<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>PhD Research Design - How Can Organisational Learning Be Leveraged to Enable Antifragility of an Organisation?⋆</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Open University</institution>
          ,
          <addr-line>Heerlen</addr-line>
          ,
          <country country="NL">the Netherlands</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Xebia Security</institution>
          ,
          <addr-line>Hilversum</addr-line>
          ,
          <country country="NL">the Netherlands</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <abstract>
        <p>The current VUCA worlds demands from organisations to be resilient and sometimes even antifragile. The domain focusing on staying relevant is that of risk management. Information security is a sub-domain of risk management where the threats and response to the threats are very well documented. Within the sub-domain of information security there is an ever going rat-race between the people that want to exploit the threat and the people reacting to the thread by for example mitigating the thread. In this research we want to look into the role of the learning organisation in the resilient behaviour of the organisation. Why the learning organisation? Since there are scholars that argue that human resilience is the key to organisational resilience.</p>
      </abstract>
      <kwd-group>
        <kwd>Organisational Learning</kwd>
        <kwd>Resilience</kwd>
        <kwd>Antifragility</kwd>
        <kwd>Information Security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1.1</p>
    </sec>
    <sec id="sec-2">
      <title>Unpredictable context threatens business continuity</title>
      <p>
        The increased internal and external hyper-connectivity of organisations lead to
more chaotic behaviour of their internal and external context [
        <xref ref-type="bibr" rid="ref12 ref13 ref26 ref30 ref33">12,13,30,26,33</xref>
        ].
      </p>
      <p>
        To deal with this unpredictability, organisations aim to become resilient by
for example implementing the agile way-of-working and/ or the adoption of a
decentralised organisation design [
        <xref ref-type="bibr" rid="ref14 ref15">14,15</xref>
        ].
1.2
      </p>
    </sec>
    <sec id="sec-3">
      <title>Business Continuity by resilience</title>
      <p>
        Organisations need to adapt since the goal of an organisation is to stay relevant to
its stakeholders [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ]. Organisational Resilience is incorporated into the definition
of Risk Management (ISO 31000), since Risk Management is the business
function that aims to optimise the business continuity of an organisation. Business
Continuity is achieved when the organisation stays relevant to its stakeholders.
[
        <xref ref-type="bibr" rid="ref10 ref29 ref3 ref4 ref5 ref6 ref7 ref8 ref9">3,4,5,6,7,10,29,8,9</xref>
        ].
      </p>
    </sec>
    <sec id="sec-4">
      <title>Business Continuity by antifragility</title>
      <p>
        Resilience is the behaviour of the value of a system over time in response to a
stressor event (f (time) = value) [
        <xref ref-type="bibr" rid="ref15 ref31">15,31</xref>
        ]. Antifragility is the behaviour of the
value of a system in response to stress (f (stress) = value) [
        <xref ref-type="bibr" rid="ref15 ref36">15,36</xref>
        ]. Resilient
behaviour maximized/ optimized leads to a system with antifragile behaviour.
Antifragile is the antithesis of fragile [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ]. In the current Body-of-Knowledge on
antifragility [
        <xref ref-type="bibr" rid="ref14 ref15">14,15</xref>
        ] it is theorised that the capability of a learning organisation
[
        <xref ref-type="bibr" rid="ref23 ref24 ref34">34,24,23</xref>
        ] is relevant for being resilient as it is relevant to be antifragile.
1.4
      </p>
    </sec>
    <sec id="sec-5">
      <title>Human factor in resilience</title>
      <p>
        In Hoogervorst (2017) [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] it is stated, in the Enterprise Engineering
Sigmatheory, that the freedom of human behaviour is the only way to deal with
the chaotic world. This is a logical deduction based on the theories on
Variety [
        <xref ref-type="bibr" rid="ref11 ref2">2,11</xref>
        ] and Requisite Variety [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] and organisation behaviour (ref needed).
Taleb (2012) [
        <xref ref-type="bibr" rid="ref36">36</xref>
        ] stated that the ideal Antifragile organisation is that of a
selfemployed worker.
1.5
      </p>
    </sec>
    <sec id="sec-6">
      <title>One or more humans?</title>
      <p>
        Organisation are complex-adaptive-systems [
        <xref ref-type="bibr" rid="ref28 ref35">28,35</xref>
        ]. Organisations can be defined
as as “The purpose and function express that enterprises aim to fulfil or address
certain (perceived) wants and needs of (certain) societal member of society at
large by delivering products and/or services.“ [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ]. Via these two lenses
organisations can exists out of one person or out of more than one person. Therefor
the attributes of an resilient organisation and an antifragile organisation can
be applied to organisations of one or of more humans. This is relevant for the
research (application) domain.
