Fredrik Karlsson 0001

dblp:54/4340 · also Fredrik J. Karlsson · DBLP profile ↗
← Back
31ranked-venue papers
15as first author
9since 2021 · last 2025
0000-0002-3265-7627ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 8 first-author · 7 since 2021Databases, data management, data science and information retrieval · 9 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 5 · 3 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Towards software for tailoring information security policies to organisations' different target groups
Elham Rostami, Fredrik Karlsson 0001, Ella Kolkowska, Shang Gao 0002
Comput. Secur.2
2025 Guest editorial: New frontiers in information security management
Fredrik Karlsson 0001, Shang Gao 0002
Inf. Comput. Secur.1
2025 Agile software development method cargo cult - Devising an analytical tool
abstract
Despite the widespread adoption of agile software development methods (ASDMs) today, many organizations struggle with effective implementation. One reason for this is that some organizations claim to use an ASDM without fully understanding its core principles, or they adhere to old practices while professing to follow a contemporary software development method. This phenomenon is sometimes referred to by practitioners as “cargo cult” (CC) behavior. However, simply labeling something as CC lacks analytical depth. This paper aims to conceptualize and validate an analytical tool for diagnosing CC and non-CC behavior in software development teams’ use of ASDMs. This study uses a longitudinal ethnographic approach to conceptualize and validate the analytical tool by analyzing four agile practices used by a global industrial manufacturing company. The analytical tool features eight stereotypes—three representing non-CC behaviors and five representing CC behaviors—designed to aid in the analysis of ASDM usage. The tool draws on Social Action Theory and Work Motivation Theory to capture and interpret the CC phenomenon in ASDM use. Using the stereotypes, 36 actions were categorized as CC behavior deviating from documented ASDM practices, and 23 actions as non-CC behavior because they aligned with the documented ASDM and reflected agile goals and values. The tool thus can help both researchers and practitioners gain a deeper understanding of ASDM use in organizations. This study advances understanding of ASDM use by moving beyond the simplistic use of the term “cargo cult”. The developed tool enables structured identification and classification of CC behaviors. The stereotypes provide a way of classifying recurring software development actions against the intended ASDM, allowing the identification of specific types of CC behaviors. The analytical tool enables managers to gain deeper insights into the underlying reasons for deviations, thereby supporting more grounded and effective agile practices within organizations.
Tanja Elina Havstorm, Fredrik Karlsson 0001, Shang Gao 0002
Inf. Softw. Technol.2
2024 Qualitative content analysis of actionable advice in information security policies - introducing the keyword loss of specificity metric
abstract
Purpose This paper aims to investigate how congruent keywords are used in information security policies (ISPs) to pinpoint and guide clear actionable advice and suggest a metric for measuring the quality of keyword use in ISPs. Design/methodology/approach A qualitative content analysis of 15 ISPs from public agencies in Sweden was conducted with the aid of Orange Data Mining Software. The authors extracted 890 sentences from these ISPs that included one or more of the analyzed keywords. These sentences were analyzed using the new metric – keyword loss of specificity – to assess to what extent the selected keywords were used for pinpointing and guiding actionable advice. Thus, the authors classified the extracted sentences as either actionable advice or other information, depending on the type of information conveyed. Findings The results show a significant keyword loss of specificity in relation to pieces of actionable advice in ISPs provided by Swedish public agencies. About two-thirds of the sentences in which the analyzed keywords were used focused on information other than actionable advice. Such dual use of keywords reduces the possibility of pinpointing and communicating clear, actionable advice. Research limitations/implications The suggested metric provides a means to assess the quality of how keywords are used in ISPs for different purposes. The results show that more research is needed on how keywords are used in ISPs. Practical implications The authors recommended that ISP designers exercise caution when using keywords in ISPs and maintain coherency in their use of keywords. ISP designers can use the suggested metrics to assess the quality of actionable advice in their ISPs. Originality/value The keyword loss of specificity metric adds to the few quantitative metrics available to assess ISP quality. To the best of the authors’ knowledge, applying this metric is a first attempt to measure the quality of actionable advice in ISPs.
