As cyberthreats pose strategic risk, both IT and business management awareness are critical for effective organisational decision making. Many cyber system failures arise from organisational, and not technical issues. This study investigates senior manager awareness of organisational cyber resilience, using case study method. The Cyber Resilience Matrix is used as a theoretical framework to communicate the multifaceted meaning of cyber resilience. This study examines whether the multilayered nature of cyber resilience is understood by both managerial levels to include the periods before and after cyber incidents. As the higher education sector faces complex cyber challenges, research data were gathered from two Australian universities. Analysis found the two management groups differed in their resilience approach. The authors posit that principles-based cyber policies contribute to an organisational view of cyber resilience. The engineering resilience approach, accompanied by a non-bureaucratic organisational structure, was preferred by IT managers. Business managers favoured an ecological approach with a vertical organisational structure. Both managerial groups emphasised the period before cyber crisis when compared to after cyber incidents. This research contributes to the limited theoretical development in the field and attempts to shift the focus from cyber security to cyber resilience.
Although practitioners have mapped the alignment between IT-related standards, this work has rarely been reported in the academic literature. In particular the methods used have not been made explicit, which has limited the value of any reported results. The research described in this paper demonstrates a rigorous method for mapping the alignment between two example IT security standards. The two standards were Control Objectives for Information and Related Technology (COBIT), widely used as a comprehensive IT control framework, and the Australian Government Information and Communications Technology Security Manual (ACSI 33) which sets out policies and procedures for IT security for Australian government agencies. Conceptual analysis was used to analyse the alignment between the two standards to reveal some insightful patterns of use and emphasis. As one of the security standards defines the base level ICT security for Australian government agencies, related future work using conceptual analysis has the potential to contribute to improved evaluation of the preparedness of commercial Australian organisations to protect the security of their systems from terrorist activities. This paper illustrates the value of such work within a counter-terrorist setting, where leverage for systems security compliance can be gained from voluntary adoption of a commercial standard.
This paper addresses the research questions, “What is the role of the IS auditor in supporting the financial audit?” and “What key determinants affect that role?” through the development of an explanation theory for the role of the IS auditor in the public sector financial audit. Results are based on semi-structured interviews with 55 senior auditors and IS auditors. These auditors worked in ten practice offices in the Australian, Canadian, New Zealand and United Kingdom public sectors. We manually coded 23 interview transcripts and used the Leximancer tool to extend this coding to the remaining transcripts through automated text analysis. The analysis allowed the identification of relevant “common statements” representing the prominent and shared perceptions of the IS auditor role amongst these auditors. These common statements provided a basis for the development of an initial explanation theory. One new construct presented in this theory is the practice office's “IS audit emphasis”, which represents the practice office's emphasis upon the relationship between the IS auditor role and the audit team. The explanation theory provides a richer description of current audit practice regarding the IS auditor's role in public sector financial audit than currently exists. Consequently, this research provides insights for those involved in the education and training of auditors by developing a foundation for a more complete understanding of the IS auditor role.
Cyber resilience has emerged as a new discipline to help organisations deal with cyber problems that cannot be addressed by traditional cyber security solutions. This study analysed the scattered literature on organisational aspects of cyber resilience using Linkov et al.'s (2013a) framework for cyber resilience. Three approaches were identified among the studies. This research found that limited investigation into organisational cyber resilience has been undertaken, while organisational aspects of cyber resilience have received less attention when compared to technical topics. The findings challenge the passive assumption of cyber resilience that appears to underlie many of the publications, which followed a cyber security approach. The limited work found, gaps in research subtopics and the underlying assumptions of organisational cyber-resilience, all point to research opportunities for researchers.
Commentators frequently identify the harmonization of the financial reporting framework across international borders as essential to consistency and transparency in the financial reporting of global corporate entities (Roussey, 1992). Long considered desirable, the alignment of the major international financial reporting standards remained an unachievable dream in the eyes of many observers (Goeltz, 1991). The Mexican currency crisis of 1994 and then, particularly, the Asian crisis of 1997 (Humphrey et al., 2009) increased the prominence of the issue of the international harmonization of the financial reporting framework. In response, the international regulatory bodies set out International Standards on Auditing (ISA) and International Financial Reporting Standards (IFRS) as template standards to encourage international convergence of the financial reporting framework (Smith et al., 2008). Major developed economies have progressively and increasingly adopted these template standards (IFRS Foundation, 2011; International Federation of Accountants, 2011).
