International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1713225

1713225 Vol 3 · Issue 5 Download Paper

Security Audit and Enterprise Risk Assessment Frameworks for Resilient Information Systems

Adetomiwa A. Dosunmu Peter Olusoji Ogundele

Subject area: Science,Engineering and Technology  ·  Area of research: Risk Assessment Framework

Abstract

The increasing dependence of organisations on complex, interconnected information systems has heightened exposure to cyber threats, operational disruptions, and systemic vulnerabilities. Security breaches, data loss incidents, service outages, and compliance failures have demonstrated that traditional, compliance-oriented security controls are insufficient for ensuring long-term information system resilience. Consequently, security auditing and enterprise risk assessment have evolved from isolated assurance activities into strategic governance mechanisms aimed at strengthening organisational resilience. This paper presents a comprehensive synthesis of security audit and enterprise risk assessment frameworks relevant to resilient information systems, drawing exclusively on literature published. The study reviews foundational audit models, risk assessment methodologies, governance standards, and resilience-oriented security paradigms, highlighting their strengths, limitations, and areas of convergence. By integrating insights from information systems security, risk management, internal control, and organisational resilience research, the paper develops a structured perspective on how security audits and enterprise risk assessments can be aligned to support robust, adaptive, and trustworthy information systems. The findings contribute to both academic and practitioner discourse by clarifying the role of assurance and risk assessment in achieving sustained information system resilience.

Keywords

Information Systems Security; Security Audit; Enterprise Risk Assessment; Cyber Resilience; Risk Governance; Information Assurance

References

[1] [1]E. N. Kamau, “Energy efficiency comparison between 2.1 GHz and 28 GHz based communication networks,” 2018.

[2] [2]T. T. Bukhari, O. Oladimeji, and E. D. Etim, “A Conceptual Framework for Designing Resilient Multi Cloud Networks Ensuring Security, Scalability, and Reliability Across Infrastructures,” IRE Journals, vol. 1, no. 8, 2018.

[3] [3]S. Shafqat, S. Kishwer, R. U. Rasool, J. Qadir, T. Amjad, and H. F. Ahmad, “Big data analytics enhanced healthcare systems: a review,” The Journal of Supercomputing 2018 76:3, vol. 76, no. 3, pp. 1754–1799, Feb. 2018, doi: 10.1007/S11227-017-2222-4.

[4] [4]N. T. Sheehan, “A risk-based approach to strategy execution,” Journal of Business Strategy, vol. 31, no. 5, pp. 25–37, 2010, doi: 10.1108/02756661011076291.

[5] [5]N. H. Z. Abidin, “Factors influencing the implementation of risk-based auditing,” Asian Review of Accounting, vol. 25, no. 3, pp. 361–375, 2017, doi: 10.1108/ARA-10-2016-0118.

[6] [6]N. Castanheira, L. L. Rodrigues, and R. Craig, “Factors associated with the adoption of risk-based internal auditing,” Managerial Auditing Journal, vol. 25, no. 1, pp. 79–98, Jan. 2010, doi: 10.1108/02686901011007315.

[7] [7]P. Coetzee and D. Lubbe, “Improving the efficiency and effectiveness of risk-based internal audit engagements,” International Journal of Auditing, vol. 18, no. 2, pp. 115–125, 2014, doi: 10.1111/IJAU.12016.

[8] [8]L. Edwards, “Privacy, Security and Data Protection in Smart Cities:,” European Data Protection Law Review, vol. 2, no. 1, pp. 28–58, Feb. 2017, doi: 10.21552/EDPL/2016/1/6.

[9] [9]Y. P. Chen et al., “An agile enterprise regulation architecture for health information security management,” Telemedicine and e-Health, vol. 16, no. 7, pp. 807–817, Sep. 2010, doi: 10.1089/TMJ.2010.0023.

[10] [10]G. Sarens, I. De Beelde, and P. Everaert, “Internal audit: A comfort provider to the audit committee,” British Accounting Review, vol. 41, no. 2, pp. 90–106, Jun. 2009, doi: 10.1016/J.BAR.2009.02.002.

[11] [11]K. A. Endaya and M. M. Hanefah, “Internal auditor characteristics, internal audit effectiveness, and moderating effect of senior management,” Journal of Economic and Administrative Sciences, vol. 32, no. 2, pp. 160–176, 2016, doi: 10.1108/JEAS-07-2015-0023.