1.6
      </p>
    </sec>
    <sec id="sec-7">
      <title>Extended Antifragile Attributes List (EAAL)</title>
      <p>
        Research has shown that to become antifragile, certain types of resilience are
relevant [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. The relevant attributes to become antifragile and resilient are grouped
in the EAAL. The ordering in the EAAL makes distinction between attributes
relevant to organisation learning as defined by [
        <xref ref-type="bibr" rid="ref34">34</xref>
        ] and attributes that are not.
2
      </p>
      <sec id="sec-7-1">
        <title>Research question</title>
        <p>The attributes relevant to organisational learning are applicable to all three types
of resilience as for an organisation with antifragile behaviour. This distinguishes
the attributes relevant to organisational learning from the other attributes in
the EAAL.</p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>Main Research Question</title>
      <p>This leads to the main research question: How can organisational learning
be leveraged to enable antifragility of an organisation?</p>
      <p>This question is relevant since the answer will have impact the design of the
organisation. information security as part of risk management.
2.2</p>
    </sec>
    <sec id="sec-9">
      <title>Sub-Research Question</title>
      <p>This research will firstly limit itself to the application of the research within the
domain of information security.</p>
      <p>
        Information Security is a sub-domain of the risk management domain [
        <xref ref-type="bibr" rid="ref17 ref26">17,26</xref>
        ].
The exposure to incident in the Information security domain is ever increasing
[
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. Information security recognizes the importance of the human factor in the
response to incidents [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Information security recognizes the importance of
absorbing change (conformance) as the enablement of creating value (performance)
[
        <xref ref-type="bibr" rid="ref26 ref27">26,27</xref>
        ]. The cost of Information security incidents and the information security
investments keep growing [
        <xref ref-type="bibr" rid="ref38">38</xref>
        ].
      </p>
      <p>
        "Worldwide spending on information security products and services will reach
more than $114 billion in 2018, an increase of 12.4 percent from last year,
according to the latest forecast from Gartner, Inc. In 2019, the market is forecast
to grow 8.7 percent to $124 billion." - Gartner in 2018 [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ].
      </p>
      <p>
        "The stakes are also getting higher. Gartner estimates by 2025, 40% of boards
of directors will have a dedicated cybersecurity committee overseen by a qualified
board member, up from less than 10% today." - Gartner in 2021 [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
      </p>
      <p>
        "Worldwide spending on information security and risk management
technology and services is forecast to grow 12.4% to reach $150.4 billion in 2021,
according to the latest forecast from Gartner, Inc. Security and risk management
spending grew 6.4% in 2020." - Gartner in 2021 [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ].
      </p>
      <p>The research sub-question that arise are:
1. When is an organisation resilient and why is this relevant to an organisation?
2. What is the role of the learning organisation in the view of an organisation
as a complex adaptive system?
3. Can personal behaviour be decoupled from organisational behaviour?
4. Is there a link between organisational behaviour and the learning
organisation?
5. What is the best way to influence personal behaviour to influence
organisational behaviour in the optimisation of organisational resilience?
3</p>
      <sec id="sec-9-1">
        <title>Work/ Product breakdown structure</title>
        <p>The following products are to be envisioned to be part of this research.
1. Research Tool RDS/Graph to improve the literature research method of
snowballing and maybe even other types of systematic literature research.
2. Position Paper (Chaos) stating that there is diference between objective and
subjective chaos and identifying the role of learning in this context.
3. Research paper on the role of resilience and antifragility in the domain of</p>
        <p>Risk Management and Information Security Management.
4. Research paper on the link between the Learning Organisation and
Organisational Behaviour and Personal Behaviour.
