Overview of the main literature contributions on CSCRM
| Cyber risks in supply chains | Sources of cyber risks | Responsibility and ownership of the CSCRM process | Information exchanged in the supply chain | Initiatives and countermeasures to manage cyber risks | Methodology | Focus of the analysis | |
|---|---|---|---|---|---|---|---|
| Bandyopadhyay et al. (2010) | ✓ | Quantitative | Investments in cyber security | ||||
| Bartol (2014) | ✓ | ✓ | Conceptual | Cyber security standards, processes, tools and techniques | |||
| Boone (2017) | ✓ | ✓ | Conceptual | Cyber security in the organizations | |||
| Boyson (2014) | ✓ | ✓ | Conceptual | Definition of the concept of CSCRM | |||
| Charitoudi and Blyth (2014) | ✓ | ✓ | ✓ | Qualitative | Estimation of the impacts of cyber attacks | ||
| Colicchia et al. (2019) | ✓ | ✓ | ✓ | ✓ | Qualitative | CSCRM initiatives and actions in the supply chain | |
| Deane et al. (2009) | ✓ | Quantitative | Quantification of IT security risks in the supply chain | ||||
| Eling and Wirfs (2019) | ✓ | ✓ | Quantitative | Assessment of cyber risks and related costs | |||
| Ezhei and Tork Ladani (2018) | ✓ | ✓ | Quantitative | Impact of interconnectivity on security investments | |||
| Faisal et al. (2007) | ✓ | ✓ | Quantitative | Assessment of information risks | |||
| Gaudenzi and Siciliano (2017) | ✓ | Qualitative | Evaluation of perceptions on cyber risks | ||||
| Ghadge et al. (2020) | ✓ | ✓ | ✓ | Conceptual | Review on CSCRM | ||
| Gordon and Ford (2006) | ✓ | Qualitative | Classification of cyber crime | ||||
| Järveläinen (2013) | ✓ | ✓ | Quantitative | Continuity management in information systems | |||
| Jones and Horowitz (2012) | ✓ | Qualitative | Definition of system-aware cyber security architecture | ||||
| Keegan (2014) | ✓ | Conceptual | Insurance policies on information and data | ||||
| Khursheed et al. (2016) | ✓ | ✓ | ✓ | Conceptual | Job profiles for cyber security | ||
| Kim and Im (2014) | ✓ | Conceptual | Issues of cyber supply chain security in Korea | ||||
| Lee and Whang (2000) | ✓ | Conceptual | Information shared in a supply chain | ||||
| Li and Xu (2020) | ✓ | ✓ | Quantitative | Impact of interconnectivity on security investments | |||
| Linton et al. (2014) | ✓ | Conceptual | Introduction to the concept of cyber supply chain security | ||||
| Lotfi et al. (2013) | ✓ | Conceptual | Information shared in a supply chain | ||||
| Luiijf et al. (2013) | ✓ | ✓ | ✓ | Qualitative | National cyber security strategies | ||
| Mukhopadhyay et al. (2013) | ✓ | ✓ | Quantitative | Decision models for cyber risk insurance | |||
| Pandey et al. (2020) | ✓ | ✓ | ✓ | Qualitative | Cyber risks in the global supply chain | ||
| Radanliev et al. (2020) | ✓ | ✓ | Conceptual | Cognitive data analytics for stronger resilience in the cyber space | |||
| Secci and Murugesan (2014) | ✓ | ✓ | Conceptual | Cloud resiliency and IT operational resilience measures | |||
| Sharma and Routroy (2016) | ✓ | Quantitative | Models of information risk | ||||
| Sindhuja (2014) | ✓ | Quantitative | Impact of information security initiatives on supply chain performance | ||||
| Sindhuja and Kunnathur (2015) | ✓ | ✓ | Conceptual | Review on information security management | |||
| Smith et al. (2007) | ✓ | ✓ | Quantitative | Trade-off between collaboration and cyber security | |||
| Spekman and Davis (2004) | ✓ | Conceptual | Risks across the extended enterprise | ||||
| Stephens and Valverde (2013) | ✓ | ✓ | ✓ | Qualitative | Cyber security, threat models, security policies for e-procurement | ||
| Tao et al. (2016) | ✓ | ✓ | Quantitative | Information sharing and disruptions in a supply chain | |||
| Tran et al. (2016) | ✓ | ✓ | ✓ | Qualitative | Supply chain managers perceptions of risks related to information sharing | ||
| Trombley (2015) | ✓ | ✓ | Qualitative | Information risk management | |||
| Urciuoli and Hintsa (2017) | ✓ | ✓ | ✓ | Qualitative | Security threats in supply chains | ||
| Volpentesta et al. (2011) | ✓ | ✓ | Quantitative | Effects of incident security awareness on information risk perception | |||
| Warren and Hutchinson (2000) | ✓ | ✓ | Conceptual | Cyber-attacks to supply chains and some seminal countermeasures | |||
| Windelberg (2016) | ✓ | ✓ | Conceptual | Objectives for managing cyber supply chain risk | |||
| Xue et al. (2013) | ✓ | ✓ | ✓ | Quantitative | Supply chain digitization and IT governance | ||
| Zuo and Hu (2009) | ✓ | ✓ | Conceptual | Trust-based information risk management in a supply chain |
| Cyber risks in supply chains | Sources of cyber risks | Responsibility and ownership of the CSCRM process | Information exchanged in the supply chain | Initiatives and countermeasures to manage cyber risks | Methodology | Focus of the analysis | |
|---|---|---|---|---|---|---|---|
| ✓ | Quantitative | Investments in cyber security | |||||
| ✓ | ✓ | Conceptual | Cyber security standards, processes, tools and techniques | ||||
| ✓ | ✓ | Conceptual | Cyber security in the organizations | ||||
| ✓ | ✓ | Conceptual | Definition of the concept of CSCRM | ||||
| ✓ | ✓ | ✓ | Qualitative | Estimation of the impacts of cyber attacks | |||
| ✓ | ✓ | ✓ | ✓ | Qualitative | CSCRM initiatives and actions in the supply chain | ||
| ✓ | Quantitative | Quantification of IT security risks in the supply chain | |||||
| ✓ | ✓ | Quantitative | Assessment of cyber risks and related costs | ||||
| ✓ | ✓ | Quantitative | Impact of interconnectivity on security investments | ||||
| ✓ | ✓ | Quantitative | Assessment of information risks | ||||
| ✓ | Qualitative | Evaluation of perceptions on cyber risks | |||||
| ✓ | ✓ | ✓ | Conceptual | Review on CSCRM | |||
| ✓ | Qualitative | Classification of cyber crime | |||||
| ✓ | ✓ | Quantitative | Continuity management in information systems | ||||
| ✓ | Qualitative | Definition of system-aware cyber security architecture | |||||
| ✓ | Conceptual | Insurance policies on information and data | |||||
| ✓ | ✓ | ✓ | Conceptual | Job profiles for cyber security | |||
| ✓ | Conceptual | Issues of cyber supply chain security in Korea | |||||
| ✓ | Conceptual | Information shared in a supply chain | |||||
| ✓ | ✓ | Quantitative | Impact of interconnectivity on security investments | ||||
| ✓ | Conceptual | Introduction to the concept of cyber supply chain security | |||||
| ✓ | Conceptual | Information shared in a supply chain | |||||
| ✓ | ✓ | ✓ | Qualitative | National cyber security strategies | |||
| ✓ | ✓ | Quantitative | Decision models for cyber risk insurance | ||||
| ✓ | ✓ | ✓ | Qualitative | Cyber risks in the global supply chain | |||
| ✓ | ✓ | Conceptual | Cognitive data analytics for stronger resilience in the cyber space | ||||
| ✓ | ✓ | Conceptual | Cloud resiliency and IT operational resilience measures | ||||
| ✓ | Quantitative | Models of information risk | |||||
| ✓ | Quantitative | Impact of information security initiatives on supply chain performance | |||||
| ✓ | ✓ | Conceptual | Review on information security management | ||||
| ✓ | ✓ | Quantitative | Trade-off between collaboration and cyber security | ||||
| ✓ | Conceptual | Risks across the extended enterprise | |||||
| ✓ | ✓ | ✓ | Qualitative | Cyber security, threat models, security policies for e-procurement | |||
| ✓ | ✓ | Quantitative | Information sharing and disruptions in a supply chain | ||||
| ✓ | ✓ | ✓ | Qualitative | Supply chain managers perceptions of risks related to information sharing | |||
| ✓ | ✓ | Qualitative | Information risk management | ||||
| ✓ | ✓ | ✓ | Qualitative | Security threats in supply chains | |||
| ✓ | ✓ | Quantitative | Effects of incident security awareness on information risk perception | ||||
| ✓ | ✓ | Conceptual | Cyber-attacks to supply chains and some seminal countermeasures | ||||
| ✓ | ✓ | Conceptual | Objectives for managing cyber supply chain risk | ||||
| ✓ | ✓ | ✓ | Quantitative | Supply chain digitization and IT governance | |||
| ✓ | ✓ | Conceptual | Trust-based information risk management in a supply chain |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.