Cyber Security Audit in Information Technology Governance: A Literature Review and Future Research Agenda 520 1284
DOI:
https://doi.org/10.26623/transformatika.v23i2.12760Kata Kunci:
Audit Keamanan Siber, Tata Kelola Teknologi Informasi (ITG), Tinjauan Literatur Sistematis, Agenda Penelitian Masa Depan.Abstrak
This study aims to examine cyber security audits in information technology governance (ITG) more deeply using a literature review approach. The method used in this research is a systematic literature review by applying PRISMA (Preferred Reporting Items for Systematic reviews and Meta-Analysis) method approach with 25 years of observation from 1999 to 2024. 980 articles were obtained, nevertheless, only 36 articles were eligible. The research results show that cyber security audit is compatible and closely related to information technology governance (ITG), mainly the domain regarding the need for the board of directors to understand and to master cyber security audit skills to overcome violations and data leaks in IT governance. Cyber security audit and information technology governance (ITG) are two key components to maintain information security as well as to manage information technology effectively. Integration between the two in a conceptual framework helps organizations identify, manage and mitigate cyber risks and maintain alignment with business objectives.
Unduhan
Referensi
[1] A. A. Ganie and S. Devi, Emerging cyber threats in the digital age: trends and challenges, Int. Res. J. Mod. Eng. Technol. Sci., vol. 05, no. 03, pp. 2542–2546, 2023, [Online]. Available: www.irjmets.com
[2]A. Calder and S. Watkins, IT Governance: An international guide to data security and ISO27001/ISO27002, 6th ed. London Philadelphia New Delhi: Kogan Page Limited, 2015.
[3] K. D. Jadhav, The Role of cyber security audits in managing company systems and aplications, Exp. Find., no. January, pp. 1–7, 2023, [Online]. Available: https://www.researchgate.net/publication/367559332_THE_ROLE_OF_CYBER_SECURITY_AUDITS
[4] S. Slapničar, T. Vuko, M. Čular, and M. Drašček, Effectiveness of cybersecurity audit, Int. J. Account. Inf. Syst., vol. 44, no. January 2021, pp. 1–21, 2022, doi: 10.1016/j.accinf.2021.100548.
[5] N. I. Jaafar and E. Jordan, Information Technology Governance (ITG) practices and accountability of Information Technology (IT) projects - A case study in a Malaysian Government-Linked Company (GLC), in PACIS 2009 - 13th Pacific Asia Conference on Information Systems: IT Services in a Global Environment, 2009, pp. 1–15.
[6] K. Al-Dosari and N. Fetais, Risk-management framework and information-security systems for Small and Medium Enterprises (SMEs): A Meta-analysis approach, Electron., vol. 12, no. 17, 2023, doi: 10.3390/electronics12173629.
[7] E. Haapamäki and J. Sihvonen, Cybersecurity in accounting research, Manag. Audit. J., vol. 34, no. 7, pp. 808–834, 2019, doi: 10.1108/MAJ-09-2018-2004.
[8] M. Antunes, M. Maximiano, and R. Gomes, A Client-centered information security and cybersecurity auditing framework, Appl. Sci., vol. 12, no. 9, 2022, doi: 10.3390/app12094102.
[9] M. Antunes, M. Maximiano, and R. Gomes, A customizable web platform to manage standards compliance of information security and cybersecurity auditing, in Procedia Computer Science, 2021, vol. 196, pp. 36–43. doi: 10.1016/j.procs.2021.11.070.
[10] B. Azinheira, M. Antunes, M. Maximiano, and R. Gomes, A methodology for mapping cybersecurity standards into governance guidelines for SME in Portugal, Procedia Comput. Sci., vol. 219, no. 2021, pp. 121–128, 2023, doi: 10.1016/j.procs.2023.01.272.
[11] S. Slapničar, T. Vuko, M. Cular, and M. Drascek, Effectiveness of cybersecurity audit, Int. J. Account. Inf. Syst., vol. 44, no. 100548, pp. 1–21, 2022.
[12] J. Bouwens, Auditors: their mindset and their decisions, Maandbl. Voor Account. en Bedrijfsecon., vol. 90, no. 10, pp. 385–390, 2016, doi: 10.5117/mab.90.31181.
