A survey of literature shows that research about
technical and formal controls for security
management of information systems is abundant but
security governance at informal level has rarely
been emphasized in the security literature. Chen [5]
emphasizes that informal organization structures are
important for information systems alignment.
Various informal “relationship-based structures that
transcend the formal division of labor and
coordination of tasks” (pp. 107) cannot be separated
from formal structures as it comprises an integral
part of the socio-technical system of an
organization. To attain comprehensive information
system security in an organization, organizations
need to attend to behavioral issues of security
governance such as informal management of
security behavior, culture, norms and individual