Understanding governance, risk and compliance information systems (GRC IS): The experts view

被引:34
|
作者
Papazafeiropoulou, Anastasia [1 ]
Spanaki, Konstantina [2 ]
机构
[1] Brunel Univ, Dept Comp Sci, St Johns Bldg, Uxbridge UB8 3PH, Middx, England
[2] Imperial Coll, Tanaka Bldg,South Kensigton Campus, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Governance; Risk and Compliance Information Systems (GRC IS); Enterprise Systems; System Aspects; FRAMEWORK; SOFTWARE;
D O I
10.1007/s10796-015-9572-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although Governance, Risk and Compliance (GRC) is an emerging field of study within the information systems (IS) academic community, the concept behind the acronym has to still be demystified and further investigated. The study investigates GRC systems in depth by (a) reviewing the literature on existing GRC studies, and (b) presenting a field study on views about GRC application by professional experts. The aim of this exploratory study is to understand the aspects and the nature of the GRC system following an enterprise systems approach. The result of this study is a framework of particular GRC characteristics that need to be taken into consideration when these systems are put in place. This framework includes specific areas such as: goals and objectives, purpose of the system, key stakeholders, methodology and requirements prior to implementation, critical success factors and problems/barriers. Further discussion about the issues, the concerns and the diverse views on GRC would assist in developing an agenda for the future research on the GRC field.
引用
收藏
页码:1251 / 1263
页数:13
相关论文
共 50 条
  • [1] Understanding governance, risk and compliance information systems (GRC IS): The experts view
    Anastasia Papazafeiropoulou
    Konstantina Spanaki
    Information Systems Frontiers, 2016, 18 : 1251 - 1263
  • [2] Patterns for Understanding Control Requirements for Information Systems for Governance, Risk Management, and Compliance (GRC IS)
    Wiesche, Manuel
    Berwing, Carolin
    Schermann, Michael
    Krcmar, Helmut
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, 2011, 83 : 208 - +
  • [3] MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons Learned
    Takamura, Eduardo
    Gomez-Rosa, Carlos
    Mangum, Kevin
    Wasiak, Fran
    2014 IEEE AEROSPACE CONFERENCE, 2014,
  • [4] Governance, Risk and Compliance in Information Systems Preface
    Sadiq, Shazia
    zur Muehlen, Michael
    Indulska, Marta
    INFORMATION SYSTEMS FRONTIERS, 2012, 14 (02) : 119 - 121
  • [5] Governance, risk and compliance: Applications in information systems
    Sadiq, Shazia
    zur Muehlen, Michael
    Indulska, Marta
    INFORMATION SYSTEMS FRONTIERS, 2012, 14 (02) : 123 - 124
  • [6] Governance, risk and compliance: Applications in information systems
    Shazia Sadiq
    Michael zur Muehlen
    Marta Indulska
    Information Systems Frontiers, 2012, 14 : 123 - 124
  • [7] Analyzing the technological challenges of Governance, Risk and Compliance (GRC)
    Abdullah, Hanifa
    2019 4TH INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER TECHNOLOGIES AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2019, : 274 - 282
  • [8] Risk management, compliance, and governance for resilient information systems
    Schermann, Michael
    Krcmar, Helmut
    Lecture Notes in Informatics (LNI), Proceedings - Series of the Gesellschaft fur Informatik (GI), 2010, P-176 : 229 - 230
  • [9] Risk management, compliance and governance for resistant information systems
    Schermann, Michael
    Krcmar, Helmut
    INFORMATIK 2010 - Service Science - Neue Perspektiven fur die Informatik, Beitrage der 40. Jahrestagung der Gesellschaft fur Informatik e.V. (GI), 2010, 2 : 229 - 230
  • [10] Workshop on Governance, Risk and Compliance in Information Systems: GRCIS
    Indulska, Marta
    Sadiq, Shazia
    Zur Muehlen, Michael
    Tan, Yao-Hua
    Lecture Notes in Business Information Processing, 2012, 112 LNBIP