Assessing Privacy and Security of Information Systems from Audit Data
J. Christopher Westland ()
Additional contact information
J. Christopher Westland: University of Illinois Chicago
Information Systems Frontiers, 2022, vol. 24, issue 5, No 3, 1417-1434
Abstract:
Abstract We investigated publicly reported security breaches of internal controls in corporate information systems to determine whether U.S. Securities and Exchange Commission (SEC) data are information bearing with respect to breaches of security and privacy. The issue has grown in importance as information systems breaches have steadily grown costlier and more frequent. Our analysis supports a high predictability for credit card breaches, portable device related breaches and breaches conducted by firm insiders. Our study also found evidence that employees are subverting particularly strict internal controls by using portable devices that can be carried outside the physical boundaries of the firm. In general, auditing and corporate data filed with the SEC was non-informative with regard to breaches involving unintended disclosures, physical losses, hacking and malware and workplace computers. Scope and fees associated with auditing are significant factors in predicting security breaches, whereas assessments of internal controls effectiveness was shown to be less significant for prediction.
Keywords: Security; Privacy; Internal control; Auditing; Computer security; Computer fraud (search for similar items in EconPapers)
Date: 2022
References: View references in EconPapers View complete reference list from CitEc
Citations:
Downloads: (external link)
http://link.springer.com/10.1007/s10796-021-10129-5 Abstract (text/html)
Access to the full text of the articles in this series is restricted.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:infosf:v:24:y:2022:i:5:d:10.1007_s10796-021-10129-5
Ordering information: This journal article can be ordered from
http://www.springer.com/journal/10796
DOI: 10.1007/s10796-021-10129-5
Access Statistics for this article
Information Systems Frontiers is currently edited by Ram Ramesh and Raghav Rao
More articles in Information Systems Frontiers from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().