Corporate governance and the information system: how a framework for IT governance supports ERM

被引:28
作者
Rubino, Michele [1 ]
Vitolla, Filippo [1 ]
机构
[1] LUM Jean Monnet Univ, Dept Econ & Management, Casamassima, Italy
来源
CORPORATE GOVERNANCE-THE INTERNATIONAL JOURNAL OF BUSINESS IN SOCIETY | 2014年 / 14卷 / 03期
关键词
Corporate governance; Internal control; IT governance; COBIT; 5; framework; COSO ERM;
D O I
10.1108/CG-06-2013-0067
中图分类号
F [经济];
学科分类号
02 ;
摘要
Purpose - The purpose of this paper is to illustrate how information technology (IT) governance supports the process of enterprise risk management (ERM). In particular, the paper illustrates how the Control Objectives for Information and related Technology (COBIT) framework helps a company reach its objectives by integrating and supporting the Enterprise Risk Management by the Committee of Sponsoring Organizations (COSO ERM) framework. Design/methodology/approach - This paper explains how the integration between the two frameworks (COSO ERM and COBIT 5) can represent, for any organization, a good way to achieve the objectives of internal control and risk management and, more generally, corporate governance. Findings - The paper identifies some gaps in the COSO ERM and illustrates how the COBIT framework facilitates the implementation of an adequate system of internal control. Originality/value - The originality of the work presented here is in analyzing the COBIT 5 together with the COSO ERM framework. This paper highlights that is not enough to apply only an internal control framework for achieving the risk management and internal control system objectives. An IT governance framework, such as COBIT 5 is proposed as a tool that support risk management in order to develop an adequate system of internal control.
引用
收藏
页码:320 / +
页数:21
相关论文
共 117 条
[91]  
Rubino M., 2012, MANAGEMENT GOVERNANC
[92]   Information system success: Individual and organizational determinants [J].
Sabherwal, Rajiv ;
Jeyaraj, Anand ;
Chowa, Charles .
MANAGEMENT SCIENCE, 2006, 52 (12) :1849-1864
[93]  
Saeidi P., 2012, INT RES J FINANCE EC, V88, P118
[94]   Arrangements for information technology governance: A theory of multiple contingencies [J].
Sambamurthy, V ;
Zmud, RW .
MIS QUARTERLY, 1999, 23 (02) :261-290
[95]   Research commentary: The organizing logic for an enterprise's IT activities in the digital era - A prognosis of practice and a call for research [J].
Sambamurthy, V ;
Zmud, RW .
INFORMATION SYSTEMS RESEARCH, 2000, 11 (02) :105-114
[96]  
Schlosser F, 2010, P ANN HICSS, P4009
[97]   The Chief Information Officer and Chief Financial Officer Dyad in the Public Sector: How an Effective Relationship Impacts Individual Effectiveness and Strategic Alignment [J].
Schobel, Kurt ;
Denford, James S. .
JOURNAL OF INFORMATION SYSTEMS, 2013, 27 (01) :261-281
[98]  
Scholey C., 2006, CMA MANAGEMENT, V32, P32
[99]   An extended platform logic perspective of IT governance: managing perceptions and activities of IT [J].
Schwarz, A ;
Hirschheim, R .
JOURNAL OF STRATEGIC INFORMATION SYSTEMS, 2003, 12 (02) :129-166
[100]  
Shenkir W. G., 2006, ENTERPRISE RISK MANA