Elham Rostami, Fredrik Karlsson 0001
Inf. Comput. Secur.2
2023 Policy components - a conceptual model for modularizing and tailoring of information security policies
abstract
Purpose This paper aims to propose a conceptual model of policy components for software that supports modularizing and tailoring of information security policies (ISPs). Design/methodology/approach This study used a design science research approach, drawing on design knowledge from the field of situational method engineering. The conceptual model was developed as a unified modeling language class diagram using existing ISPs from public agencies in Sweden. Findings This study’s demonstration as proof of concept indicates that the conceptual model can be used to create free-standing modules that provide guidance about information security in relation to a specific work task and that these modules can be used across multiple tailored ISPs. Thus, the model can be considered as a step toward developing software to tailor ISPs. Research limitations/implications The proposed conceptual model bears several short- and long-term implications for research. In the short term, the model can act as a foundation for developing software to design tailored ISPs. In the long term, having software that enables tailorable ISPs will allow researchers to do new types of studies, such as evaluating the software's effectiveness in the ISP development process. Practical implications Practitioners can use the model to develop software that assist information security managers in designing tailored ISPs. Such a tool can offer the opportunity for information security managers to design more purposeful ISPs. Originality/value The proposed model offers a detailed and well-elaborated starting point for developing software that supports modularizing and tailoring of ISPs.
Elham Rostami, Fredrik Karlsson 0001, Shang Gao 0002
Inf. Comput. Secur.2
2022 Information security policy compliance-eliciting requirements for a computerized software to support value-based compliance analysis
abstract
When end users have to prioritize between different rationalities in organisations there is a risk of non-compliance with information security policies. Thus, in order for information security managers to align information security with the organisations’ core work practices, they need to understand the competing rationalities. The Value-based compliance (VBC) analysis method has been suggested to this end, however it has proven to be complex and time-consuming. Computerized software may aid this type of analysis and make it more efficient and executable. The purpose of this paper is to elicit a set of requirements for computerized software that support analysis of competing rationalities in relation to end users’ compliance and non-compliance with information security policies. We employed a design science research approach, drawing on design knowledge on VBC and elicited 17 user stories. These requirements can direct future research efforts to develop computerized software in this area.
Fredrik Karlsson 0001, Ella Kolkowska, Johan Petersson
Comput. Secur.1
2022 "Standardizing information security - a structurational analysis"
abstract
Given that there are an increasing number of information security breaches, organizations are being driven to adopt best practice for coping with attacks. Information security standards are designed to embody best practice and the legitimacy of these standards is a core issue for standardizing organizations. This study uncovers how structures at play in de jure standard development affect the input and throughput legitimacy of standards. We participated as members responsible for standards on information security and our analysis revealed two structures: consensus and warfare. A major implication of the combination of these structures is that legitimacy claims based on appeals to best practice are futile because it is difficult to know which the best practice is.
Annika Andersson, Karin Hedström, Fredrik Karlsson 0001
Inf. Manag.3
2022 The effect of perceived organizational culture on employees' information security compliance
abstract
Purpose This paper aims to investigate the connection between different perceived organizational cultures and information security policy compliance among white-collar workers. Design/methodology/approach The survey using the Organizational Culture Assessment Instrument was sent to white-collar workers in Sweden ( n = 674), asking about compliance with information security policies. The survey instrument is an operationalization of the Competing Values Framework that distinguishes between four different types of organizational culture: clan, adhocracy, market and bureaucracy. Findings The results indicate that organizational cultures with an internal focus are positively related to employees’ information security policy compliance. Differences in organizational culture with regards to control and flexibility seem to have less effect. The analysis shows that a bureaucratic form of organizational culture is most fruitful for fostering employees’ information security policy compliance. Research limitations/implications The results suggest that differences in organizational culture are important for employees’ information security policy compliance. This justifies further investigating the mechanisms linking organizational culture to information security compliance. Practical implications Practitioners should be aware that the different organizational cultures do matter for employees’ information security compliance. In businesses and the public sector, the authors see a development toward customer orientation and marketization, i.e. the opposite an internal focus, that may have negative ramifications for the information security of organizations. Originality/value Few information security policy compliance studies exist on the consequences of different organizational/information cultures.
