ERROR: relation "aaa160401_proceeding_action_tracker" does not exist LINE 1: INSERT INTO aaa160401_proceeding_action_tracker(action_track... ^There was an unexpected database error.ERROR: relation "aaa160401_proceeding_action_tracker" does not exist LINE 1: INSERT INTO aaa160401_proceeding_action_tracker(action_track... ^There was an unexpected database error.Joint Mid-Year Meeting of the Accounting Information Systems Section and the Strategic and Emerging Technologies Section: The Influence of IT Governance Structures on Information Security Effectiveness: Perceptions of Audit Professionals
Individual Submission Summary
Share...

Direct link:

The Influence of IT Governance Structures on Information Security Effectiveness: Perceptions of Audit Professionals

Fri, January 22, 3:30 to 5:00pm, TBA

Abstract

Practitioners recognize the importance of internal audit in managing information security risks. The role of internal audit in information security is to provide objective assurance to the board and executive management on how well an organization manages risk in this area. Indeed, internal audit is a key component of information security governance, along with an organization’s executive management and other managers who are responsible for specific oversight regarding information security. Therefore, the objective of this study is to examine the association between audit professionals’ perceptions regarding information security governance and the relationship between these perceptions and self-reported measures of information security effectiveness. It reports the results of a survey of 111 AICPA Information Management and Technology Assurance (IMTA) interest area members regarding information security governance and outcomes. Respondents include external auditors, consultants, internal auditors, and other individuals with internal information security responsibilities. Results show that a positive working relationship between the information security and internal audit functions generally has a positive impact on information security outcomes. In addition, top management support for information security has a positive influence on the awareness of harmful security incidents and on stopping potentially harmful security outcomes.

Authors