Abstract- Behavioral information systems security
governance entails managing the informal structures
in an organization to ensure an appropriate security
environment. Informal structures in an organization
comprise the individual values, beliefs and behavior
prevalent in an organization guiding the norms and
employee perception of job responsibilities. Five
consistent themes arise from a critical review of the
extant literature in this area: security culture, internal
control assessment, security policy implementation,
individual values, beliefs, and security training. A
theoretical framework from the field of sociology is
proposed to investigate the current issues in
behavioral aspects of security governance.
Contributions of this paper are discussed and future
research directions suggested.