A Systematic Review on Cyber Security Integration in Information Technology Governance

Mopati Kekgathetse, Botlhe Lucas, Mavuna Sebapalo · 2024

The wake of growing cyber threats to organizations has made integration of cybersecurity practices into Information Technology Governance of paramount importance. The paper presents a systematic literature review (SLR) that seeks to understand the current state of IT governance frameworks and how they integrate issues of cybersecurity governance. It reviews four specific research questions: (1) the existing IT governance frameworks and their integration with cybersecurity practices, (2) the challenges and limitations to this integration, (3) the alignment of IT governance with internationally recognized cybersecurity standards, and finally, (4) best practices to enhance cybersecurity governance within IT governance. The findings reveal that while frameworks such as COBIT and ITIL embrace aspects of cybersecurity, some gaps still exist. Furthermore, standards in the lines of ISOIIEC 27001 and the NIST Cybersecurity framework remain partially adhered to at best by the IT governance frameworks; hence, the approach to cyber security governance is to be tailored to respective specific needs of an organization. The research contributes to the growing knowledge base of IT governance and cybersecurity by adding actionable insight for practitioners while demarcating areas for further research to enhance cybersecurity governance within IT governance frameworks.

Read the paper · More papers on PaperTik