首页> 外文学位 >Evaluating the effectiveness of information security governance practices in developing nations: A case of Ghana.
【24h】

Evaluating the effectiveness of information security governance practices in developing nations: A case of Ghana.

机译:评估发展中国家信息安全治理实践的有效性:以加纳为例。

获取原文
获取原文并翻译 | 示例

摘要

The problem organizations are facing is lack of effective information security governance (ISG) to address emerging security risks, threats and vulnerabilities. The intent of this quantitative cross-sectional survey research is to evaluate the level of ISG effectiveness within the five ISG domain areas, namely strategic alignment (SA), risk management (RM), resource management (RM), performance measurement (PM), and value delivery (VD), identified by the Information Technology Governance Institute (ITGI) and required to improve ISG practices. Random sampling strategy is employed and an empirical survey, a Web-based questionnaire, is conducted using the Information Security Governance Assessment Questionnaire to collect data from five major industry sectors in Ghana. Simple and multiple regression analyses are employed to assess the extent of the relationship between ISG domain practices, outcomes, and effectiveness; and ANOVA (analysis of variance) is used to benchmark industry sectors' ISG effectiveness. Overall, the multiple regression model produced R2 = .505, indicating that 50.5% of the variance in ISG effectiveness was explained by ISG domain practices. The results highlight the consistent importance of RM, PM, and RK as the predictors of organizational ISG effectiveness while SA contributed marginally to the model. The linear regression analyses results highlight the importance of SA (R2 = .836) as the major predictor of organizational information security RK. The findings show significant contributions of SA to RM (R 2 = .747), SA to PM (R2 = .722), and SA to VD (R2 = .718). The ANOVA results also show that Financial Institutions outperforms all the other sectors in each of the five ISG domain areas, the Public Service and the Health Care sectors perform at the lowest level, and the PM is the least implemented domain. Accordingly, to attain higher ISG effectiveness, organizations should focus on strategic alignment between business and information security and performance measurement attributes. The study provides researchers the avenue to conduct comparative studies between developed and developing nations. From a practical standpoint, the study enables organizational leaders to gain better understanding of the factors that contribute to ISG effectiveness, benchmark industry sectors' performance, and to champion ISG development for business success in Ghanaian organizations.
机译:组织面临的问题是缺乏有效的信息安全治理(ISG)来解决新兴的安全风险,威胁和漏洞。这项定量横断面调查研究的目的是评估ISG五个领域内ISG有效性的水平,即战略一致性(SA),风险管理(RM),资源管理(RM),绩效衡量(PM),和价值传递(VD),由信息技术治理研究所(ITGI)确定,并需要改进ISG做法。采用了随机抽样策略,并使用“信息安全治理评估问卷”进行了基于Web的问卷调查,以实证调查为基础,从加纳的五个主要行业部门收集数据。简单和多元回归分析用于评估ISG领域实践,结果和有效性之间的关系程度; ANOVA(方差分析)用于基准行业部门的ISG有效性。总体而言,多元回归模型得出R2 = .505,表明ISG领域实践解释了ISG有效性差异的50.5%。结果突出了RM,PM和RK作为组织ISG有效性的预测因素的一贯重要性,而SA对模型的贡献很小。线性回归分析结果突出了SA(R2 = .836)作为组织信息安全RK的主要预测指标的重要性。研究结果表明,SA对RM(R 2 = .747),SA对PM(R2 = .722)和SA对VD(R2 = .718)有重要贡献。方差分析的结果还表明,在ISG的五个领域中,金融机构的表现均优于其他所有领域,公共服务和卫生保健领域的绩效最低,而PM是实施最少的领域。因此,为了获得更高的ISG有效性,组织应将重点放在业务和信息安全以及绩效度量属性之间的战略一致性上。该研究为研究人员提供了在发达国家与发展中国家之间进行比较研究的途径。从实践的角度来看,该研究使组织领导者可以更好地理解影响ISG有效性,基准行业部门绩效的因素,并支持ISG为加纳组织的业务成功而发展。

著录项

  • 作者

    Yaokumah, Winfred.;

  • 作者单位

    Capella University.;

  • 授予单位 Capella University.;
  • 学科 Information Technology.
  • 学位 Ph.D.
  • 年度 2013
  • 页码 273 p.
  • 总页数 273
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号