DocumentCode
3590434
Title
An Empirical Study into Information Security Governance Focus Areas and their Effects on Risk Management
Author
Yaokumah, Winfred ; Brown, Steven
Author_Institution
Dept. of Inf. Technol., Pentecost Univ. Coll., Accra, Ghana
fYear
2014
Firstpage
42
Lastpage
49
Abstract
This paper aimed at determining the extent to which information security governance (ISG) focus areas impact risk management. A total of 81 valid questionnaires were collected and processed using multiple linear regression and frequency analyses. The results showed that 92.7% of the variances in risk management were explained by the resource management, information security and business strategic alignment, value delivery, and performance measurement. Resource management and strategic alignment made significant positive contribution to risk management. Among the most applied attributes within the ISG focus areas, the organizations appreciably implemented policies that address risk management and non-compliance to security risk. However, risk assessment was not frequently and exhaustively performed and security personnel were not adequately trained. The study contributed to the literature by empirically determining the impact of ISG focus areas on risk management, provided organizational leaders better understanding of ISG focus areas, and suggested improvement to ISG practices.
Keywords
business data processing; regression analysis; resource allocation; risk management; security of data; ISG focus areas; business strategic alignment; frequency analyses; information security governance; linear regression; organizational leaders; performance measurement; resource management; risk management; value delivery; Information security; Organizations; Resource management; Risk management; Standards organizations; Information Security Governance; Performance Measurement; Resource Management; Risk Management; Strategic Alignment; Value Delivery;
fLanguage
English
Publisher
ieee
Conference_Titel
Information and Computer Technology (GOCICT), 2014 Annual Global Online Conference on
Type
conf
DOI
10.1109/GOCICT.2014.12
Filename
7113663
Link To Document