AN EMPIRICAL STUDY INTO INFORMATION SECURITY GOVERNANCE FOCUS AREAS AND THEIR EFFECTS ON RISK MANAGEMENT

被引:1
|
作者
Yaokumah, Winfred [1 ]
Brown, Steven [2 ]
机构
[1] Pentecost Univ Coll, Dept Informat Technol, Accra, Ghana
[2] Capella Univ, Sch Business & Technol, Minneapolis, MN USA
关键词
Information Security Governance; Risk Management; Strategic Alignment; Value Delivery; Resource Management; Performance Measurement;
D O I
10.1109/GOCICT.2014.12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper aimed at determining the extent to which information security governance (ISG) focus areas impact risk management. A total of 81 valid questionnaires were collected and processed using multiple linear regression and frequency analyses. The results showed that 92.7% of the variances in risk management were explained by the resource management, information security and business strategic alignment, value delivery, and performance measurement. Resource management and strategic alignment made significant positive contribution to risk management. Among the most applied attributes within the ISG focus areas, the organizations appreciably implemented policies that address risk management and non-compliance to security risk. However, risk assessment was not frequently and exhaustively performed and security personnel were not adequately trained. The study contributed to the literature by empirically determining the impact of ISG focus areas on risk management, provided organizational leaders better understanding of ISG focus areas, and suggested improvement to ISG practices.
引用
收藏
页码:42 / 49
页数:8
相关论文
共 50 条
  • [31] A Dependency analysis for Information Security and Risk Management
    Krishna, B. Chaitanya
    Subrahmanyam, Kodukula
    Kim, Tai-hoon
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (08): : 205 - 210
  • [32] The Case for improvisation in information Security Risk Management
    Njenga, Kennedy
    Brown, Irwin
    E-GOVERNMENT, E-SERVICES AND GLOBAL PROCESSES, 2010, 334 : 220 - +
  • [33] Information technology, security and risk management (paperback)
    Fitz-Gerald, S.
    JOURNAL OF THE OPERATIONAL RESEARCH SOCIETY, 2008, 59 (08) : 1146 - 1147
  • [34] INFORMATION SECURITY ASPECT OF OPERATIONAL RISK MANAGEMENT
    Zawila-Niedzwiecki, Janusz
    Byczkowski, Maciej
    FOUNDATIONS OF MANAGEMENT, 2009, 1 (02) : 45 - 60
  • [35] Information Security Risk Management for Air Transport
    Volner, Rudolf
    Volner, L'ubomir
    2011 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2011,
  • [36] Information Chaos, Risk Management and Cyber Security
    Capek, Jan
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON STRATEGIC MANAGEMENT AND ITS SUPPORT BY INFORMATION SYSTEMS, 2015, : 36 - 45
  • [37] Research on Enterprise Information Security Risk Management
    Wu Xiaoyan
    Yuan Hong
    Lin Hua
    PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON INNOVATION AND MANAGEMENT, 2013, : 924 - +
  • [38] Improvement of Information System Security Risk Management
    Abbass, Wissam
    Baina, Amine
    Bellafkih, Mostafa
    2016 4TH IEEE INTERNATIONAL COLLOQUIUM ON INFORMATION SCIENCE AND TECHNOLOGY (CIST), 2016, : 182 - 187
  • [39] Performance metrics for information security risk management
    Ryan, Julie J. C. H.
    Ryan, Daniel J.
    IEEE SECURITY & PRIVACY, 2008, 6 (05) : 38 - 44
  • [40] Information Security Risk Management in a World of Services
    Lalanne, Vincent
    Munier, Manuel
    Gabillon, Alban
    2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 586 - 593