AN EMPIRICAL STUDY INTO INFORMATION SECURITY GOVERNANCE FOCUS AREAS AND THEIR EFFECTS ON RISK MANAGEMENT

被引:1
|
作者
Yaokumah, Winfred [1 ]
Brown, Steven [2 ]
机构
[1] Pentecost Univ Coll, Dept Informat Technol, Accra, Ghana
[2] Capella Univ, Sch Business & Technol, Minneapolis, MN USA
关键词
Information Security Governance; Risk Management; Strategic Alignment; Value Delivery; Resource Management; Performance Measurement;
D O I
10.1109/GOCICT.2014.12
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper aimed at determining the extent to which information security governance (ISG) focus areas impact risk management. A total of 81 valid questionnaires were collected and processed using multiple linear regression and frequency analyses. The results showed that 92.7% of the variances in risk management were explained by the resource management, information security and business strategic alignment, value delivery, and performance measurement. Resource management and strategic alignment made significant positive contribution to risk management. Among the most applied attributes within the ISG focus areas, the organizations appreciably implemented policies that address risk management and non-compliance to security risk. However, risk assessment was not frequently and exhaustively performed and security personnel were not adequately trained. The study contributed to the literature by empirically determining the impact of ISG focus areas on risk management, provided organizational leaders better understanding of ISG focus areas, and suggested improvement to ISG practices.
引用
收藏
页码:42 / 49
页数:8
相关论文
共 50 条
  • [41] Integration of IT Governance and Security Risk Management: a Systematic Literature Review
    De Smet, Dieter
    Mayer, Nicolas
    INTERNATIONAL CONFERENCE ON INFORMATION SOCIETY (I-SOCIETY 2016), 2016, : 143 - 148
  • [42] Anticipatory Governance in Biobanking: Security and Risk Management in Digital Health
    Rychnovska, Dagmar
    SCIENCE AND ENGINEERING ETHICS, 2021, 27 (03)
  • [43] Anticipatory Governance in Biobanking: Security and Risk Management in Digital Health
    Dagmar Rychnovská
    Science and Engineering Ethics, 2021, 27
  • [44] Risk management, compliance, and governance for resilient information systems
    Schermann, Michael
    Krcmar, Helmut
    Lecture Notes in Informatics (LNI), Proceedings - Series of the Gesellschaft fur Informatik (GI), 2010, P-176 : 229 - 230
  • [45] Risk management, compliance and governance for resistant information systems
    Schermann, Michael
    Krcmar, Helmut
    INFORMATIK 2010 - Service Science - Neue Perspektiven fur die Informatik, Beitrage der 40. Jahrestagung der Gesellschaft fur Informatik e.V. (GI), 2010, 2 : 229 - 230
  • [46] Information Security Governance model to enhance zakat information management in Malaysian Zakat Institutions
    Sulaiman, Hidayah
    Jamil, Norziana
    PROCEEDINGS OF THE 2014 6TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND MULTIMEDIA (ICIM), 2014, : 200 - 205
  • [47] Information security risk management for computerized health information systems in hospitals: a case study of Iran
    Zarei, Javad
    Sadoughi, Farahnaz
    RISK MANAGEMENT AND HEALTHCARE POLICY, 2016, 9 : 75 - 85
  • [48] Study of orgware for information security management
    Zhang, LT
    Cheng, JM
    Qian, XS
    PROGRESS IN SAFETY SCIENCE AND TECHNOLOGY, VOL V, PTS A AND B, 2005, 5 : 464 - 469
  • [49] Study on Information Security of Industry Management
    Li Xuemei
    Li Yan
    Ding Lixing
    2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 1, PROCEEDINGS, 2009, : 522 - +
  • [50] Information systems security policy compliance: An empirical study of the effects of socialisation, influence, and cognition
    Ifinedo, Princely
    INFORMATION & MANAGEMENT, 2014, 51 (01) : 69 - 79