Defining Internal Control Objectives for Information Systems Security: A Value Focused Assessment
Sushma Mishra, Gurpreet S. Dhillon · Journal of the Association for Information Systems · 2008
Internal controls play an important role in overall effectiveness of information systems security.A theoretical framework of means-fundamental objectives for internal controls in information systems security context is presented.Data was collected through in-depth interview of 52 IT managers about their values in defining internal controls.A total of 68 objectives are identified which are organized into 25 clusters of seven fundamental and 18 means objectives.The findings form the basis for further theoretical expositions in security governance area.The objectives also help in defining governance related policy initiatives.