Martin Karlsson, Fredrik Karlsson 0001, Joachim Åström, Thomas Denk
Inf. Comput. Secur.2
2021 Developing an information classification method
abstract
Purpose The purpose of this paper is to develop a method for information classification. The proposed method draws on established standards, such as the ISO/IEC 27002 and information classification practices. The long-term goal of the method is to decrease the subjective judgement in the implementation of information classification in organisations, which can lead to information security breaches because the information is under- or over-classified. Design/methodology/approach The results are based on a design science research approach, implemented as five iterations spanning the years 2013 to 2019. Findings The paper presents a method for information classification and the design principles underpinning the method. The empirical demonstration shows that senior and novice information security managers perceive the method as a useful tool for classifying information assets in an organisation. Research limitations/implications Existing research has, to a limited extent, provided extensive advice on how to approach information classification in organisations systematically. The method presented in this paper can act as a starting point for further research in this area, aiming at decreasing subjectivity in the information classification process. Additional research is needed to fully validate the proposed method for information classification and its potential to reduce the subjective judgement. Practical implications The research contributes to practice by offering a method for information classification. It provides a hands-on-tool for how to implement an information classification process. Besides, this research proves that it is possible to devise a method to support information classification. This is important, because, even if an organisation chooses not to adopt the proposed method, the very fact that this method has proved useful should encourage any similar endeavour. Originality/value The proposed method offers a detailed and well-elaborated tool for information classification. The method is generic and adaptable, depending on organisational needs.
Erik Bergström, Fredrik Karlsson 0001, Rose-Mharie Åhlfeldt
Inf. Comput. Secur.2
2020 Consensus versus warfare - unveiling discourses in de jure information security standard development
abstract
Information security standards are influential tools in society today. The validity claim of standards is based on what is considered “best practice.” We unveil the negotiations that take place when “best practice” is constructed during standard development. By using discourse analysis, we investigate how power operates in national and international contexts of de jure information security standard development work. As members of a standardization committee, we analyzed the language used by this committee. The results showed two discourses at play: the consensus discourse and the warfare discourse. We conclude by proposing six theoretical propositions on how power operates in the above-mentioned contexts of de jure standard development.
Annika Andersson, Fredrik Karlsson 0001, Karin Hedström
Comput. Secur.2
2020 Requirements for computerized tools to design information security policies
abstract
Information security is a hot topic nowadays, and while top-class technology exists to safeguard information assets, organizations cannot rely on technical controls alone. Information security policy (ISP) is one of the most important formal controls when organizations work with implementing information security. However, designing ISPs is a challenging task for information security managers and to ease the burden, computerized tools have been suggested to support this design task. One important prerequisite for developing such tools is the requirements. However, existing research has, to a very limited extent, synthesized existing requirements. Against this backdrop, this study aims to elicit a set of requirements, anchored in existing ISP research, for computerized tools that support ISP design. First, we summarize existing ISP research into 14 requirement themes. Second, we suggest a set of user stories that operationalize these requirement themes from an information security manager's perspective. Third, we suggest another set of user stories that operationalize the same requirement themes from an ISP user's perspective. In total, we suggest 28 user stories that can act as a starting point for both researchers and practitioners when developing computerized tools that provide ISP design support for information security managers.
Elham Rostami, Fredrik Karlsson 0001, Shang Gao 0002
Comput. Secur.2
2020 Artefactual and empirical contributions in information systems research
abstract
To qualify for publication in a top-tier information systems (IS) journal, such as the European Journal of Information Systems (EJIS), an article must make a substantial contribution to knowledge. ...
