AN EMPIRICAL STUDY INTO INFORMATION SECURITY GOVERNANCE FOCUS AREAS AND THEIR EFFECTS ON RISK MANAGEMENT

被引:1
作者
Yaokumah, Winfred [1 ]
Brown, Steven [2 ]
机构
[1] Pentecost Univ Coll, Dept Informat Technol, Accra, Ghana
[2] Capella Univ, Sch Business & Technol, Minneapolis, MN USA
来源
2014 ANNUAL GLOBAL ONLINE CONFERENCE ON INFORMATION AND COMPUTER TECHNOLOGY | 2014年
关键词
Information Security Governance; Risk Management; Strategic Alignment; Value Delivery; Resource Management; Performance Measurement;
D O I
10.1109/GOCICT.2014.12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper aimed at determining the extent to which information security governance (ISG) focus areas impact risk management. A total of 81 valid questionnaires were collected and processed using multiple linear regression and frequency analyses. The results showed that 92.7% of the variances in risk management were explained by the resource management, information security and business strategic alignment, value delivery, and performance measurement. Resource management and strategic alignment made significant positive contribution to risk management. Among the most applied attributes within the ISG focus areas, the organizations appreciably implemented policies that address risk management and non-compliance to security risk. However, risk assessment was not frequently and exhaustively performed and security personnel were not adequately trained. The study contributed to the literature by empirically determining the impact of ISG focus areas on risk management, provided organizational leaders better understanding of ISG focus areas, and suggested improvement to ISG practices.
引用
收藏
页码:42 / 49
页数:8
相关论文
共 46 条
[1]   Information security governance in Saudi organizations: An empirical study [J].
Abu-Musa A. .
Information Management and Computer Security, 2010, 18 (04) :226-276
[2]  
Allen J., 2009, MUCH SECURITY IS ENO
[3]   Factors impacting the perceived organizational support of IT employees [J].
Allen, Myria W. ;
Armstrong, Deborah J. ;
Reid, Margaret F. ;
Riemenschneider, Cynthia K. .
INFORMATION & MANAGEMENT, 2008, 45 (08) :556-563
[4]  
[Anonymous], 2006, NIST SPECIAL PUBLICA
[5]   Information Security management: A human challenge? [J].
Department of Informatics and Sensors, Cranfield University, Swindon, SN6 8LA, United Kingdom .
Inf Secur Tech Rep, 2008, 4 (195-201) :195-201
[6]  
Bonabeau E, 2007, MIT SLOAN MANAGE REV, V48, P62
[7]  
Bowen Paul L., 2007, International Journal of Accounting Information Systems, V8, P191, DOI 10.1016/j.accinf.2007.07.002
[8]  
Bulgurcu B, 2010, MIS QUART, V34, P523
[9]  
Coles R. S., 2006, COMPUT SECUR, V22, P580
[10]  
Educause, 2006, INF SEC GOV ASS TOOL