Defining Internal Control Objectives for Information Systems Security: A Value Focused Assessment

Sushma Mishra, Gurpreet S. Dhillon · Journal of the Association for Information Systems · 2008

Internal controls play an important role in overall effectiveness of information systems security.A theoretical framework of means-fundamental objectives for internal controls in information systems security context is presented.Data was collected through in-depth interview of 52 IT managers about their values in defining internal controls.A total of 68 objectives are identified which are organized into 25 clusters of seven fundamental and 18 means objectives.The findings form the basis for further theoretical expositions in security governance area.The objectives also help in defining governance related policy initiatives.

Read the paper · More papers on PaperTik