Abstract
Driven by escalating threats and regulatory scrutiny, information security risk management (ISRM) is now a strategic imperative for organizations across the industrial spectrum. Although prior literature reviews offer valuable insights into ISRM subdomains, they remain fragmented and overly reliant on manual methods, limiting their scope and scalability. Additionally, only limited reviews have been able to comprehensively synthesize ISRM literature across its three foundational pillars: processes, governance, and strategy. To address this gap, we conduct a large-scale systematic literature review of 623 ISRM-related articles using a mixed-methods approach which combines natural language processing techniques with thematic analysis. We identify 22 thematic clusters and aggregate them into an integrated framework comprising three interdependent perspectives: Technical, Socio-Behavioral, and Strategic & Governance. Our integrated framework bridges disciplinary silos to inform research opportunities at the intersection of technical controls, human behavior, and strategic oversight.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License.
Publication Date
5-5-2026
Document Type
Article
Department, Program, or Center
MIS, Marketing, and Analytics Department
College
Saunders College of Business
Recommended Citation
Varghese, B. B., & Bui, Q. (2026). An integrated framework for information security risk management: A mixed-methods systematic literature review. Computers & Security, 104957.
Campus
RIT – Main Campus
