1. Broderick, J.S.: Information security management – when should it be managed? Inf. Secur. Tech. Rep. 3, 12–16 (2001)
2. ISO/IEC 17799: International Standard ISO/IEC 17799:2000 Code of Practice for Information Security Management, International Organization for Standardization/International Electrotechnical Commission (2012)
3. de Sá-Soares, F.: A theory of action interpretation of information systems security. Ph.D. thesis, University of Minho, Guimarães (2005)
4. Wood, L.: Writing InfoSec policies. Compute. Secur. 14(8), 667–674 (1995)
5. Carr, N.G.: It doesn’t matter. Harvard Bus. Rev. 41–9 (2003)