Developing an agile, analytics-based information security maturity framework for Malaysian SMEs: a systematic literature review

Abd Goni, Siti Zaleha and Harun, Qamarul Nazrin (2026) Developing an agile, analytics-based information security maturity framework for Malaysian SMEs: a systematic literature review. Journal of Information and Knowledge Management (JIKM), 16 (1). pp. 13-26. ISSN ISSN:2231-8836 ; E-ISSN:2289-5337

Official URL: https://journal.uitm.edu.my/ojs/index.php/JIKM

Identification Number (DOI): 10.24191/xjsx9r29

Abstract

In the age of technology, information security has become a critical component for small and medium enterprises (SMEs), which remain highly vulnerable to cyber risks. However, most Information Security Maturity Models (ISMMs) provide limited applicability to the SME context, particularly in Malaysia, due to resource constraints, complex systems, and organizational resistance to new methodologies. This study addresses this gap by conducting a narrative review that synthesizes 30 scholarly articles published between 2022 and 2025 across leading databases. The objectives of this study are to (i) classify existing ISMM models that are relevant to SMEs, (ii) assess the extent to which these models are suitable and easy to implement by SMEs, and (iii) explore the integration of agile development approaches and analytical technologies into security maturity models. The findings reveal the need for lighter and more flexible ISMM models that enable automated digital self-assessment. Accordingly, this article proposes a conceptual three- dimensional framework that integrates agility, SME suitability, and analytic functionalities as the foundation for a contextualized ISMM for SMEs in Malaysia.

Metadata

Item Type: Article
Creators:
Creators
Email / ID Num.
Abd Goni, Siti Zaleha
sitizaleha.ag@gmail.com
Harun, Qamarul Nazrin
qamarulnazrin@uitm.edu.my
Subjects: H Social Sciences > HD Industries. Land use. Labor > Small business. Medium-sized business
Q Science > QA Mathematics > Computers and civilization. Social aspects of computers. Hackers
T Technology > T Technology (General) > Information technology. Information systems
Divisions: Universiti Teknologi MARA, Selangor > Puncak Perdana Campus > Faculty of Information Management
Journal or Publication Title: Journal of Information and Knowledge Management (JIKM)
ISSN: ISSN:2231-8836 ; E-ISSN:2289-5337
Volume: 16
Number: 1
Page Range: pp. 13-26
Keywords: Agile, Information security, Security maturity, Malaysian SME's, Analytics
Date: April 2026
URI: https://ir.uitm.edu.my/id/eprint/134960
Edit Item
Edit Item

Download

[thumbnail of 134960.pdf] Text
134960.pdf

Download (448kB)

ID Number

134960

Indexing

Altmetric
PlumX
Dimensions

Statistic

Statistic details