To Örebro University

oru.seÖrebro University Publications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Defining Actionable Advice in Information Security Policies - Guiding Employees to Strengthen Digital Sovereignty of Organizations
Örebro University, Örebro University School of Business. Department of Informatics.ORCID iD: 0000-0002-4439-4713
Örebro University, Örebro University School of Business. Department of Informatics.
Örebro University, Örebro University School of Business. Department of Informatics.ORCID iD: 0000-0002-3265-7627
Örebro University, Örebro University School of Business. Department of Informatics.ORCID iD: 0000-0002-3722-6797
2025 (English)In: Procedia Computer Science, E-ISSN 1877-0509, Vol. 254, p. 30-38Article in journal (Refereed) Published
Abstract [en]

In today's digital age, protecting information assets is critical to maintain organizations’ digital sovereignty. Yet existing research offers limited guidance on creating effective, actionable advice in information security policies (ISPs) that instructs employees on how to carry out their tasks and contribute to protecting information assets. Addressing this gap, the aim of this paper is to propose a definition of actionable advice. A clear definition can aid in designing ISPs and enhance communication with employees, guiding them in the expected behavior to protect the organization’s information assets. The research question guiding this work is: how can actionable advice be defined in information security policies? To achieve this aim, the definition is informed by a literature review and analysis of 47 ISPs from public agencies in Sweden. The proposed definition of actionable advice is: a demarcated part of an ISP, that instructs someone on a task to execute or not to execute regarding information security, and, in case of execution, how to carry out the task. The definition of actionable advice provides researchers with a starting point to understand this term, helping advancing future studies on ISPs. This work also has practical implications for ISP developers, offering guidance on writing pieces of actionable advice that are concrete and directly applicable in employees' daily tasks to protect their organizations.

Place, publisher, year, edition, pages
Elsevier, 2025. Vol. 254, p. 30-38
Keywords [en]
Actionable advice, information security policy, operational policy, compliance, cyber security policy
National Category
Security, Privacy and Cryptography
Identifiers
URN: urn:nbn:se:oru:diva-122091DOI: 10.1016/j.procs.2025.02.061OAI: oai:DiVA.org:oru-122091DiVA, id: diva2:1978895
Funder
Swedish Civil Contingencies AgencyAvailable from: 2025-06-29 Created: 2025-06-29 Last updated: 2025-07-23Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Rostami, ElhamHanif, MuhammadKarlsson, FredrikGao, Shang

Search in DiVA

By author/editor
Rostami, ElhamHanif, MuhammadKarlsson, FredrikGao, Shang
By organisation
Örebro University School of Business
In the same journal
Procedia Computer Science
Security, Privacy and Cryptography

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 47 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf