated NLRs classification. GPT-4o performs well in identifying functional requirements, with the highest consistency occurring at a temperature setting of one. Additionally, non-functional requirements classification improves at higher temperatures, indicating a trade-off between determinism and adaptability. LLAMA3.3-70B is more consistent than GPT-4o, and its classification accuracy varies less depending on temperature adjustments.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2025
Keywords
Software engineering, Predictive models, Accuracy, Transformers, Training, Natural languages, Temperature measurement, Software reliability, Natural language processing
National Category
Information Systems, Social aspects
Research subject
Informatics
Identifiers
urn:nbn:se:oru:diva-122267 (URN)10.1109/MS.2025.3572561 (DOI)001600046500002 ()2-s2.0-105006549832 (Scopus ID)
Available from: 2025-07-03 Created: 2025-07-03 Last updated: 2026-08-12Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-3265-7627

Search in DiVA

Show all publications