[13] G. Hardy, X Coordinating IT governance-A new role for the IT strategy committee, Inf. Syst. Control J., vol. 4, pp. 1–5, 2003.
[14] P. Best and S. Buckby, Development of a board IT governance (ITG) review model, in Accounting & Finance Association of Australia and New Zealand Conference (AFAANZ 2007), 2007, no. March, pp. 1–16. [Online]. Available: http://eprints.usq.edu.au/6031/
[15] S. Buckby, P. Best, and J. Stewart, The Role of boards in reviewing Information Technology Governance (ITG) as part of organizational control environment assessments, in Proceedings 2005 IT Governance International Conference, 2005, pp. 1–15.
[16]G. J. Selig, Implementing IT Governance: A practical guide to global best practices in IT Management, 1st ed., no. December. 2008. [Online]. Available: https://books.google.es/books?hl=es&lr=&id=rdVEBAAAQBAJ&oi=fnd&pg=PR5&dq=implementing+it+governance+a+practical+guide+to+global+best+practices+in+it+management&ots=K_vhQQNhEl&sig=mw7_EdcxzSK4PHH4pfKv1xa7DGE
[17] S. Slapničar, M. Axelsen, I. Bongiovanni, and D. Stockdale, A pathway model to five lines of accountability in cybersecurity governance, Int. J. Account. Inf. Syst., vol. 51, no. August, 2023, doi: 10.1016/j.accinf.2023.100642.
[18] G. Lame, Systematic literature reviews: An introduction, in Proceedings of the International Conference on Engineering Design, ICED, 2019, no. July, pp. 1633–1642. doi: 10.1017/dsi.2019.169.
[19] R. Handayani, E. Utami, and E. T. Luthfi, Systematic literature review on auditing information technology risk management using the COBIT framework, Prism. Sains, vol. 11, no. 4, pp. 1028–1036, 2023, doi: 10.33394/j-ps.v11i4.8871.
[20] A. Trifu, E. Smîdu, D. O. Badea, E. Bulboacă, and V. Haralambie, Applying the PRISMA method for obtaining systematic reviews of occupational safety issues in literature search, in MATEC Web of Conferences, 2022, vol. 354, p. 00052. doi: 10.1051/matecconf/202235400052.
[21] S. Simamora, Systematic literature review with the prisma method: the impact of blockchain technology on digital advertising, M-Progress, vol. 14, no. 1, 2024, doi: 10.35968/m-pu.v14i1.1182.
[22] M. J. Page et al., The PRISMA 2020 statement: An updated guideline for reporting systematic reviews, BMJ, vol. 372, no. n71, pp. 1–9, 2021, doi: 10.1136/bmj.n71.
[23] A. Liberati et al., The PRISMA statement for reporting systematic reviews and meta-analyses of studies that evaluate health care interventions: Explanation and elaboration, PLoS Med., vol. 6, no. 7, pp. 1–28, 2009, doi: 10.1371/journal.pmed.1000100.
[24] I. A. Moosa, Publish or perish: Origin and perceived benefits, in Publish or Perish, 2018, pp. 1–17. doi: 10.4337/9781786434937.00007.
[25] J. Gabrielsson, Corporate governance and entrepreneurship : current states and future directions, in Handbook of Research on Corporate Governance and Entrepreneurship, 2017, pp. 1–25.
[26] D. F. Al Husaeni and A. B. D. Nandiyanto, Bibliometric using Vosviewer with Publish or Perish (using Google Scholar data): from step-by-step processing for users to the practical examples in the analysis of digital learning articles in pre and post Covid-19 pandemic, ASEAN J. Sci. Eng., vol. 2, no. 1, pp. 19–46, 2022, doi: 10.17509/ajse.v2i1.37368.
[27] P. L. Bowen, M. Y. D. Cheung, and F. H. Rohde, Enhancing IT governance practices: A model and case study of an organization’s efforts, Int. J. Account. Inf. Syst., vol. 8, no. 3, pp. 191–221, 2007, doi: 10.1016/j.accinf.2007.07.002.
[28] P. J. Steinbart, R. L. Raschke, G. Gal, and W. N. Dilla, The relationship between internal audit and information security: An exploratory investigation, Int. J. Account. Inf. Syst., vol. 13, no. 3, pp. 228–243, 2012, doi: 10.1016/j.accinf.2012.06.007.