Pär J. Ågerfalk, Fredrik Karlsson 0001
Eur. J. Inf. Syst.2
2020 The hunt for computerized support in information security policy management
abstract
Purpose The purpose of this paper is to survey existing information security policy (ISP) management research to scrutinise the extent to which manual and computerised support has been suggested, and the way in which the suggested support has been brought about. Design/methodology/approach The results are based on a literature review of ISP management research published between 1990 and 2017. Findings Existing research has focused mostly on manual support for managing ISPs. Very few papers have considered computerised support. The entire complexity of the ISP management process has received little attention. Existing research has not focused much on the interaction between the different ISP management phases. Few research methods have been used extensively and intervention-oriented research is rare. Research limitations/implications Future research should to a larger extent address the interaction between the ISP management phases, apply more intervention research to develop computerised support for ISP management, investigate to what extent computerised support can enhance integration of ISP management phases and reduce the complexity of such a management process. Practical implications The limited focus on computerised support for ISP management affects the kind of advice and artefacts the research community can offer to practitioners. Originality/value Today, there are no literature reviews on to what extent computerised support the ISP management process. Findings on how the complexity of ISP management has been addressed and the research methods used extend beyond the existing knowledge base, allowing for a critical discussion of existing research and future research needs.
Elham Rostami, Fredrik Karlsson 0001, Ella Kolkowska
Inf. Comput. Secur.2
2018 Guest editorial
Fredrik Karlsson 0001, Ella Kolkowska, Marianne Törner
Inf. Comput. Secur.1
2017 Practice-based discourse analysis of information security policies
Fredrik Karlsson 0001, Karin Hedström, Göran Goldkuhl
Comput. Secur.1
2017 Measuring employees' compliance - the importance of value pluralism
abstract
Purpose This paper aims to investigate two different types of compliance measures: the first measure is a value-monistic compliance measure, whereas the second is a value-pluralistic measure, which introduces the idea of competing organisational imperatives. Design/methodology/approach A survey was developed using two sets of items to measure compliance. The survey was sent to 600 white-collar workers and analysed through ordinary least squares. Findings The results suggest that when using the value-monistic measure, employees’ compliance was a function of employees’ intentions to comply, their self-efficacy and awareness of information security policies. In addition, compliance was not related to the occurrence of conflicts between information security and other organisational imperatives. However, when the dependent variable was changed to a value-pluralistic measure, the results suggest that employees’ compliance was, to a great extent, a function of the occurrence of conflicts between information security and other organisational imperatives, indirect conflicts with other organisational values. Research limitations/implications The results are based on small survey; yet, the findings are interesting and justify further investigation. The results suggest that relevant organisational imperatives and value systems, along with information security values, should be included in measures for employees’ compliance with information security policies. Practical implications Practitioners and researchers should be aware that there is a difference in measuring employees’ compliance using value monistic and value pluralism measurements. Originality/value Few studies exist that critically compare the two different compliance measures for the same population.
Fredrik Karlsson 0001, Martin Karlsson, Joachim Åström
Inf. Comput. Secur.1
2017 Towards analysing the rationale of information security non-compliance: Devising a Value-Based Compliance analysis method
abstract
Employees’ poor compliance with information security policies is a perennial problem. Current information security analysis methods do not allow information security managers to capture the rationalities behind employees’ compliance and non-compliance. To address this shortcoming, this design science research paper suggests: (a) a Value-Based Compliance analysis method and (b) a set of design principles for methods that analyse different rationalities for information security. Our empirical demonstration shows that the method supports a systematic analysis of why employees comply/do not comply with policies. Thus we provide managers with a tool to make them more knowledgeable about employees’ information security behaviours.
Ella Kolkowska, Fredrik Karlsson 0001, Karin Hedström
J. Strateg. Inf. Syst.2
2016 Inter-organisational information security: a systematic literature review
abstract
Purpose The purpose of this paper is to survey existing inter-organisational information security research to scrutinise the kind of knowledge that is currently available and the way in which this knowledge has been brought about. Design/methodology/approach The results are based on a literature review of inter-organisational information security research published between 1990 and 2014. Findings The authors conclude that existing research has focused on a limited set of research topics. A majority of the research has focused management issues, while employees’/non-staffs’ actual information security work in inter-organisational settings is an understudied area. In addition, the majority of the studies have used a subjective/argumentative method, and few studies combine theoretical work and empirical data. Research limitations/implications The findings suggest that future research should address a broader set of research topics, focusing especially on employees/non-staff and their use of processes and technology in inter-organisational settings, as well as on cultural aspects, which are lacking currently; focus more on theory generation or theory testing to increase the maturity of this sub-field; and use a broader set of research methods. Practical implications The authors conclude that existing research is to a large extent descriptive, philosophical or theoretical. Thus, it is difficult for practitioners to adopt existing research results, such as governance frameworks, which have not been empirically validated. Originality/value Few systematic reviews have assessed the maturity of existing inter-organisational information security research. Findings of authors on research topics, maturity and research methods extend beyond the existing knowledge base, which allow for a critical discussion about existing research in this sub-field of information security.
