Integration of it governance and security risk management: A systematic literature review

Authors

D. D. Smet and N. Mayer

Reference

in 2016 International Conference on Information Society (i-Society), pp. 143-148, 2016

Description

GRC is an umbrella acronym covering the three disciplines of governance, risk management and compliance. In this context, IT GRC is the subset of GRC dealing with IT aspects of GRC. The main challenge of GRC is to have an approach as integrated as possible of the three domains. The objective of our paper is to study one facet of IT GRC: the links and integration between IT governance and risk management that we consider today as the least integrated. To do so, the method followed in this paper is a systematic literature review, in order to identify the existing research works in this field. The resulting contribution of the paper is a set of recommendations established for practitioners and for researchers on how better deal with the integration between IT governance and risk management.

Link

DOI: 10.1109/i-Society.2016.7854200

Share this page: