AN EMPIRICAL STUDY INTO INFORMATION SECURITY GOVERNANCE FOCUS AREAS AND THEIR EFFECTS ON RISK MANAGEMENT

被引:1
|
作者
Yaokumah, Winfred [1 ]
Brown, Steven [2 ]
机构
[1] Pentecost Univ Coll, Dept Informat Technol, Accra, Ghana
[2] Capella Univ, Sch Business & Technol, Minneapolis, MN USA
关键词
Information Security Governance; Risk Management; Strategic Alignment; Value Delivery; Resource Management; Performance Measurement;
D O I
10.1109/GOCICT.2014.12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper aimed at determining the extent to which information security governance (ISG) focus areas impact risk management. A total of 81 valid questionnaires were collected and processed using multiple linear regression and frequency analyses. The results showed that 92.7% of the variances in risk management were explained by the resource management, information security and business strategic alignment, value delivery, and performance measurement. Resource management and strategic alignment made significant positive contribution to risk management. Among the most applied attributes within the ISG focus areas, the organizations appreciably implemented policies that address risk management and non-compliance to security risk. However, risk assessment was not frequently and exhaustively performed and security personnel were not adequately trained. The study contributed to the literature by empirically determining the impact of ISG focus areas on risk management, provided organizational leaders better understanding of ISG focus areas, and suggested improvement to ISG practices.
引用
收藏
页码:42 / 49
页数:8
相关论文
共 50 条
  • [1] Information security governance in Saudi organizations: An empirical study
    Abu-Musa A.
    Information Management and Computer Security, 2010, 18 (04): : 226 - 276
  • [2] A Framework for Information Security Governance and Management
    Carcary, Marian
    Renaud, Karen
    McLaughlin, Stephen
    O'Brien, Conor
    IT PROFESSIONAL, 2016, 18 (02) : 22 - 30
  • [3] Information security governance implementation within Ghanaian industry sectors an empirical study
    Yaokumah, Winfred (winfred91@gmail.com), 1600, Emerald Group Holdings Ltd. (22):
  • [4] MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons Learned
    Takamura, Eduardo
    Gomez-Rosa, Carlos
    Mangum, Kevin
    Wasiak, Fran
    2014 IEEE AEROSPACE CONFERENCE, 2014,
  • [5] Information security governance: A challenge for senior management
    von Solms, R
    Innovations Through Information Technology, Vols 1 and 2, 2004, : 1130 - 1131
  • [6] Information Security: Risk, Governance and Implementation Setback
    Fazlida, M. R.
    Said, Jamaliah
    7TH INTERNATIONAL CONFERENCE ON FINANCIAL CRIMINOLOGY 2015, 7TH ICFC 2015, 2015, 28 : 243 - 248
  • [7] A Case Study on Risk Management of Enterprise Information Security
    Huang, Rengen
    Zhu, Zhen
    2015 2nd International Conference on Creative Education (ICCE 2015), Pt 2, 2015, 11 : 201 - 208
  • [8] A Path to Successful Management of Employee Security Compliance: An Empirical Study of Information Security Climate
    Goo, Jahyun
    Yim, Myung-Seong
    Kim, Dan J.
    IEEE TRANSACTIONS ON PROFESSIONAL COMMUNICATION, 2014, 57 (04) : 286 - 308
  • [9] Empirical evaluation of a cloud computing information security governance framework
    Rebollo, Oscar
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Mouratidis, Haralambos
    INFORMATION AND SOFTWARE TECHNOLOGY, 2015, 58 : 44 - 57
  • [10] The Information Security Risk Management
    Semin, Valeriy G.
    Shmakova, Elena G.
    Los, Lexei B.
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE QUALITY MANAGEMENT,TRANSPORT AND INFORMATION SECURITY, INFORMATION TECHNOLOGIES (IT&QM&IS), 2017, : 106 - 109