Fredrik Karlsson 0001, Ella Kolkowska, Frans Prenkert
Inf. Comput. Secur.1
2015 Practice-Based Discourse Analysis of InfoSec Policies
Fredrik Karlsson 0001, Göran Goldkuhl, Karin Hedström
SEC1
2015 Information security culture - state-of-the-art review between 2000 and 2013
abstract
Purpose – The aim of this paper is to survey existing information security culture research to scrutinise the kind of knowledge that has been developed and the way in which this knowledge has been brought about. Design/methodology/approach – Results are based on a literature review of information security culture research published between 2000 and 2013 (December). Findings – This paper can conclude that existing research has focused on a broad set of research topics, but with limited depth. It is striking that the effects of different information security cultures have not been part of that focus. Moreover, existing research has used a small repertoire of research methods, a repertoire that is more limited than in information systems research in general. Furthermore, an extensive part of the research is descriptive, philosophical or theoretical – lacking a structured use of empirical data – which means that it is quite immature. Research limitations/implications – Findings call for future research that: addresses the effects of different information security cultures; addresses the identified research topics with greater depth; focuses more on generating theories or testing theories to increase the maturity of this subfield of information security research; and uses a broader set of research methods. It would be particularly interesting to see future studies that use intervening or ethnographic approaches because, to date, these have been completely lacking in existing research. Practical implications – Findings show that existing research is, to a large extent, descriptive, philosophical or theoretical. Hence, it is difficult for practitioners to adopt these research results, such as frameworks for cultivating or assessment tools, which have not been empirically validated. Originality/value – Few state-of-the-art reviews have sought to assess the maturity of existing research on information security culture. Findings on types of research methods used in information security culture research extend beyond the existing knowledge base, which allows for a critical discussion about existing research in this sub-discipline of information security.
Fredrik Karlsson 0001, Joachim Åström, Martin Karlsson
Inf. Comput. Secur.1
2013 Longitudinal use of method rationale in method configuration: an exploratory study
abstract
Organizations that implement a company-wide method to standardize the way that systems development is carried out still have a need to adapt this method to specific projects. When adapting this method the end results should align with the basic philosophy of the original method. To this end, goal-driven situational method engineering has been proposed. However, there are no longitudinal studies on systems developers’ use of such approaches and their intentions to balance their need of adaptation with the basic philosophy of the original method. This paper explores how goal-driven method configuration has been used by two project teams in six successive systems development projects, with the intention to balance the goals and values of a specific method with the systems developers’ need for method adaptation. We do that through the use of method rationality resonance theory. Through content examples of method configurations, we report on (a) lessons learned from the project teams’ work on balancing the goals of the company-wide method with their needs and (b) theoretical development of the method rationality resonance theory.
Fredrik Karlsson 0001
Eur. J. Inf. Syst.1
2013 Social action theory for understanding information security non-compliance in hospitals: The importance of user rationale
abstract
Purpose – Employees' compliance with information security policies is considered an essential component of information security management. The research aims to illustrate the usefulness of social action theory (SAT) for management of information security. Design/methodology/approach – This research was carried out as a longitudinal case study at a Swedish hospital. Data were collected using a combination of interviews, information security documents, and observations. Data were analysed using a combination of a value-based compliance model and the taxonomy laid out in SAT to determine user rationality. Findings – The paper argues that management of information security and design of countermeasures should be based on an understanding of users' rationale covering both intentional and unintentional non-compliance. The findings are presented in propositions with practical and theoretical implications: P1. Employees' non-compliance is predominantly based on means-end calculations and based on a practical rationality, P2. An information security investigation of employees' rationality should not be based on an a priori assumption about user intent, P3. Information security management and choice of countermeasures should be based on an understanding of the use rationale, and P4. Countermeasures should target intentional as well as unintentional non-compliance. Originality/value – This work is an extension of Hedström et al. arguing for the importance of addressing user rationale for successful management of information security. The presented propositions can form a basis for information security management, making the objectives underlying the study presented in Hedström et al. more clear.