5. Research paper on what defines and influences Personal Behaviour.
6. By somebody else: EAAL Framework replication (in the Organisational
domain)
7. By somebody else: EAAL Framework validation in the IT domain
4</p>
        <p>
          Relevant Theories
1. Variety definition by Asbey and Beer [
          <xref ref-type="bibr" rid="ref11 ref2">2,11</xref>
          ]
2. Viable Systems Theory by Beer [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ]
3. Chaos definition by Lorentz [
          <xref ref-type="bibr" rid="ref37">37</xref>
          ]
4. Function and Construction by Dietz and Mulder [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]
5. Holistic view on Learning Organisation defined by Senge [
          <xref ref-type="bibr" rid="ref34">34</xref>
          ]
6. Risk Management by Hutchins [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ]
7. Enterprise Governance of IT by Haes et al. [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]
5
        </p>
        <p>Domain Lenses
1. Complexity Science in contrast to reductionist science
2. Complex Adaptive Systems in the context of Complexity Science
3. Organisation as Complex Adaptive Systems
4. (Organisational) behaviour of organisations
5. Resilience as specific organisational "behaviour"
6. Human behaviour as specific element of resilience
7. Human as a social being
8. Human as an emotional being.
6</p>
      </sec>
      <sec id="sec-9-2">
        <title>Research Lenses</title>
        <p>1. Science through the lens of Karl Popper (Verification &amp; Falsification)
2. Science should be open (FAIR, OSF) otherwise verification and falsification
is very limited.
3. Work will be done under CC BY-SA 4.0
4. Research will be done in public gitlab repositories.</p>
        <p>The research notes are versioned in a wiki (https://gitlab.com/edzob/com
plex_adaptive_systems-knowledge_base/-/wikis/home).</p>
        <p>The research project files are versioned in a repository (https://gitlab.com
/edzob/complex_adaptive_systems-knowledge_base/-/tree/master/)
This paper is versioned on gitlab (https://gitlab.com/edzob/complex_ada
ptive_systems-knowledge_base/-/tree/master/eewc.dc.2021) and
this paper is versioned on overleaf (https://www.overleaf .com/read/wncj
ywdqdhpc).</p>
        <p>Research dogmatic Statements
1. Replication of scientific experiments in the social domain are impossible due
to the influence of human beings. This impacts the research design.
2. Enterprise Architecture (EA) and Enterprise Engineering (EE) are part of
the social science domain.
3. Organisational Resilience is part of risk management.
4. Risk management aims to "optimise" business continuity.
5. CyberSecurity and Information Security Management are organisational
capability in the domain of risk management.
6. The goal of an organisation is to stay relevant for its stakeholders.
7. Business continuity is about staying relevant.
8. Designing and managing the organisation to stay relevant is the shared goal
of the expertises of risk management, Enterprise Architecture, Enterprise
Engineering and and Enterprise Governance.
8</p>
        <p>
          Produced Work
1. Botjes 2020 - MSc Thesis “Defining Antifragility and the application on
Organisation Design” - peer reviewed by 4 in exam commission, 7 practitioners
and 30 subject matter experts. [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]
2. Botjes 2021a - IEEE Paper “Attributes relevant to antifragile organizations”
- peer reviewed by 4 experts. [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]
3. Botjes 2021b - Whitepaper on objective &amp; subjective chaos “Design for chaos”
- not-peer reviewed [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ]
9
        </p>
        <p>Changelog
version 2021-12-09
1. section 9 "changelog" added
2. typo’s fixed
3. added CC BY-SA 4.0 to running author
4. final sentence added to section 1.2 "Business Continuity by resilience"
5. made more clear diference between resilience and antfragility at the
beginning of section 1.3 "Business Continuity by antifragility"
6. rewrite of 1.5 section "One or more humans?"
7. replaced "to optimise the resilience" by "to enable antifragility" in section
2.1 "main research question"
8. added reference to the relevance of Information Security in section 2.2
"Sub</p>
        <p>Research Question"
9. extended the description at the beginning of section 3 "Work/ Product
breakdown structure"
1. added section 1.6 "Extended Antifragile Attributes List (EAAL)"
2. added paragraf at the beginning of section 2 "Research question"
3. added links to wiki, paper and research repositoru in section 6 "Research
lenses"
version 2021-12-02 version submitted to EEWC-DC.
version 2021-10-11 created draft version.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Ali</surname>
            ,
            <given-names>R.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dominic</surname>
          </string-name>
          , P.D.D.,
          <string-name>
            <surname>Ali</surname>
            ,
            <given-names>S.E.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rehman</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sohail</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Information security behavior and information security policy compliance: A systematic literature review for identifying the transformation process from noncompliance to compliance</article-title>
          .
          <source>Applied Sciences</source>
          <volume>11</volume>
          (
          <issue>8</issue>
          ) (
          <year>2021</year>
          ), https://doi.org/10.3390/app11083383
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Ashby</surname>
            ,
            <given-names>W.R.:</given-names>
          </string-name>
          <article-title>An Introduction to Cybernetics</article-title>
          . Chapman &amp; Hall and University Paperbacks, London, UK (
          <year>1956</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Aven</surname>
          </string-name>
          , T.:
          <article-title>On some recent definitions and analysis frameworks for risk, vulnerability, and resilience</article-title>
          .
