AN EMPIRICAL STUDY INTO INFORMATION SECURITY GOVERNANCE FOCUS AREAS AND THEIR EFFECTS ON RISK MANAGEMENT

被引:1
|
作者
Yaokumah, Winfred [1 ]
Brown, Steven [2 ]
机构
[1] Pentecost Univ Coll, Dept Informat Technol, Accra, Ghana
[2] Capella Univ, Sch Business & Technol, Minneapolis, MN USA
关键词
Information Security Governance; Risk Management; Strategic Alignment; Value Delivery; Resource Management; Performance Measurement;
D O I
10.1109/GOCICT.2014.12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper aimed at determining the extent to which information security governance (ISG) focus areas impact risk management. A total of 81 valid questionnaires were collected and processed using multiple linear regression and frequency analyses. The results showed that 92.7% of the variances in risk management were explained by the resource management, information security and business strategic alignment, value delivery, and performance measurement. Resource management and strategic alignment made significant positive contribution to risk management. Among the most applied attributes within the ISG focus areas, the organizations appreciably implemented policies that address risk management and non-compliance to security risk. However, risk assessment was not frequently and exhaustively performed and security personnel were not adequately trained. The study contributed to the literature by empirically determining the impact of ISG focus areas on risk management, provided organizational leaders better understanding of ISG focus areas, and suggested improvement to ISG practices.
引用
收藏
页码:42 / 49
页数:8
相关论文
共 50 条
  • [11] Information security and risk management
    Bodin, Lawrence D.
    Gordon, Lawrence A.
    Loeb, Martin P.
    COMMUNICATIONS OF THE ACM, 2008, 51 (04) : 64 - 68
  • [12] Information Security Governance - Compliance management vs operational management
    von Solms, SH
    COMPUTERS & SECURITY, 2005, 24 (06) : 443 - 447
  • [13] Peer governance effects of information security breaches
    Wang, Jiaxin
    Wu, Zhifeng
    Yuan, Xue
    Song, Zilong
    ENERGY ECONOMICS, 2024, 129
  • [14] Information Security Employment: An Empirical Study
    Nelson, James A.
    Nelson, Darlene
    Nelson, Nicholas J.
    MICBE '09: PROCEEDINGS OF THE 10TH WSEAS INTERNATIONAL CONFERENCE ON MATHEMATICS AND COMPUTERS IN BUSINESS AND ECONOMICS, 2009, : 297 - +
  • [15] Bias and noise in security risk assessments, an empirical study on the information position and confidence of security professionals
    Johan de Wit
    Wolter Pieters
    Pieter van Gelder
    Security Journal, 2024, 37 : 170 - 191
  • [16] Bias and noise in security risk assessments, an empirical study on the information position and confidence of security professionals
    de Wit, Johan
    Pieters, Wolter
    van Gelder, Pieter
    SECURITY JOURNAL, 2024, 37 (01) : 170 - 191
  • [17] Study on Efficiency of Risk Management for Information Security Based on Transaction
    Lu, Zhigang
    Wang, Xiaozhen
    Liu, Baoxu
    Xu, Rongsheng
    PROCEEDINGS OF THE SECOND INTERNATIONAL SYMPOSIUM ON ELECTRONIC COMMERCE AND SECURITY, VOL II, 2009, : 356 - 360
  • [18] Managing Information Security Risk Using Integrated Governance Risk and Compliance
    Nicho, Mathew
    Khan, Shafaq
    Rahman, M. S. M. K.
    2017 INTERNATIONAL CONFERENCE ON COMPUTER AND APPLICATIONS (ICCA), 2017, : 56 - 66
  • [19] Security through Information Risk Management
    Johnson, M. Eric
    Goetz, Eric
    Pfleeger, Shari Lawrence
    IEEE SECURITY & PRIVACY, 2009, 7 (03) : 45 - 52
  • [20] The Quantification Management of Information Security Risk
    Lao, Guoling
    Wang, Liping
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 10377 - 10380