Understanding governance, risk and compliance information systems (GRC IS): The experts view

被引:34
|
作者
Papazafeiropoulou, Anastasia [1 ]
Spanaki, Konstantina [2 ]
机构
[1] Brunel Univ, Dept Comp Sci, St Johns Bldg, Uxbridge UB8 3PH, Middx, England
[2] Imperial Coll, Tanaka Bldg,South Kensigton Campus, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Governance; Risk and Compliance Information Systems (GRC IS); Enterprise Systems; System Aspects; FRAMEWORK; SOFTWARE;
D O I
10.1007/s10796-015-9572-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although Governance, Risk and Compliance (GRC) is an emerging field of study within the information systems (IS) academic community, the concept behind the acronym has to still be demystified and further investigated. The study investigates GRC systems in depth by (a) reviewing the literature on existing GRC studies, and (b) presenting a field study on views about GRC application by professional experts. The aim of this exploratory study is to understand the aspects and the nature of the GRC system following an enterprise systems approach. The result of this study is a framework of particular GRC characteristics that need to be taken into consideration when these systems are put in place. This framework includes specific areas such as: goals and objectives, purpose of the system, key stakeholders, methodology and requirements prior to implementation, critical success factors and problems/barriers. Further discussion about the issues, the concerns and the diverse views on GRC would assist in developing an agenda for the future research on the GRC field.
引用
收藏
页码:1251 / 1263
页数:13
相关论文
共 50 条
  • [31] Information governance - a view from the NHS
    Donaldson, A
    Walker, P
    INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2004, 73 (03) : 281 - 284
  • [32] Public understanding of risk and risk governance
    Klinke, Andreas
    JOURNAL OF RISK RESEARCH, 2021, 24 (01) : 2 - 13
  • [33] Corporate governance and Islamic law compliance risk
    Mukhibad, Hasan
    Nurkhin, Ahmad
    Jati, Kuat Waluyo
    Jayanto, Prabowo Yudo
    McMillan, David
    COGENT ECONOMICS & FINANCE, 2022, 10 (01):
  • [34] Integrating IT Governance, Risk, and Compliance Management Processes
    Racz, Nicolas
    Weippl, Edgar
    Seufert, Andreas
    DATABASES AND INFORMATION SYSTEMS VI: SELECTED PAPERS FROM THE NINTH INTERNATIONAL BALTIC CONFERENCE (DB&IS 2010), 2011, 224 : 325 - 338
  • [35] A Framework for Assessing Organisational IT Governance, Risk and Compliance
    Vunk, Mikhel
    Mayer, Nicolas
    Matulevicius, Raimundas
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, SPICE 2017, 2017, 770 : 337 - 350
  • [36] SECURITY OF INFORMATION SYSTEMS FROM RISK MANAGEMENT POINT OF VIEW
    Capek, Jan
    STRATEGIC MANAGEMENT AND ITS SUPPORT BY INFORMATION SYSTEMS, PROCEEDINGS, 2007, : 1 - 10
  • [37] Various ways of understanding compliance: a psychiatrist's view
    Jaeschke, Rafal
    Siwek, Marcin
    Dudek, Dominika
    ARCHIVES OF PSYCHIATRY AND PSYCHOTHERAPY, 2011, 13 (03): : 49 - 55
  • [38] Understanding the Ecosystem of Enterprise Risk Governance
    Beasley, Mark S.
    Branson, Bruce C.
    Braumann, Evelyn C.
    Pagach, Donald P.
    ACCOUNTING REVIEW, 2023, 98 (05): : 99 - 128
  • [39] STRUCTURED APPROACH TO THE ADOPTION OF INFORMATION TECHNOLOGY GOVERNANCE, RISK AND COMPLIANCE IN HOSPITALS USING DESIGN SCIENCE PRINCIPLES
    Krey, Mike
    Furnell, Steven
    Harriehausen, Bettina
    Knoll, Matthias
    PROCEEDINGS OF THE IADIS INTERNATIONAL CONFERENCE E-HEALTH 2012, 2012, : 85 - 96
  • [40] A Novel Approach for Optimizing Governance, Risk management and Compliance for Enterprise Information security using DEMATEL and FoM
    Ramalingam, Dharmalingam
    Arun, Shivasankarappa
    Anbazhagan, Neelamegam
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 365 - 370