[12] [12]L. de Zwaan, J. Stewart, and N. Subramaniam, “Internal audit involvement in enterprise risk management,” Managerial Auditing Journal, vol. 26, no. 7, pp. 586–604, Jul. 2011, doi: 10.1108/02686901111151323.

[13] [13]R. Lenz, G. Sarens, and F. Hoos, “Internal Audit Effectiveness: Multiple Case Study Research Involving Chief Audit Executives and Senior Management,” EDPACS, vol. 55, no. 1, pp. 1–17, Jan. 2017, doi: 10.1080/07366981.2017.1278980.

[14] [14]M. Arena and G. Azzone, “Identifying Organizational Drivers of Internal Audit Effectiveness,” International Journal of Auditing, vol. 13, no. 1, pp. 43–60, Mar. 2009, doi: 10.1111/J.1099-1123.2008.00392.X.

[15] [15]M. K. Power, “Auditing and the production of legitimacy,” Account Organ Soc, vol. 28, no. 4, pp. 379–94, 2003, doi: 10.1016/s0361-3682(01)00047-2.

[16] [16]A. Fernández-Laviada, “Internal audit function role in operational risk management,” Journal of Financial Regulation and Compliance, vol. 15, no. 2, pp. 143–155, 2007, doi: 10.1108/13581980710744039.

[17] [17]M. Allegrini and G. D’Onza, “Internal Auditing and Risk Assessment in Large Italian Companies: an Empirical Survey,” International Journal of Auditing, vol. 7, no. 3, pp. 191–208, Nov. 2003, doi: 10.1046/J.1099-1123.2003.00070.X.

[18] [18]R. Lenz and U. Hahn, “A synthesis of empirical internal audit effectiveness literature pointing to new research opportunities,” Managerial Auditing Journal, vol. 30, no. 1, pp. 5–33, Jan. 2015, doi: 10.1108/MAJ-08-2014-1072.

[19] [19]“Supply Chain Modelling of the Automobile Multi-Stage Production Considering Circular Economy by Waste Management Using Recycling and Reworking Operations.” Accessed: Dec. 09, 2018. [Online]. Available: https://www.mdpi.com/2071-1050/14/22/15428

[20] [20]E. G. Birgin, G. Haeser, and A. Ramos, “Augmented lagrangians with constrained subproblems and convergence to second-order stationary points,” Comput Optim Appl, vol. 69, no. 1, pp. 51–75, Jan. 2018, doi: 10.1007/S10589-017-9937-2.

[21] [21]K. Schittkowski, “NLPQL: A fortran subroutine solving constrained nonlinear programming problems,” Ann Oper Res, vol. 5, no. 1–4, pp. 485–500, May 1986, doi: 10.1007/BF02739235.

[22] [22]M. Omair, B. Sarkar, and L. E. Cárdenas-Barrón, “Minimum quantity lubrication and carbon footprint: A step towards sustainability,” Sustainability (Switzerland), vol. 9, no. 5, 2017, doi: 10.3390/SU9050714.

[23] [23]B. Sarkar, L. E. Cárdenas-Barrón, M. Sarkar, and M. L. Singgih, “An economic production quantity model with random defective rate, rework process and backorders for a single stage production system,” J Manuf Syst, vol. 33, no. 3, pp. 423–435, 2014, doi: 10.1016/J.JMSY.2014.02.001.

[24] [24]B. Sarkar, “Supply Chain Coordination with Variable Backorder, Inspections, and Discount Policy for Fixed Lifetime Products,” Math Probl Eng, vol. 2016, 2016, doi: 10.1155/2016/6318737.

[25] [25]M. L. Longana, N. Ong, H. N. Yu, and K. D. Potter, “Multiple closed loop recycling of carbon fibre composites with the HiPerDiF (High Performance Discontinuous Fibre) method,” Compos Struct, vol. 153, pp. 271–277, Oct. 2016, doi: 10.1016/J.COMPSTRUCT.2016.06.018.

[26] [26]Q. Tan, X. Zeng, W. L. Ijomah, L. Zheng, and J. Li, “Status of end-of-life electronic product remanufacturing in China,” J Ind Ecol, vol. 18, no. 4, pp. 577–587, 2014, doi: 10.1111/JIEC.12124.

[27] [27]G. A. Keoleian and J. L. Sullivan, “Materials challenges and opportunities for enhancing the sustainability of automobiles,” MRS Bull, vol. 37, no. 4, pp. 365–372, Apr. 2012, doi: 10.1557/MRS.2012.52.

