2025 27th International Conference on Business Informatics (CBI)(2025)
Department of Information Science
被引用0|浏览0
摘要
The rising frequency of cyberattacks, data breaches, and regulatory pressures has increased the importance of board-level involvement in Information Security Governance (ISG). While prior conceptual research has defined six fundamental board roles, how these roles are understood and enacted in practice remains unclear. To address this gap, this study investigates board-level ISG involvement through twelve semi-structured interviews with Chief Information Security Officers (CISOs). Using an inductive thematic analysis followed by deductive interpretive mappings of the six conceptual board roles, the study provides empirical insights into their actual manifestations. Although many aspects of conceptual role definitions align with practice, important nuances emerged, including the reactive and compliance-driven nature of board engagement. In addition to refining theoretical understanding, the paper analyzes board-level responsibilities, challenges, and contextual influences; identifies key barriers to implementation; and proposes future research directions to reduce the gap between boards' theoretical responsibilities and practical activities.
更多
查看译文
关键词
Information Security Governance (ISG),Board Involvement,Chief Information Security Officer (CISO),Board of Directors