From information security management to enterprise risk management

被引:0
作者
Stoll, Margareth [1 ]
机构
[1] University of Innsbruck, Technikerstr. 21a, Innsbruck, Tyrol
来源
Lecture Notes in Electrical Engineering | 2015年 / 313卷
关键词
COSO; Enterprise risk management; Framework; Information security management; ISO; 27000; 31000; Risk management;
D O I
10.1007/978-3-319-06773-5_2
中图分类号
学科分类号
摘要
Organizations are faced with increasing complexity, uncertainty and enhanced threats from a wide range of forces. Depending on how this situation is handled, it can become risk or opportunity to erode or enhance business value. In addition, organizations have to meet most different stakeholders’, legal and regulatory risk management requirements. Thus, comprehensive enterprise risk management has become key challenge and core competence for organizations’ sustainable success. Given the central role of information security management and the common goals with enterprise risk management, organizations need guidance how to extend information security management in order to fulfill enterprise risk management requirements. Yet, interdisciplinary security research at the organizational level is still missing. Accordingly, we propose a systemic framework, which guides organizations to promote enterprise risk management starting from information security management. The results of our case studies in different small and medium-sized organizations suggest that the framework was useful to promote enterprise risk management in an effective, efficient, cost-effective and sustainable way. New insights for practice and future research are offered. © Springer International Publishing Switzerland 2015.
引用
收藏
页码:9 / 16
页数:7
相关论文
共 41 条
  • [1] Taleb N., The Black Swan, The Impact of the Highly Improbable, (2007)
  • [2] Power M., Organized Uncertainty, (2007)
  • [3] Brown I., Steen A., Foreman J., Risk management in corporate governance: A review and proposal, Corporate Governance: An International Review, 17, 5, pp. 546-558, (2009)
  • [4] Windram B., Song J., Non-executive directors and the changing nature of audit committees, Corporate Ownership and Control, 1, pp. 108-115, (2004)
  • [5] Company laws
  • [6] Corporate Law and Governance
  • [7] Gates S., Nicolas J., Walker P.L., Enterprise risk management: A process for enhanced management and improved performance, Management Accounting Quarterly, 13, 3, pp. 28-38, (2012)
  • [8] Hoyt R.E., Liebenberg A.P., The value of enterprise risk management, Journal of Risk & Insurance, 78, 4, pp. 795-822, (2011)
  • [9] Arnold V., Benford T.S., Hampton C., Sutton S.G., Enterprise risk management as a strategic governance mechanism in B2Benabled transnational supply chains, J.Inf.Syst, 26, 1, pp. 51-76, (2012)
  • [10] (2009)