Search
Program Calendar
Browse By Day
Search Tips
Virtual Exhibit Hall
Personal Schedule
Sign In
Practitioners recognize the importance of internal audit in managing information security risks. The role of internal audit in information security is to provide objective assurance to the board and executive management on how well an organization manages risk in this area. Indeed, internal audit is a key component of information security governance, along with an organization’s executive management and other managers who are responsible for specific oversight regarding information security. Therefore, the objective of this study is to examine the association between audit professionals’ perceptions regarding information security governance and the relationship between these perceptions and self-reported measures of information security effectiveness. It reports the results of a survey of 111 AICPA Information Management and Technology Assurance (IMTA) interest area members regarding information security governance and outcomes. Respondents include external auditors, consultants, internal auditors, and other individuals with internal information security responsibilities. Results show that a positive working relationship between the information security and internal audit functions generally has a positive impact on information security outcomes. In addition, top management support for information security has a positive influence on the awareness of harmful security incidents and on stopping potentially harmful security outcomes.
Paul J Steinbart, Arizona State University - Tempe
Graham Gal, University of Massachusetts-Amherst
Robyn L Raschke, University of Nevada-Las Vegas
William N Dilla, Iowa State University