Managing Information Security Risk Using Integrated Governance Risk and Compliance

被引:0
|
作者
Nicho, Mathew [1 ]
Khan, Shafaq [2 ]
Rahman, M. S. M. K. [3 ]
机构
[1] Robert Gordon Univ, Sch Comp & Digital Media, Aberdeen, Scotland
[2] Univ Dubai, Coll Engn & IT, Dubai, U Arab Emirates
[3] Xpert Governance Consultancy, Dubai, U Arab Emirates
来源
2017 INTERNATIONAL CONFERENCE ON COMPUTER AND APPLICATIONS (ICCA) | 2017年
关键词
IT GRC; IT governance; IT risk management; IT compliance; risk management; IT GRC model; integrated IT governance model; SERVICE MANAGEMENT; SYSTEMS; BANKING; FRAMEWORK; COBIT; ORGANIZATIONS;
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
This paper aims to demonstrate the building blocks of an IT Governance Risk and Compliance (IT GRC) model as well the phased stages of the optimal integration of IT GRC frameworks, standards and model through a longitudinal study. A qualitative longitudinal single case study methodology through multiple open-ended interviews were conducted over a period of four years (July 2012 to November 2015) in a retail financial institution. Our empirical study contributes to both academic research and practice in IT GRC. First, we identified the various building blocks of IT GRC domain from vertical as well as horizontal perspectives. Second, we methodologically demonstrated the gradual metamorphosis of the evolution of an IT GRC from a single ITG framework to multiple IT GRC building blocks. The journey thus throws light on the gradual staged process of attaining maturity in IT GRC by an organization. The resultant IT GRC model thus, guides managerial actions towards a better understanding of the positioning of IT GRC building blocks in an organization through the understanding of the interaction of vertical and horizontal domains. The results of the paper thus enable practitioners and academics to better understand and evaluate IT GRC implementation for effective governance, reduce risk and ensure compliance in organizations.
引用
收藏
页码:56 / 66
页数:11
相关论文
共 50 条
  • [1] Information Governance: Beyond Risk and Compliance
    Beijer, Peter
    Kooper, Michiel
    PROCEEDINGS OF THE 6TH EUROPEAN CONFERENCE ON MANAGEMENT LEADERSHIP AND GOVERNANCE, 2010, : 34 - 39
  • [2] MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons Learned
    Takamura, Eduardo
    Gomez-Rosa, Carlos
    Mangum, Kevin
    Wasiak, Fran
    2014 IEEE AEROSPACE CONFERENCE, 2014,
  • [3] A Novel Approach for Optimizing Governance, Risk management and Compliance for Enterprise Information security using DEMATEL and FoM
    Ramalingam, Dharmalingam
    Arun, Shivasankarappa
    Anbazhagan, Neelamegam
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 365 - 370
  • [4] Managing Information Technology Security Risk
    Gilliam, DP
    SOFTWARE SECURITY - THEORIES AND SYSTEMS, 2004, 3233 : 296 - 317
  • [5] Governance, Risk and Compliance in Information Systems Preface
    Sadiq, Shazia
    zur Muehlen, Michael
    Indulska, Marta
    INFORMATION SYSTEMS FRONTIERS, 2012, 14 (02) : 119 - 121
  • [6] Governance, risk and compliance: Applications in information systems
    Sadiq, Shazia
    zur Muehlen, Michael
    Indulska, Marta
    INFORMATION SYSTEMS FRONTIERS, 2012, 14 (02) : 123 - 124
  • [7] Governance, risk and compliance: Applications in information systems
    Shazia Sadiq
    Michael zur Muehlen
    Marta Indulska
    Information Systems Frontiers, 2012, 14 : 123 - 124
  • [8] A process model for integrated IT governance, risk, and compliance management
    Racz, Nicolas
    Weippl, Edgar
    Seufert, Andreas
    DATABASES AND INFORMATION SYSTEMS, 2010, : 155 - 169
  • [9] Information Security: Risk, Governance and Implementation Setback
    Fazlida, M. R.
    Said, Jamaliah
    7TH INTERNATIONAL CONFERENCE ON FINANCIAL CRIMINOLOGY 2015, 7TH ICFC 2015, 2015, 28 : 243 - 248
  • [10] Risk management, compliance, and governance for resilient information systems
    Schermann, Michael
    Krcmar, Helmut
    Lecture Notes in Informatics (LNI), Proceedings - Series of the Gesellschaft fur Informatik (GI), 2010, P-176 : 229 - 230