Information Security Professionals' Perceptions about the Relationship between the Information Security and Internal Audit Functions

被引:24
|
作者
Steinbart, Paul John [1 ]
Raschke, Robyn L. [2 ]
Gal, Graham [3 ]
Dilla, William N. [4 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
[2] Univ Nevada, Las Vegas, NV 89557 USA
[3] Univ Massachusetts, Amherst, MA 01003 USA
[4] Iowa State Univ, Ames, IA 50011 USA
关键词
internal audit; information systems security; information security governance; perceptions; survey;
D O I
10.2308/isys-50510
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
Internal auditors and information security professionals both play important roles in protecting an organization's assets. Indeed, there are potential synergistic benefits if they work together. The relationship between the two functions, however, is not always supportive. This paper presents the results of a survey of information security professionals' perceptions about the nature of the relationship between the information security and internal audit functions in their organization. We find that information security professionals' perceptions about the level of technical expertise possessed by internal auditors and the extent of internal audit review of information security are positively related to their assessment about the quality of the relationship between the two functions. We also find that the quality of the relationship between the internal audit and information security functions is positively associated with perceptions about the value provided by internal audit and, most important, with measures of overall effectiveness of the organization's information security endeavors. We discuss the implications of our findings for both research and practice.
引用
收藏
页码:65 / 86
页数:22
相关论文
共 50 条
  • [1] The influence of a good relationship between the internal audit and information security functions on information security outcomes
    Steinbart, Paul John
    Raschke, Robyn L.
    Gal, Graham
    Dilla, William N.
    [J]. ACCOUNTING ORGANIZATIONS AND SOCIETY, 2018, 71 : 15 - 29
  • [2] The relationship between internal audit and information security: An exploratory investigation
    Steinbart, Paul John
    Raschke, Robyn L.
    Gal, Graham
    Dilla, William N.
    [J]. INTERNATIONAL JOURNAL OF ACCOUNTING INFORMATION SYSTEMS, 2012, 13 (03) : 228 - 243
  • [3] Discussion of "The relationship between internal audit and information security: An exploratory investigation"
    Grabski, Severin
    [J]. INTERNATIONAL JOURNAL OF ACCOUNTING INFORMATION SYSTEMS, 2012, 13 (03) : 244 - 247
  • [4] The Potential for a Synergistic Relationship Between Information Security and a Financial Audit
    Singleton, Tommie W.
    Singleton, Aaron J.
    [J]. INFORMATION SECURITY JOURNAL, 2008, 17 (02): : 80 - 86
  • [5] EXAMINING THE RELATIONSHIP BETWEEN INFORMATION SECURITY EFFECTIVENESS AND INFORMATION SECURITY THREATS
    Masrek, Mohamad Noorman
    Soesantari, Tri
    Khan, Asad
    Dermawan, Aang Kisnu
    [J]. INTERNATIONAL JOURNAL OF BUSINESS AND SOCIETY, 2020, 21 (03): : 1203 - 1214
  • [6] THE RELATIONSHIP BETWEEN INFORMATION SYSTEMS RESOURCES AND INFORMATION SECURITY
    Anwar, Norizan
    Masrek, Mohamad Noorman
    Zaini, Muhamad Khairulnizam
    Harun, Qamarul Nazrin
    [J]. 4TH INTERNATIONAL CONFERENCE ON EDUCATION AND SOCIAL SCIENCES (INTCESS 2017), 2017, : 884 - 894
  • [7] Exploring the Relationship between Internal Information Security, Response Cost, and Security Intention in Container Shipping
    Wang, Hsin-Wei
    Kuo, Szu-Yu
    Chen, Liang-Bi
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (06):
  • [8] IS professionals' information security behaviors in Chinese IT organizations for information security protection
    Ma, Xiaofen
    [J]. INFORMATION PROCESSING & MANAGEMENT, 2022, 59 (01)
  • [9] INTERNAL AUDIT OF INFORMATION TECHNOLOGIES IN STRENGTHENING SECURITY IN ROMANIAN UNIVERSITIES
    Sabau, Constantin
    Sabau, Daniela-Veronica
    Zacharias, Domnita
    [J]. QUALITY MANAGEMENT IN HIGHER EDUCATION, VOL 2, 2010, : 635 - 638
  • [10] Information Security Culture Concept towards Information Security Compliance: A Comparison between IT and Non-IT Professionals
    Nasir, Akhyari
    Arshah, Ruzaini Abdullah
    Ab Hamid, Mohd Rashid
    Fahmy, Syahrul
    [J]. INTERNATIONAL JOURNAL OF INTEGRATED ENGINEERING, 2022, 14 (03): : 157 - 165