Too busy to monitor? Board busyness and the occurrence of reported information security incidents

4Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.

Abstract

This paper investigates the association between board busyness (i.e., directors with multiple positions) and the occurrence of reported information security incidents. Building on prior studies of board busyness, this paper argues that directors holding multiple board seats may fail to commit the time and effort necessary to ensure the appropriate information security strategy or investment plans are in place. Our results demonstrate that board busyness is positively associated with reported information security incidents. This effect is larger when independent directors are busy, thus suggesting the importance of the governance role played by independent directors in managing information security risks. The board of directors' role has been emphasized in anecdotal evidence and IT governance frameworks, but our study empirically demonstrates the board's relevance in information security strategy and management.

Cite

CITATION STYLE

APA

Hsu, C., & Wang, T. (2021). Too busy to monitor? Board busyness and the occurrence of reported information security incidents. In Proceedings of the Annual Hawaii International Conference on System Sciences (Vol. 2020-January, pp. 6232–6241). IEEE Computer Society. https://doi.org/10.24251/hicss.2021.752

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free