ERROR: relation "aaa150501_proceeding_action_tracker" does not exist LINE 1: INSERT INTO aaa150501_proceeding_action_tracker(action_track... ^There was an unexpected database error.ERROR: relation "aaa150501_proceeding_action_tracker" does not exist LINE 1: INSERT INTO aaa150501_proceeding_action_tracker(action_track... ^There was an unexpected database error.Information Systems Section Midyear Meeting and AIS New Scholar Consortium: IT Governance and the Maturity of IT Risk Management Practices
Individual Submission Summary
Share...

Direct link:

IT Governance and the Maturity of IT Risk Management Practices

Fri, January 23, 3:30 to 5:00pm, TBA

Abstract

With the Securities and Exchange Commission’s enhanced disclosure rules along with states’ requirements to publicly disclose compromised customer information, IT risk management has emerged is a major concern for boards of directors and management. The Committee of Sponsoring Organizations (COSO) Enterprise Risk Management (ERM) framework further emphasizes the importance of the board’s oversight role and the organization’s reporting structure. This study examines whether the maturity of Information Technology (IT) risk management practices depends on CEO/Chairman duality and Chief Information Officer (CIO) reporting structure.

Using a survey methodology sent to high level IT professionals, we develop a scale to measure strategic maturity and operational maturity under the larger auspice of IT risk management. We then ask the IT professionals about the governance structure of their firms. Consistent with our hypothesis, we find that the maturity of strategic IT risk management practices are higher when the CIO reports to the Chief Executive Officer (CEO). However, contrary to expectations, we do not find that operational risk management is more mature when the CIO reports to the Chief Financial Officer (CFO). Instead, operational risk management is higher when the CIO reports to the CEO. For public firms, the maturity of IT risk management practices are higher when the CEO is also chairman of the board of directors. As C-level officers may have asymmetric assess to the board, understanding reporting structures may inform how well firms manage IT risk and therefore influence IT Governance.

Authors