Systematic Literature Review and ISO Standards analysis to Integrate IT Governance and Security Risk Management

  • Mayer N
  • De Smet D
N/ACitations
Citations of this article
40Readers
Mendeley users who have this article in their library.

Abstract

GRC is an umbrella acronym covering the three disciplines of governance, risk management and compliance. In this context, IT GRC is the subset of GRC dealing with IT aspects of GRC. The main challenge of GRC is to have an approach as integrated as possible of the three domains. The objective of our paper is to study one facet of IT GRC: the links and integration between IT governance and risk management that we consider today as the least integrated. To do so, the method followed in this paper is first a systematic literature review, in order to identify the existing research works in this field. The resulting contribution of the paper is a set of recommendations established for practitioners and for researchers on how better deal with the integration between IT governance and risk management. It is then complemented by an analysis of ISO related standards, representative of industrial practices.

Cite

CITATION STYLE

APA

Mayer, N., & De Smet, D. (2017). Systematic Literature Review and ISO Standards analysis to Integrate IT Governance and Security Risk Management. International Journal for Infonomics, 10(1). https://doi.org/10.20533/iji.1742.4712.2017.0154

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free