          <source>Risk Analysis: An International Journal</source>
          <volume>31</volume>
          (
          <issue>4</issue>
          ),
          <fpage>515</fpage>
          -
          <lpage>522</lpage>
          (
          <year>2011</year>
          ), https://dx.doi.org/10.1111/j.1539-
          <fpage>6924</fpage>
          .
          <year>2010</year>
          .
          <volume>01528</volume>
          .x
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Foundational issues in risk assessment and risk management</article-title>
          .
          <source>Risk Analysis: An International Journal</source>
          <volume>32</volume>
          (
          <issue>10</issue>
          ),
          <fpage>1647</fpage>
          -
          <lpage>1656</lpage>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>The risk concept - historical and recent development trends</article-title>
          .
          <source>Reliability Engineering &amp; System Safety</source>
          <volume>99</volume>
          ,
          <fpage>33</fpage>
          -
          <lpage>44</lpage>
          (
          <year>2012</year>
          ), https://dx.doi.org/10.1016/j.ress.
          <year>2011</year>
          .
          <volume>11</volume>
          .006
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>The concept of antifragility and its implications for the practice of risk analysis</article-title>
          .
          <source>Risk Analysis</source>
          <volume>35</volume>
          (
          <issue>3</issue>
          ),
          <fpage>476</fpage>
          -
          <lpage>483</lpage>
          (
          <year>2015</year>
          ), https://dx.doi.org/10.1111/risa.12 279
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Risk assessment and risk management: Review of recent advances on their foundation</article-title>
          .
          <source>European Journal of Operational Research</source>
          <volume>253</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>13</lpage>
          (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Fundamental principles of risk management and governance: Review of recent advances</article-title>
          .
          <source>Japanese Journal of Risk Analysis</source>
          <volume>29</volume>
          (
          <issue>1</issue>
          ),
          <fpage>3</fpage>
          -
          <lpage>10</lpage>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thekdi</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <source>Enterprise Risk Management: Advances on Its Foundation and Practice</source>
          .
          <source>Routledge</source>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zio</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          :
          <article-title>Knowledge in risk assessment and management</article-title>
          . John Wiley &amp; Sons (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Beer</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>The heart of enterprise: the managerial cybernetics of organization, Managerial cybernetics of organization</article-title>
          , vol.
          <volume>2</volume>
          . John Wiley &amp; Sons, Chichester, West Sussex, UK (
          <year>1979</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Bennett</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lemoine</surname>
            ,
            <given-names>G.J.</given-names>
          </string-name>
          :
          <article-title>What a diference a word makes: Understanding threats to performance in a vuca world</article-title>
          .
          <source>Business Horizons</source>
          <volume>57</volume>
          (
          <issue>3</issue>
          ),
          <fpage>311</fpage>
          -
          <lpage>317</lpage>
          (may
          <year>2014</year>
          ), https://dx.doi.org/10.2139/ssrn.2406676
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Bennett</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lemoine</surname>
            ,
            <given-names>G.J.:</given-names>
          </string-name>
          <article-title>What vuca really means for you</article-title>
          .
          <source>Harvard Business Review</source>
          <volume>92</volume>
          (
          <issue>1</issue>
          /2) (feb
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Botjes</surname>
          </string-name>
          , E.:
          <article-title>Defining Antifragility and the application on Organisation Design. Master's thesis</article-title>
          , Antwerp Management School (may
          <year>2020</year>
          ), https://dx.doi.org/10.5281 /zenodo.3719389
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Botjes</surname>
            , E., van den Berg, M.,
            <given-names>van Gils</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bart Mulder</surname>
          </string-name>
          , H.:
          <article-title>Attributes relevant to antifragile organizations</article-title>
          .
          <source>In: 2021 IEEE 23nd Conference on Business Informatics (CBI)</source>
          (
          <year>2021</year>
          ), https://dx.doi.org/10.1109/CBI52690.
          <year>2021</year>
          .00017
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Botjes</surname>
            ,
            <given-names>E.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Eusterbrock</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nouwens</surname>
            , H., van Steenbergen,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Design for chaos - a dya white paper by sogeti</article-title>
          . https://labs.sogeti.com/wp-content/uploads/2021/ 11/
          <article-title>Design-for-Chaos-a-DYA-white-paper-by-</article-title>
          <string-name>
            <surname>Sogeti-version-</surname>
          </string-name>
          20211008
          <source>-v1.pdf (11</source>
          <year>2021</year>
          ), (Accessed on 12/02/2021)
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Culot</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nassimbeni</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Podrecca</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sartor</surname>
            ,
            <given-names>M.:</given-names>
          </string-name>
          <article-title>The iso/iec 27001 information security management standard: literature review and theory-based research agenda</article-title>
          .
          <source>The TQM Journal</source>
          (
          <year>2021</year>
          ), https://doi.org/10.1108/TQM-09-2020-0202
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>De Haes</surname>
          </string-name>
          , S.,
          <string-name>
            <surname>Van Grembergen</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Huygh</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Enterprise Governance of IT</article-title>
          , Alignment, and Value. Springer International Publishing,
          <source>Cham (01</source>
          <year>2020</year>
          ), https://doi.org/10.1007/978-3-
          <fpage>030</fpage>
          -25918-
          <issue>1</issue>
          _
          <fpage>1</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Dietz</surname>
            ,
            <given-names>J.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mulder</surname>
          </string-name>
          , H.B.:
          <article-title>Enterprise Ontology: A Human-Centric Approach to Understanding the Essence of Organisation</article-title>
          .
          <source>The Enterprise Engineering Series</source>
          , Springer International Publishing (
          <year>2020</year>
          ), https://www.springer.com/de/book/9 783030388539
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Gartner</surname>
          </string-name>
          :
          <article-title>Information security spending to exceed $124b 2019 | gartner</article-title>
          . https: //www.gartner.com/en/newsroom/press-releases/2018-08-15
          <article-title>-gartner-forecast s-worldwide-information-security-spending-to-</article-title>
          <string-name>
            <surname>exceed-</surname>
          </string-name>
          124
          <string-name>
            <surname>-</surname>
          </string-name>
          billion-in-2019 (aug
          <year>2018</year>
          ), (Accessed on 12/08/2021)
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21. Gartner:
          <article-title>Cybersecurity presentation guide for security and risk leaders</article-title>
          . https: //www.gartner.com/en/articles/the-15
          <string-name>
            <surname>-</surname>
          </string-name>
          minute-7
          <article-title>-slide-security-presentation-foryour-board-of-directors (dec</article-title>
          <year>2021</year>
          ), (Accessed on 12/08/2021)
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22. Gartner:
          <article-title>Gartner forecasts worldwide security and risk management spending to exceed $150 billion in 2021</article-title>
          . https://www.gartner.com/en/newsroom/press-rele ases/2021-05-17
          <article-title>-gartner-forecasts-worldwide-security-and-risk-managem</article-title>
          (may
          <year>2021</year>
          ), (Accessed on 12/08/2021)
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Garvin</surname>
            ,
            <given-names>D.A.</given-names>
          </string-name>
          :
          <article-title>Building a learning organization</article-title>
          .
          <source>Harvard business review 71(4)</source>
          ,
          <fpage>78</fpage>
          -
          <lpage>91</lpage>
          (jul
          <year>1993</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Garvin</surname>
            ,
            <given-names>D.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Edmondson</surname>
            ,
            <given-names>A.C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gino</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>Is yours a learning organization? Harvard business review 86(3</article-title>
          ),
          <fpage>109</fpage>
          -
          <lpage>116</lpage>
          (apr
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>Hoogervorst</surname>
            ,
            <given-names>J.A.</given-names>
          </string-name>
          :
          <article-title>Foundations of Enterprise Governance and Enterprise Engineering. Presenting the Employee-Centric Theory of organisation</article-title>
          . Springer (
          <year>2017</year>
          ), https://doi.org/10.1007/978-3-
          <fpage>319</fpage>
          -72107-1
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Hutchins</surname>
          </string-name>
          , G.:
          <article-title>ISO 31000: 2018 Enterprise Risk Management</article-title>
          .
          <source>CERM Academy Series on Enterprise Risk Management</source>
          ,
          <string-name>
            <surname>Certified Enterprise Risk Manager(R) Academy</surname>
          </string-name>
          (nov
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          27.
          <string-name>
            <surname>Huygh</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Steuperaert</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Haes</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Joshi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>The role of compliance requirements in it governance implementation: An empirical study based on cobit 2019</article-title>
          .
          <source>In: Proceedings of Hawaii International Conference on System Sciences (HICSS 55)</source>
          (
          <year>01 2022</year>
          ), https://www.researchgate.net/publication/354718657
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          28.