[28] [28]A. Elgowainy et al., “Current and Future United States Light-Duty Vehicle Pathways: Cradle-to-Grave Lifecycle Greenhouse Gas Emissions and Economic Assessment,” Environ Sci Technol, vol. 52, no. 4, pp. 2392–2399, Feb. 2018, doi: 10.1021/ACS.EST.7B06006.

[29] [29]J. Östlin, E. Sundin, and M. Björkman, “Product life-cycle implications for remanufacturing strategies,” J Clean Prod, vol. 17, no. 11, pp. 999–1009, Jul. 2009, doi: 10.1016/J.JCLEPRO.2009.02.021.

[30] [30]M. Thierry, M. Salomon, J. van Nunen, and L. van Wassenhove, “Strategic Issues in Product Recovery Management,” Calif Manage Rev, vol. 37, no. 2, pp. 114–135, 1995, doi: 10.2307/41165792.

[31] [31]J. H. Barnes, “Recycling: A Problem in Reverse Logistics,” Journal of Macromarketing, vol. 2, no. 2, pp. 31–37, 1982, doi: 10.1177/027614678200200204.

[32] [32]V. V. Agrawal, A. Atasu, and K. Van Ittersum, “Remanufacturing, third-party competition, and consumers’ perceived value of new products,” Manage Sci, vol. 61, no. 1, pp. 60–72, Jan. 2015, doi: 10.1287/MNSC.2014.2099.

[33] [33]M. Bicket and R. Vanner, “Designing policy mixes for resource efficiency: The role of public acceptability,” Sustainability (Switzerland), vol. 8, no. 4, 2016, doi: 10.3390/SU8040366.

[34] [34]C. Dobbs, F. J. Escobedo, and W. C. Zipperer, “A framework for developing urban forest ecosystem services and goods indicators,” Landsc Urban Plan, vol. 99, no. 3–4, pp. 196–206, Mar. 2011, doi: 10.1016/J.LANDURBPLAN.2010.11.004.

[35] [35]R. Aydin, C. K. Kwong, M. W. Geda, and G. E. Okudan Kremer, “Determining the optimal quantity and quality levels of used product returns for remanufacturing under multi-period and uncertain quality of returns,” International Journal of Advanced Manufacturing Technology, vol. 94, no. 9–12, pp. 4401–4414, Feb. 2018, doi: 10.1007/S00170-017-1141-0.

[36] [36]T. Aljuneidi and A. A. Bulgak, “A mathematical model for designing reconfigurable cellular hybrid manufacturing-remanufacturing systems,” International Journal of Advanced Manufacturing Technology, vol. 87, no. 5–8, pp. 1585–1596, Nov. 2016, doi: 10.1007/S00170-016-9141-Z.

[37] [37]T. Wang, K. N. Kannan, and J. R. Ulmer, “The association between the disclosure and the realization of information security risk factors,” Information Systems Research, vol. 24, no. 2, pp. 201–218, 2013, doi: 10.1287/ISRE.1120.0437.

[38] [38]A. Dorri, S. S. Kanhere, R. Jurdak, and P. Gauravaram, “Blockchain for IoT security and privacy: The case study of a smart home,” 2017 IEEE International Conference on Pervasive Computing and Communications Workshops, PerCom Workshops 2017, pp. 618–623, May 2017, doi: 10.1109/PERCOMW.2017.7917634.

[39] [39]L. Curren and J. Kaye, “Revoking consent: A ‘blind spot’ in data protection law?,” Computer Law and Security Review, vol. 26, no. 3, pp. 273–283, May 2010, doi: 10.1016/J.CLSR.2010.03.001.

[40] [40]P. De Hert and V. Papakonstantinou, “The new General Data Protection Regulation: Still a sound system for the protection of individuals?,” Computer Law and Security Review, vol. 32, no. 2, pp. 179–194, Apr. 2016, doi: 10.1016/J.CLSR.2016.02.006.

[41] [41]S. Spiekermann and A. Novotny, “A vision for global privacy bridges: Technical and legal measures for international data markets,” Computer Law and Security Review, vol. 31, no. 2, pp. 181–200, Apr. 2015, doi: 10.1016/J.CLSR.2015.01.009.

[42] [42]A. Mantelero, “The EU Proposal for a General Data Protection Regulation and the roots of the right to be forgotten,” Computer Law and Security Review, vol. 29, no. 3, pp. 229–235, Jun. 2013, doi: 10.1016/J.CLSR.2013.03.010.

