ERROR: relation "aaa170501_proceeding_action_tracker" does not exist LINE 1: INSERT INTO aaa170501_proceeding_action_tracker(action_track... ^There was an unexpected database error.ERROR: relation "aaa170501_proceeding_action_tracker" does not exist LINE 1: INSERT INTO aaa170501_proceeding_action_tracker(action_track... ^There was an unexpected database error.Joint Mid-Year Meeting of the AIS and SET Sections: IT Risk Management Practices: Management Focus and Patterns
Individual Submission Summary
Share...

Direct link:

IT Risk Management Practices: Management Focus and Patterns

Sat, January 21, 8:15 to 9:45am, TBA

Abstract

Information Technology (IT) risk management is an important component of enterprise risk management. As a result of increased cybersecurity incidents, regulators and external stakeholders are putting pressure on the board of directors and the management to take adequate actions to reduce risks related to IT. Therefore, this study explores whether firms emphasize on a particular IT risk type at different maturity levels and identify any underlying patterns in IT risk management practices.
I survey IT professionals on their perception of IT risk management practices in their respective firms. I determine maturity scores for benefit/value enablement, operations/service delivery, and both risk types (overall maturity score). The findings suggest that firms focus more on operations/service delivery IT risk management practices in spite of the level of maturity. Further, the results suggests that management is not taking a holistic view of IT risk management practices.
These results contribute to 1) IT risk management strategies, an under researched area, in IT governance literature, and 2) the profession by highlighting the current management practices and emphasizing that management is not taking an holistic view of IT risk management.

Author