[29] P. J. Steinbart, R. L. Raschke, G. Gal, and W. N. Dilla, Information Security Professionals’ Perceptions about the Relationship between the Information Security and Internal Audit Functions, J. Inf. Syst., vol. 27, no. 2, pp. 65–86, 2013.
[30] B. Kuerbis and F. Badiei, Mapping the cybersecurity institutional landscape, Digit. Policy, Regul. Gov. , vol. 19, no. 6, pp. 466–492, 2017, doi: 10.1108/DPRG-05-2017-0024.
[31] T. Stafford and S. Islam, Information technology (it) integration and cybersecurity/security: The security savviness of board of directors, in AMCIS 2017 - America’s Conference on Information Systems: A Tradition of Innovation, 2017, vol. 2017-Augus, pp. 1–5.
[32] M. van Eeten, Patching security governance: an empirical view of emergent governance mechanisms for cybersecurity, Digit. Policy, Regul. Gov. , vol. 19, no. 6, pp. 429–448, 2017, doi: 10.1108/DPRG-05-2017-0029.
[33] E. Amir, S. Levi, and T. Livne, Do firms underreport information on cyber-attacks? Evidence from capital markets, Rev. Account. Stud., vol. 23, no. 3, pp. 1177–1206, 2018, doi: 10.1007/s11142-018-9452-4.
[34] S. Bozkus Kahyaoglu and K. Caliyurt, Cyber security assurance process from the internal audit perspective, Manag. Audit. J., vol. 33, no. 4, pp. 360–376, 2018, doi: 10.1108/MAJ-02-2018-1804.
[35] M. S. Islam, N. Farah, and T. F. Stafford, Factors associated with security/cybersecurity audit by internal audit function: An international study, Manag. Audit. J., vol. 33, no. 4, pp. 377–409, 2018, doi: 10.1108/MAJ-07-2017-1595.
[36] T. Stafford, G. Deitz, and Y. Li, The role of internal audit and user training in information security policy compliance, Manag. Audit. J., vol. 33, no. 4, pp. 410–424, 2018, doi: 10.1108/MAJ-07-2017-1596.
[37] P. J. Steinbart, R. L. Raschke, G. Gal, and W. N. Dilla, The influence of a good relationship between the internal audit and information security functions on information security outcomes, Accounting, Organ. Soc., vol. 71, pp. 15–29, 2018, doi: 10.1016/j.aos.2018.04.005.
[38] B. von Solms and R. von Solms, Cybersecurity and information security – what goes where?, Inf. Comput. Secur., vol. 26, no. 1, pp. 2–9, 2018, doi: 10.1108/ICS-04-2017-0025.
[39] F. Caron, Obtaining reasonable assurance on cyber resilience, Manag. Audit. J., vol. 36, no. 2, pp. 193–217, 2019, doi: 10.1108/MAJ-11-2017-1690.
[40] T. J. Smith, J. L. Higgs, and R. E. Pinsker, Do auditors price breach risk in their audit fees?, J. Inf. Syst., vol. 33, no. 2, pp. 177–204, 2019, doi: 10.2308/isys-52241.
[41] A. M. A. M. Al-Sartawi, Information technology governance and cybersecurity at the board level, Int. J. Crit. Infrastructures, vol. 16, no. 2, pp. 150–161, 2020, doi: 10.1504/ijcis.2020.10029173.
[42] H. Li, W. G. No, and J. Efrim Boritz, Are external auditors concerned about cyber incidents? Evidence from audit fees, Audit. A J. Pract. Theory, vol. 39, no. 1, pp. 151–171, 2020, doi: 10.2308/ajpt-52593.
[43] C. C. Hartmann and J. Carmenate, Academic research on the role of corporate governance and it expertise in addressing cybersecurity breaches: Implications for practice, policy, and research, Curr. Issues Audit., vol. 15, no. 2, pp. A9–A23, 2021, doi: 10.2308/CIIA-2020-034.
[44] T. Vuko, S. Slapničar, M. Čular, and M. Drašček, Key drivers of cybersecurity audit effectiveness: the neo-institutional perspective, SSRN Electron. J., no. October, 2021, doi: 10.2139/ssrn.3932177.
[45] S. Héroux and A. Fortin, Board of directors’ attributes and aspects of cybersecurity disclosure, J. Manag. Gov., no. 0123456789, p. 10997, 2022, doi: 10.1007/s10997-022-09660-7.
[46] M. Malatji, A. L. Marnewick, and S. Von Solms, Cybersecurity capabilities for critical infrastructure resilience, Inf. Comput. Secur., vol. 30, no. 2, pp. 255–279, 2022, doi: 10.1108/ICS-06-2021-0091.
[47] C. Medoh and A. Telukdarie, The Future of Cybersecurity: A System Dynamics Approach, Procedia Comput. Sci., vol. 200, no. 2019, pp. 318–326, 2022, doi: 10.1016/j.procs.2022.01.230.
[48] R. Villalón-Fonseca, The nature of security: A conceptual framework for integral-comprehensive modeling of IT security and cybersecurity, Comput. Secur., vol. 120, pp. 1–22, 2022, doi: 10.1016/j.cose.2022.102805.
[49] A. Fortin and S. Héroux, Limited usefulness of firm-provided cybersecurity information in institutional investors’ investment analysis, Inf. Comput. Secur., vol. 31, no. 1, pp. 108–123, 2023, doi: 10.1108/ICS-07-2022-0122.
[50] H. M. Melaku, A Dynamic and Adaptive Cybersecurity Governance Framework, J. Cybersecurity Priv., vol. 3, no. 3, pp. 327–350, 2023, doi: 10.3390/jcp3030017.
[51] S. Saeed, S. A. Suayyid, M. S. Al-Ghamdi, H. Al-Muhaisen, and A. M. Almuhaideb, A Systematic Literature Review on Cyber Threat Intelligence for Organizational Cybersecurity Resilience, Sensors, vol. 23, no. 7273, pp. 1–27, 2023, doi: 10.3390/s23167273.
[52] K. Shaheen and A. H. Zolait, The impacts of the cyber-trust program on the cybersecurity maturity of government entities in the Kingdom of Bahrain, Inf. Comput. Secur., vol. 31, no. 5, pp. 529–544, 2023, doi: 10.1108/ICS-06-2022-0108.
[53] N. Smaili, C. Radu, and A. Khalili, Board effectiveness and cybersecurity disclosure, J. Manag. Gov., vol. 27, no. 4, pp. 1049–1071, 2023, doi: 10.1007/s10997-022-09637-6.
[54] U. Tariq, I. Ahmed, A. K. Bashir, and K. Shaukat, A Critical Cybersecurity Analysis and Future Research Directions for the Internet of Things: A Comprehensive Review, Sensors, vol. 23, no. 4117, pp. 1–46, 2023, doi: 10.1080/19361610.2021.1962677.
[55] A. Yeboah-Ofori and F. A. Opoku-Boateng, Mitigating cybercrimes in an evolving organizational landscape, Contin. Resil. Rev., vol. 5, no. 1, pp. 53–78, 2023, doi: 10.1108/crr-09-2022-0017.
[56] S. Héroux and A. Fortin, How the three lines of defense can contribute to public firms’ cybersecurity effectiveness, Int. J. Discl. Gov., p. 2, 2024, doi: 10.1057/s41310-024-00226-7.
[57] W. Jiang, Cybersecurity Risk and Audit Pricing—A Machine Learning-Based Analysis, J. Inf. Syst., vol. 38, no. 1, pp. 91–117, 2024, doi: 10.2308/ISYS-2023-019.
[58] H. Li, Z. Sun, and F. Huang, The Impact of Audit Office Cybersecurity Experience on Nonbreach Client’s Audit Fees and Cybersecurity Risks, J. Inf. Syst., vol. 38, no. 1, pp. 177–206, 2024, doi: 10.2308/ISYS-2023-014.
Unduhan
Diterbitkan
Terbitan
Bagian
Lisensi
Hak Cipta (c) 2026 Saifudin Saifudin, Nazri Sidqi Fachriaz

Artikel ini berlisensi Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.

Transformatika is licensed under a Creative Commons Attribution 4.0 International License.