[43] [43]C. Bartolini and L. Siry, “The right to be forgotten in the light of the consent of the data subject,” Computer Law and Security Review, vol. 32, no. 2, pp. 218–237, Apr. 2016, doi: 10.1016/J.CLSR.2016.01.005.

[44] [44]A. A. Cain, M. E. Edwards, and J. D. Still, “An exploratory study of cyber hygiene behaviors and knowledge,” Journal of Information Security and Applications, vol. 42, pp. 36–45, Oct. 2018, doi: 10.1016/J.JISA.2018.08.002.

[45] [45]G. Prause, “Sustainable business models and structures for industry 4.0,” Journal of Security and Sustainability Issues, vol. 5, no. 2, pp. 159–169, 2015, doi: 10.9770/JSSI.2015.5.2(3).

[46] [46]Y. Zhang and B. Li, “A Novel Software Defined Networking Framework for Cloud Environments,” Proceedings - 3rd IEEE International Conference on Cyber Security and Cloud Computing, CSCloud 2016 and 2nd IEEE International Conference of Scalable and Smart Cloud, SSC 2016, pp. 30–35, Aug. 2016, doi: 10.1109/CSCLOUD.2016.22.

[47] [47]M. Bar-Sinai, L. Sweeney, and M. Crosas, “DataTags, Data Handling Policy Spaces and the Tags Language,” Proceedings - 2016 IEEE Symposium on Security and Privacy Workshops, SPW 2016, pp. 1–8, Aug. 2016, doi: 10.1109/SPW.2016.11.

[48] [48]M. J. Nigrini, “Benford’s law: Applications for forensic accounting, auditing, and fraud detection,” Benford’s Law: Applications for Forensic Accounting, Auditing, and Fraud Detection, pp. 1–330, Jan. 2012, doi: 10.1002/9781119203094.

[49] [49]J. Cohen, G. Krishnamoorthy, and A. Wright, “Corporate governance in the post-Sarbanes-Oxley era: Auditors’ experiences,” Contemporary Accounting Research, vol. 27, no. 3, pp. 751–786, Sep. 2010, doi: 10.1111/J.1911-3846.2010.01026.X;WEBSITE:WEBSITE:PERICLES;JOURNAL:JOURNAL:19113846;WGROUP:STRING:PUBLICATION.

[50] [50]E. A. Gordon, E. Henry, T. J. Louwers, and B. J. Reed, “Auditing Related Party Transactions: A Literature Overview and Research Synthesis,” Accounting Horizons, vol. 21, no. 1, pp. 81–102, Mar. 2007, doi: 10.2308/ACCH.2007.21.1.81.

[51] [51]M. El-Helaly, “Related-party transactions: a review of the regulation, governance and auditing literature,” Managerial Auditing Journal, vol. 33, no. 8–9, pp. 779–806, Nov. 2018, doi: 10.1108/MAJ-07-2017-1602.

[52] [52]A. Alzeban and D. Gwilliam, “Factors affecting the internal audit effectiveness: A survey of the Saudi public sector,” Journal of International Accounting, Auditing and Taxation, vol. 23, no. 2, pp. 74–86, 2014, doi: 10.1016/J.INTACCAUDTAX.2014.06.001.

[53] [53]F. Kabuye, S. K. Nkundabanyanga, J. Opiso, and Z. Nakabuye, “Internal audit organisational status, competencies, activities and fraud management in the financial services sector,” Managerial Auditing Journal, vol. 32, no. 9, pp. 924–944, Nov. 2017, doi: 10.1108/MAJ-09-2016-1452.

[54] [54]G. Sarens, M. J. Abdolmohammadi, and R. Lenz, “Factors associated with the internal audit function’s role in corporate governance,” Journal of Applied Accounting Research, vol. 13, no. 2, pp. 191–204, 2012, doi: 10.1108/09675421211254876.

[55] [55]A. A. M. Al-Twaijry, J. A. Brierley, and D. R. Gwilliam, “The development of internal audit in Saudi Arabia: An institutional theory perspective,” Critical Perspectives on Accounting, vol. 14, no. 5, pp. 507–531, 2003, doi: 10.1016/S1045-2354(02)00158-2.

[56] [56]N. Wilkinson and P. Coetzee, “Internal audit assurance or consulting services rendered on governance: How does one decide?,” Journal of Governance and Regulation, vol. 4, no. 1, pp. 186–200, 2015, doi: 10.22495/JGR_V4_I1_C2_P3.

