Skip to main content
Article
The influence of a good relationship between the internal audit and information security functions on information security outcomes
Accounting, Organizations and Society
  • Paul John Steinbart, Arizona State University, Tempe
  • Robyn Raschke, University of Nevada, Las Vegas
  • Graham Gal, University of Massachusetts, Amherst
  • William N. Dilla, Iowa State University
Document Type
Article
Publication Version
Accepted Manuscript
Publication Date
1-1-2018
DOI
10.1016/j.aos.2018.04.005
Abstract
Given the increasing financial impact of cybercrime, it has become critical for companies to manage information security risk. The practitioner literature has long argued that the internal audit function (IAF) can play an important role both in providing assurance with respect to information security and in generating insights about how to improve the organization's information security. Nevertheless, there is scant empirical evidence to support this belief. Using a unique data set, this study examines how the quality of the relationship between the internal audit and the information security functions affects objective measures of the overall effectiveness of an organization's information security efforts. The quality of this relationship has a positive effect on the number of reported internal control weaknesses and incidents of noncompliance, as well as on the numbers of security incidents detected, both before and after they caused material harm to the organization. In addition, we find that higher levels of management support for information security and having the chief information security officer (CISO) report independently of the IT function have a positive effect on the quality of the relationship between the internal audit and information security functions.
Comments

This is a manuscript of the article published as Steinbart, Paul John, Robyn L. Raschke, Graham Gal, and William N. Dilla. "The influence of a good relationship between the internal audit and information security functions on information security outcomes." Accounting, Organizations and Society (2018). DOI: 10.1016/j.aos.2018.04.005. Posted with permission.

Creative Commons License
Creative Commons Attribution-Noncommercial-No Derivative Works 4.0
Copyright Owner
Elsevier Ltd.
Language
en
File Format
application/pdf
Citation Information
Paul John Steinbart, Robyn Raschke, Graham Gal and William N. Dilla. "The influence of a good relationship between the internal audit and information security functions on information security outcomes" Accounting, Organizations and Society (2018)
Available at: http://works.bepress.com/william-dilla/10/