PurposeThe aim of this study is to investigate factors considered to impact on the research productivity of accounting academics, and identify how the factors were related. The study aims to set itself within an international context of increased workloads, and revenue‐driven research and teaching.Design/methodology/approachA meta‐analysis was conducted of international studies from accounting and related business fields, published between 1988 and 2008, that examined factors influencing the research productivity of academics. A data‐driven approach to thematic analysis was used to synthesise the results, which were categorised into two time periods.FindingsThree clusters of factors that accounted for researcher productivity were found to have had most focus in related studies over the period. These were “Institutional characteristics”, “Intrinsic motivation” and “Knowledge, skills and other individual characteristics”. Hierarchical clusters of factors operating at government, institution and individual levels appeared to influence the research output of accounting academics.Practical implicationsIncreased understanding of the factors that affect the research productivity of accounting academics, and how they are related, has potential to benefit individual researchers and their institutions.Originality/valueModels identified in previous studies have not considered the impact of the relatively recent global market pressures on accounting academics. As the proposed model was developed from a meta‐analysis of many international studies it is likely to accommodate current global pressures better than previous models.
Researchers have sought a theoretical perspective to explain the under-representation of women in the information technology (IT) workforce of many nations. Gender imbalance limits the size and skill sets of IT human resources. The essentialist theory, social construction theory and individual differences theory of gender and IT have been proposed to account for the IT gender gap. This study examined evidence for these theories to explain this gap through content analysis of articles published in the national newspaper, The Australian, over three time periods. Newspaper articles report implicit theoretical perspectives on IT and gender and influence the views of the Australian public, including women. While evidence to support all theories was found over the three periods, the essentialist theory was dominant. Increased utility of the individual differences theory to account for the IT gender gap was seen in 20072008. The primary contribution of this study is to provide evidence that suggests that theoretical approaches, whether implicit or explicit, shape how people understand the under-representation of women in the IT workforce. Media interventions are proposed to help redress the imbalance through increased awareness.
This article argues for an extension to the scope of corporate social responsibility (CSR) research to include a contemporary issue of importance to national and global security, critical infrastructure resilience. Rather than extending the multiple perspectives on CSR, this study aimed to identify a method of recognising CSR-related issues, before applying it to two dissimilar case studies on critical infrastructure resilience. One case study was of an international telecommunications company based in the US while the other was of the railway network in Britain during a period of privatisation. The method used was derived from Okoye’s (J Bus Ethics 89(4):613–627, 2009 ) common reference core for CSR. Both case studies satisfied all the criteria sought which points to critical infrastructure resilience as being an emerging CSR issue. Because ongoing change characterises CSR, the method may have application for identifying future new CSR strands. As the findings suggest that some aspects of national and global security are CSR-related phenomena, the study demonstrates how CSR research may be significant at a societal, national and global level. Implications of the study include a broadening of the value and reach of contributions from CSR researchers and practitioners.
There is a tension in the role of the IS auditor in public sector financial audits. Budgets for the conduct of such audits are tight. However, systems facilitating the production of financial reports are increasingly complex. How can IS audit be most effectively used to improve audit effectiveness and efficiency? Accordingly, this research reports the results of 23 extended interviews with public sector auditors from four public sector audit offices in contemplation of the IS audit function’s role in the public sector. Overall, the evidence supports the expectation that financial IS audit increasingly contributes to audit planning, is more involved when significant changes to existing IS are made or new IS are implemented, and increasingly utilizes sophisticated tools to support the financial audit. By contrast the evidence does not support the expectation that financial IS audit is increasingly involved in the implementation of continuous auditing and undertaking application control reviews. Training of future IS auditors should aim to ensure a strong understanding of IS audit’s role in the audit planning process. The results also imply that training for future IS auditors in environment and system general controls, and in sophisticated data mining and knowledge discovery tools, is crucial.
