Organizations nowadays rely heavily on information technology and information security has caught a great deal of attention; however, few information security strategies and guidelines could be found for practitioners. This may result from a lack of coherent and comprehensive information security management theory. The paper integrates different perspectives from security policy, risk management, control and auditing, management systems and contingency theories and builds an IST, which may lay a more solid foundation for further empirical studies. The contribution of this study is as follows: