메뉴 건너뛰기




Volumn 25, Issue 1, 2011, Pages 185-211

Information security and sarbanes-oxley compliance: An exploratory study

Author keywords

Information security; Internal control; ISO 17799; Sarbanes oxley

Indexed keywords


EID: 79961156940     PISSN: 08887985     EISSN: 15587959     Source Type: Journal    
DOI: 10.2308/jis.2011.25.1.185     Document Type: Article
Times cited : (56)

References (38)
  • 3
    • 33847748221 scopus 로고    scopus 로고
    • Is information security under control? Investigating quality in information security management
    • Baker, W., and L. Wallace. 2007. Is information security under control? Investigating quality in information security management. IEEE Security and Privacy 5 (1): 36-44.
    • (2007) IEEE Security and Privacy , vol.5 , Issue.1 , pp. 36-44
    • Baker, W.1    Wallace, L.2
  • 5
    • 85006687496 scopus 로고    scopus 로고
    • Sarbanes-Oxley and enterprise security: IT governance-What it takes to get the job done
    • Brown, W., and F. Nasuti. 2002. Sarbanes-Oxley and enterprise security: IT governance-What it takes to get the job done. Security Management Practices 14 (5): 15-28.
    • (2002) Security Management Practices , vol.14 , Issue.5 , pp. 15-28
    • Brown, W.1    Nasuti, F.2
  • 7
    • 84889602684 scopus 로고    scopus 로고
    • Bay Area, CA: Orange Parachute
    • Carlson, T. 2008. Understanding ISO 27002. Bay Area, CA: Orange Parachute. Available at: http://www.orangeparachute.com/documents/Understanding(ISO)27001.pdf.
    • (2008) Understanding ISO 27002
    • Carlson, T.1
  • 8
    • 33645607311 scopus 로고    scopus 로고
    • CIOInsight, New York, NY: CIOInsight
    • CIOInsight. 2004. EXP Research: Sarbanes-Oxley 2004: Are You Ready to Comply? New York, NY: CIOInsight. Available at: http://www.cioinsight.com/c/a/Research/Research-SarbanesOxley-Are-You-Ready-to-Comply/.
    • (2004) EXP Research: Sarbanes-Oxley 2004: Are You Ready to Comply?
  • 9
    • 77956747502 scopus 로고    scopus 로고
    • Auditors' training and proficiency in information systems: A research synthesis
    • Curtis, M. B., J. G. Jenkins, J. C. Bedard, and D. R. Deis. 2009. Auditors' training and proficiency in information systems: A research synthesis. Journal of Information Systems 23 (1): 79-96.
    • (2009) Journal of Information Systems , vol.23 , Issue.1 , pp. 79-96
    • Curtis, M.B.1    Jenkins, J.G.2    Bedard, J.C.3    Deis, D.R.4
  • 11
    • 10244236477 scopus 로고    scopus 로고
    • Sarbanes-Oxley and IT governance: New guidance on IT control and compliance
    • Damianides, M. 2005. Sarbanes-Oxley and IT governance: New guidance on IT control and compliance. Information Systems Management 22 (1): 77-85.
    • (2005) Information Systems Management , vol.22 , Issue.1 , pp. 77-85
    • Damianides, M.1
  • 12
    • 35148886676 scopus 로고    scopus 로고
    • An information security governance framework
    • Da Veiga, A., and J. Eloff. 2007. An information security governance framework. Information Systems Management 24 (4): 361-372.
    • (2007) Information Systems Management , vol.24 , Issue.4 , pp. 361-372
    • da Veiga, A.1    Eloff, J.2
  • 13
    • 34250795250 scopus 로고    scopus 로고
    • The Sarbanes-Oxley Act and firms' going-private decisions
    • Engel, E., R. Hayes, and X. Wang. 2007. The Sarbanes-Oxley Act and firms' going-private decisions. Journal of Accounting and Economics 44: 116-145.
    • (2007) Journal of Accounting and Economics , vol.44 , pp. 116-145
    • Engel, E.1    Hayes, R.2    Wang, X.3
  • 14
    • 70149117261 scopus 로고    scopus 로고
    • Size, structure and change implementation: An empirical comparison of small and large organizations
    • Ford, M. 2009. Size, structure and change implementation: An empirical comparison of small and large organizations. Management Research News 32 (4): 303-320.
    • (2009) Management Research News , vol.32 , Issue.4 , pp. 303-320
    • Ford, M.1
  • 15
    • 84991755401 scopus 로고    scopus 로고
    • Seven points financial institutions should know about IT spending for compliance
    • Garcia, V. 2004. Seven points financial institutions should know about IT spending for compliance. Journal of Financial Regulation and Compliance 12 (4): 330-339.
    • (2004) Journal of Financial Regulation and Compliance , vol.12 , Issue.4 , pp. 330-339
    • Garcia, V.1
  • 17
    • 79961132379 scopus 로고    scopus 로고
    • Alphabet soup: Understanding standards for risk management and compliance
    • June 2
    • Harris, S. 2006. Alphabet soup: Understanding standards for risk management and compliance. Information Security Magazine (June 2).
    • (2006) Information Security Magazine
    • Harris, S.1
  • 18
    • 29544446298 scopus 로고    scopus 로고
    • Sarbanes-Oxley: Achieving compliance by starting with ISO 17799
    • Haworth, D. A., and L. R. Pietron. 2006. Sarbanes-Oxley: Achieving compliance by starting with ISO 17799. Information Systems Management 23 (1): 73-87.
    • (2006) Information Systems Management , vol.23 , Issue.1 , pp. 73-87
    • Haworth, D.A.1    Pietron, L.R.2
  • 19
    • 84889579702 scopus 로고    scopus 로고
    • Information Systems Audit and Control Association (ISACA(, Rolling Meadows, IL: ISACA. Available at
    • Information Systems Audit and Control Association (ISACA(. 2005. COBIT Mapping: Mapping ISO/IEC 17799: 2000 with COBIT. Rolling Meadows, IL: ISACA. Available at: http://www.isaca-oregon.org/docs/Mapping%20Cobit%20to%20ISO%2017799.pdf.
    • (2005) COBIT Mapping: Mapping ISO/IEC 17799: 2000 With COBIT
  • 20
    • 28044457328 scopus 로고    scopus 로고
    • International Organization for Standardization (ISO), Geneva, Switzerland: ISO
    • International Organization for Standardization (ISO). 2005. Information Technology-Security Techniques-Code of Practice for Information Security Management. Geneva, Switzerland: ISO. Available at: http://www.iso.org/iso/iso(catalogue/catalogue)tc/catalogue(detail.htm?csnumber)39612.
    • (2005) Information Technology-Security Techniques-Code of Practice For Information Security Management
  • 21
    • 53249102207 scopus 로고    scopus 로고
    • IT Governance Institute (ITGI)
    • IT Governance Institute (ITGI). 2006. IT Control Objectives for Sarbanes-Oxley. Available at: http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables?Pages/IT-Control-Objectives-for-Sarbanes-Oxley-2nd-Edition.aspx.
    • (2006) IT Control Objectives For Sarbanes-Oxley
  • 23
    • 79151469252 scopus 로고    scopus 로고
    • SOX 404 reported internal control weaknesses: A test of COSO framework components and information technology
    • Klamm, B., and M. Weidenmier-Watson. 2009. SOX 404 reported internal control weaknesses: A test of COSO framework components and information technology. Journal of Information Systems (Fall): 1-23.
    • (2009) Journal of Information Systems (Fall) , pp. 1-23
    • Klamm, B.1    Weidenmier-Watson, M.2
  • 27
    • 49249127269 scopus 로고    scopus 로고
    • Information security management objectives and practices: A parsimonious framework
    • Ma, Q., A. Johnston, and M. Pearson. 2008. Information security management objectives and practices: A parsimonious framework. Information Management & Computer Security 16 (3): 251-270.
    • (2008) Information Management & Computer Security , vol.16 , Issue.3 , pp. 251-270
    • Ma, Q.1    Johnston, A.2    Pearson, M.3
  • 28
    • 79961138006 scopus 로고    scopus 로고
    • The ABCs of reporting on controls
    • October
    • McCuaig, B. 2006. The ABCs of reporting on controls. Internal Auditor (October): 35-39.
    • (2006) Internal Auditor , pp. 35-39
    • McCuaig, B.1
  • 30
    • 0003957502 scopus 로고    scopus 로고
    • National Institute of Standards and Technology, Gaithersburg, MD: National Institute of Standards and Technology
    • National Institute of Standards and Technology. 2007. Criteria for Performance Excellence. Gaithersburg, MD: National Institute of Standards and Technology.
    • (2007) Criteria For Performance Excellence
  • 31
    • 84889594811 scopus 로고    scopus 로고
    • Praxiom Research Group Limited, Edmonton, Canada: Praxiom Research Group Limited
    • Praxiom Research Group Limited. 2008. ISO IEC 27002 2005 Introduction. Edmonton, Canada: Praxiom Research Group Limited. Available at: http://www.praxiom.com/iso-17799-intro.htm.
    • (2008) ISO IEC 27002 2005 Introduction
  • 32
    • 0347178887 scopus 로고    scopus 로고
    • New York, NY: Computer Security Institute
    • Richardson, R. 2008. 2008 CSI Computer Crime & Security Survey. New York, NY: Computer Security Institute. http://i.cmpnet.com/v2.gocsi.com/pdf/CSIsurvey2008.pdf.
    • (2008) CSI Computer Crime & Security Survey
    • Richardson, R.1
  • 33
    • 64949196361 scopus 로고    scopus 로고
    • The implementation of Deming's System Model to improve security management: A case study
    • Tang, J. 2008. The implementation of Deming's System Model to improve security management: A case study. International Journal of Management 25 (1): 54-68.
    • (2008) International Journal of Management , vol.25 , Issue.1 , pp. 54-68
    • Tang, J.1
  • 34
    • 79961142956 scopus 로고    scopus 로고
    • United States Code, Title 44, Section 3552. Washington, D.C.: United States Code
    • United States Code. 2008. Public Printing and Documents: Definitions. Title 44, Section 3552. Washington, D.C.: United States Code.
    • (2008) Public Printing and Documents: Definitions
  • 35
    • 8744256700 scopus 로고    scopus 로고
    • U.S. House of Representatives, Committee on Financial Services, Public Law No. 107-204. Washington, D.C.: Government Printing Office
    • U.S. House of Representatives, Committee on Financial Services. 2002. Sarbanes-Oxley Act of 2002. Public Law No. 107-204. Washington, D.C.: Government Printing Office.
    • (2002) Sarbanes-Oxley Act of 2002
  • 36
    • 70149121254 scopus 로고    scopus 로고
    • U.S. Small Business Administration, Washington, D.C.: U.S. Small Business Administration
    • U.S. Small Business Administration. 2006. Table of Small Business Size Standards. Washington, D.C.: U.S. Small Business Administration.
    • (2006) Table of Small Business Size Standards
  • 37
    • 17844364638 scopus 로고    scopus 로고
    • Information security governance: COBIT or ISO 17799 or both?
    • von Solms, B. 2005. Information security governance: COBIT or ISO 17799 or both? Computers & Security 24: 99-104.
    • (2005) Computers & Security , vol.24 , pp. 99-104
    • von Solms, B.1
  • 38
    • 70449719381 scopus 로고    scopus 로고
    • Research opportunities in information technology and internal auditing
    • Weidenmier, M., and S. Ramamoorti. 2006. Research opportunities in information technology and internal auditing. Journal of Information Systems 20 (1): 205-219.
    • (2006) Journal of Information Systems , vol.20 , Issue.1 , pp. 205-219
    • Weidenmier, M.1    Ramamoorti, S.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.