This chapter examines the potential to use an audit program based on the Control Objectives for Information and related Technologies (CobiT) framework for IT audit within a public sector audit office. It documents research that derives, implements and evaluates such a program with the cooperation of the public sector audit office in an Australian state. Additionally a comparison of the study results was undertaken with those of Guldentops, van Grembergen and de Haes (2002), Liu and Ridley (2005) and the European Organisation of Supreme Audit Institutions (EUROSAI) IT Working Group CobiT Selfassessment Project. The results suggest that the CobiT-derived instrument was effective for IT audit, and was able to be tailored to the needs of Tasmanian state public sector organization, when evaluated against a number of criteria.
This paper proposes a four-model framework for modelling the relationship between healthcare providers and healthcare users, and the associated acquisition of health information, modified from D'Alessandro and Dosa (2001) and Tomes (2007). Case studies were used to illuminate this investigation's research scope, rather than its research design, as is more usual. Using Keating's (1995) classification of case studies, this investigation presents four theory illustration cases, designed for theory refinement, seeking to establish the plausibility of the framework. The case study context used is the provision of healthcare to rural residents of Tasmania, the island state of Australia. This study found an occurrence of all four models from a search of the literature, which operated in parallel over similar time periods, within the case study setting. The findings were interpreted as supporting the plausibility of the framework. Further research will be needed to test the framework.
Information Technology control frameworks such as the Control Objectives for Information and Related Technology (COBIT) are designed to promote effective IT governance. This paper guides future scholarly evaluations of COBIT by identifying gaps in, and facilitating, research. It uses a framework to update a classification of the COBIT literature, by examining publications that report on how COBIT has been used in organisations. The findings from content analysis of extensive printed resources carried out on three occasions between 2003 and 2006 suggest that very few academically-focused evaluations of COBIT implementations have been undertaken, despite COBIT's extensive use in organisations throughout the world. Analysis points to growing acceptance of COBIT by both academics and practitioners, as well as a maturation in practitioner discussion of the framework. However, considerable potential exists for academic research that evaluates COBIT's effectiveness, to determine COBIT's value for organisations.
This paper is one of a set of two that report upon a meta-analysis of international studies from accounting and related business fields, published between 1988 and 2008, that examined factors influencing the research productivity of academics. In this current paper more than 70 factors were identified from 25 studies, which were then reduced to clusters of factors, or themes. A data-driven approach to thematic analysis was used to identify the factors and to allocate them to nine themes. The paper examines the relationships between the themes and proposes a model of how they are linked. The study suggests that three hierarchical clusters of factors at government, institution and individual levels influence the research output of accounting academics. These themes operate within a context with two others.
The study reported in this monograph aims to investigate the state of the information systems (IS) academic discipline in Australia from a historical and current perspective, collecting evidence across a range of dimensions. To maximise the strategic potential of the study, the results need to be capable of integration, so that the relationships within and across the dimensions and geographical units are understood. A meaningful theoretical framework will help relate the results of the different dimensions of the study to characterise the discipline in the region, and assist in empowering the Australian IS research community. This chapter reviewed literature on the development of disciplines, before deriving a theoretical framework for the broader study reported in this volume. The framework considered the current and past state of IS in Australian universities from the perspective of the development of a discipline. The components of the framework were derived and validated through a thematic analysis of the IS and non-IS literature. This chapter also presents brief vignettes of the development of two other related disciplines. The framework developed in this chapter, which has been guided partly by Whitley's theory of scientific change, has been used elsewhere to analyse data collated from the Australian states and the Australian Capital Territory. The degree of variation in Australian IS as an indication of its 'professionalisation', the nature of its body of knowledge and its mechanisms of control will be used to frame the analysis. Information systems is acknowledged as a discipline that is subject to frequent change. Pragmatism is used as an example to test the framework's capability of accommodating future changes in IS. Information systems scholars from three other world regions-North America, the United Kingdom and Scandinavia-have commented on the application of the framework to their own region. Research reported in the chapters and the meta-analysis that follow in this monograph have drawn on the theoretical framework presented below.