          <string-name>
            <surname>Jackson</surname>
            ,
            <given-names>M.C.</given-names>
          </string-name>
          :
          <article-title>Critical Systems Thinking and the Management of Complexity</article-title>
          . Wiley,
          <volume>1</volume>
          <fpage>edn</fpage>
          . (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          29.
          <string-name>
            <surname>Jensen</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Aven</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>A new definition of complexity in a risk analysis setting</article-title>
          .
          <source>Reliability Engineering &amp; System Safety</source>
          <volume>171</volume>
          ,
          <fpage>169</fpage>
          -
          <lpage>173</lpage>
          (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          30.
          <string-name>
            <surname>Mack</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Khare</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Krämer</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Burgartz</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Managing in a VUCA World</article-title>
          . Springer, Cham, Switzerland (jul
          <year>2015</year>
          ), https://dx.doi.org/10.1007/978-3-319-1
          <fpage>6889</fpage>
          -
          <lpage>0</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          31.
          <string-name>
            <surname>Martin-Breen</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Anderies</surname>
            ,
            <given-names>J.M.:</given-names>
          </string-name>
          <article-title>The bellagio initiative, background paper, resilience: A literature review</article-title>
          . In: Resilience:
          <string-name>
            <given-names>A Literature</given-names>
            <surname>Review</surname>
          </string-name>
          .
          <source>Brighton:IDS</source>
          (11
          <year>2011</year>
          ), http://opendocs.ids.ac.uk/opendocs/handle/123456789/3692
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          32.
          <string-name>
            <surname>Op't Land</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Proper</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Waage</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cloo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Steghuis</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          :
          <article-title>Enterprise Architecture: creating value by informed governance</article-title>
          .
          <source>The Enterprise Engineering Series</source>
          , Springer Science &amp; Business
          <string-name>
            <surname>Media</surname>
          </string-name>
          , Berlin, Germany (oct
          <year>2008</year>
          ), https: //doi.org/10.1007/978-3-
          <fpage>540</fpage>
          -85232-2
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          33.
          <string-name>
            <given-names>O</given-names>
            <surname>'Reilly</surname>
          </string-name>
          ,
          <string-name>
            <surname>B.M.:</surname>
          </string-name>
          <article-title>No more snake oil: Architecting agility through antifragility</article-title>
          .
          <source>Procedia Computer Science</source>
          <volume>151</volume>
          ,
          <fpage>884</fpage>
          -
          <lpage>890</lpage>
          (
          <year>2019</year>
          ), https://dx.doi.org/10.1016/j.procs .
          <year>2019</year>
          .
          <volume>04</volume>
          .122
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          34.
          <string-name>
            <surname>Senge</surname>
            ,
            <given-names>P.M.:</given-names>
          </string-name>
          <article-title>The Fifth Discipline: The Art and Practice of the Learning organisation. A Currency book</article-title>
          , Doubleday/Currency, New York, NY, USA (mar
          <year>1990</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          35.
          <string-name>
            <surname>Stacey</surname>
          </string-name>
          , R.D.:
          <article-title>Strategic management and organisational dynamics: The challenge of complexity to ways of thinking about organisations</article-title>
          .
          <source>Pearson education</source>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          36.
          <string-name>
            <surname>Taleb</surname>
            ,
            <given-names>N.N.</given-names>
          </string-name>
          :
          <article-title>Antifragile: Things That Gain from Disorder</article-title>
          .
          <source>Random House</source>
          , New York, NY, USA (nov
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          37.
          <article-title>Wikipedia contributors: Chaos theory - Wikipedia, the free encyclopedia</article-title>
          . https: //en.wikipedia.org/w/index.php?title=Chaos_theory&amp;oldid=
          <volume>944540733</volume>
          (
          <year>2020</year>
          ), (Online; accessed 12-March-2020)
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          38.
          <string-name>
            <surname>Yaqoob</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Arshad</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Abbas</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Amjad</surname>
            ,
            <given-names>M.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shafqat</surname>
          </string-name>
          , N.:
          <article-title>Framework for calculating return on security investment (rosi) for security-oriented organizations</article-title>
          .
          <source>Future Generation Computer Systems</source>
          <volume>95</volume>
          ,
          <fpage>754</fpage>
          -
          <lpage>763</lpage>
          (
          <year>2019</year>
          ), https://doi.org/10.101 6/j.future.
          <year>2018</year>
          .
          <volume>12</volume>
          .033
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>