Karin Hedström, Fredrik Karlsson 0001, Ella Kolkowska
Inf. Manag. Comput. Secur.2
2012 MC Sandbox: Devising a tool for method-user-centered method configuration
Fredrik Karlsson 0001, Pär J. Ågerfalk
Inf. Softw. Technol.1
2011 Value conflicts for information security management
Karin Hedström, Ella Kolkowska, Fredrik Karlsson 0001, Jonathan P. Allen
J. Strateg. Inf. Syst.3
2010 Using Actor Network Theory to Understand Information Security Management
Karin Hedström, Gurpreet Dhillon, Fredrik Karlsson 0001
SEC3
2009 Exploring agile values in method configuration
abstract
The Method for Method Configuration (MMC) has been proposed as a method engineering approach to tailoring information systems development methods. This meta-method has been used on a variety of methods, but none of these studies have focused on the ability to manage method tailoring with the intention to promote specific values and goals, such as agile ones. This paper explores how MMC has been used during three software development projects to manage method tailoring with the intention to promote agile goals and values. Through content examples of method configurations we have shown that it is possible to use MMC and its conceptual framework on eXtreme Programming and we report on lessons learned with regard to maintaining coherency with the overall goals of the original method.
Fredrik Karlsson 0001, Pär J. Ågerfalk
Eur. J. Inf. Syst.1
2009 Towards Structured Flexibility in Information Systems Development: Devising a Method for Method Configuration
abstract
Method configuration is a specific type of Method Engineering (ME) that takes an existing organization-wide Information Systems Development Method (ISDM) as its point of departure. Existing assembly-based ME approaches are not well suited to this task. As an alternative, this article suggests a metamethod approach to tailoring organization-wide ISDMs. We refer to this approach as the Method for Method Configuration (MMC). MMC takes into account the need to combine structure, which is one reason for choosing an organization-wide ISDM in the first place, with flexibility, which is essential for making the chosen ISDM fit actual projects. The metamethod is built using a three-layered reuse model comprising method components, configuration packages, and configuration templates. These concepts are combined efficiently to produce a situational method and thereby to facilitate the work of method engineers.
Fredrik Karlsson 0001, Pär J. Ågerfalk
J. Database Manag.1
2008 Method Configuration: The eXtreme Programming Case
Fredrik Karlsson 0001, Pär J. Ågerfalk
XP1
2006 Combining method engineering with activity theory: theoretical grounding of the method component concept
abstract
The complex and demanding business of developing information systems often involves the use of different systems development methods such as the Rational Unified Process or the Microsoft Solution Framework. Through these methods the development organisation can be viewed as a collective of actors following different rules in the form of prescribed actions in order to guide a work process in accord with activity theory. Very often standardised systems development methods need tailoring for unique projects and strategies for this process have been labelled method engineering. Method configuration, a sub-discipline to method engineering, is applicable in situations where a single base method is used as a starting point for the engineering process. A meta-method (method for method configuration) has been developed addressing these issues. A fundamental part of this meta-method is the method component construct as a means to facilitate efficient and rationally motivated modularisation of systems development methods. This paper is an exploration of possible benefits of combining activity theory and method engineering as theoretical grounding of the method component concept.
Fredrik Karlsson 0001, Kai Wistrand
Eur. J. Inf. Syst.1
2004 Method Components - Rationale Revealed
Kai Wistrand, Fredrik Karlsson 0001
CAiSE2
2004 Method configuration: adapting to situational characteristics while creating reusable assets
Fredrik Karlsson 0001, Pär J. Ågerfalk
Inf. Softw. Technol.1