[57] [57]K. Singh, P. J. Best, M. Bojilov, and C. Blunt, “Continuous Auditing and Continuous Monitoring in ERP Environments: Case Studies of Application Implementations,” Journal of Information Systems, vol. 28, no. 1, pp. 287–310, Jun. 2014, doi: 10.2308/ISYS-50679.

[58] [58]M. Abdullatif and S. Kawuq, “The role of internal auditing in risk management: evidence from banks in Jordan,” Journal of Economic and Administrative Sciences, vol. 31, no. 1, pp. 30–50, 2015, doi: 10.1108/JEAS-08-2013-0025.

[59] [59]E. Burrell Nickell and R. W. Roberts, “Organizational legitimacy, conflict, and hypocrisy: An alternative view of the role of internal auditing,” Critical Perspectives on Accounting, vol. 25, no. 3, pp. 217–221, 2014, doi: 10.1016/J.CPA.2013.10.005.

[60] [60]M. Å. Hugoson, “Centralized versus Decentralized Information Systems: A Historical Flashback,” IFIP Adv Inf Commun Technol, vol. 303, pp. 106–115, 2008, doi: 10.1007/978-3-642-03757-3_11.

[61] [61]J. M. Gesulga, A. Berjame, K. S. Moquiala, and A. Galido, “Barriers to Electronic Health Record System Implementation and Information Systems Resources: A Structured Review,” Procedia Comput Sci, vol. 124, pp. 544–551, 2017, doi: 10.1016/J.PROCS.2017.12.188.

[62] [62]J. Gesulga, A. Berjame, K. Moquiala, and A. Galido, “Barriers to Electronic Health Record System Implementation and Information Systems Resources: A Structured Review,” Procedia Comput Sci, vol. 124, 2017.

[63] [63]J. Gomes and M. Romão, “Information System Maturity Models in Healthcare,” J Med Syst, vol. 42, no. 12, pp. 1–14, Dec. 2018, doi: 10.1007/S10916-018-1097-0/TABLES/4.

[64] [64]P. W. Handayani et al., “Integrated hospital information system architecture design in Indonesia,” Maximizing Healthcare Delivery and Management through Technology Integration, pp. 207–236, Sep. 2015, doi: 10.4018/978-1-4666-9446-0.CH013.

[65] [65]C. Moucheraud et al., “Sustainability of health information systems: A three-country qualitative study in southern Africa,” BMC Health Serv Res, vol. 17, no. 1, Jan. 2017, doi: 10.1186/S12913-016-1971-8.

[66] [66]P. Besson and F. Rowe, “Strategizing information systems-enabled organizational transformation: A transdisciplinary review and new directions,” Journal of Strategic Information Systems, vol. 21, no. 2, pp. 103–124, 2012, doi: 10.1016/J.JSIS.2012.05.001.

[67] [67]S. Madon, S. Krishna, and E. Michael, “Health information systems, decentralisation and democratic accountability,” Public Administration and Development, vol. 30, no. 4, pp. 247–260, Oct. 2010, doi: 10.1002/PAD.571.

[68] [68]H. Haberleitner, H. Meyr, and A. Taudes, “Implementation of a demand planning system using advance order information,” Int J Prod Econ, vol. 128, no. 2, pp. 518–526, Dec. 2010, doi: 10.1016/j.ijpe.2010.07.003.

[69] [69]F. M. Behlen, R. E. Sayre, J. B. Weldy, and J. S. Michael, “`Permanent’ records: Experience with data migration in radiology information system and picture archiving and communication system replacement,” J Digit Imaging, vol. 13, no. 2 SUPPL. 1, pp. 171–174, 2000, doi: 10.1007/BF03167653.

[70] [70]H. Liu, “The research of information disseminating system management in new media age,” Lecture Notes in Electrical Engineering, vol. 241 LNEE, no. VOL. 1, pp. 249–258, 2014, doi: 10.1007/978-3-642-40078-0_21.

[71] [71]H. C. Kimaro, “Strategies for Developing Human Resource Capacity to Support Sustainability of ICT Based Health Information Systems: A Case Study from Tanzania,” Electronic Journal of Information Systems in Developing Countries, vol. 26, no. 1, pp. 1–23, Aug. 2006, doi: 10.1002/J.1681-4835.2006.TB00171.X.

[72] [72]P. L. Reichertz, “Hospital information systems - Past, present, future,” Int J Med Inform, vol. 75, no. 3-4 SPEC. ISS., pp. 282–299, Mar. 2006, doi: 10.1016/J.IJMEDINF.2005.10.001.

[73] [73]M. Smith, S. Madon, A. Anifalaje, M. Lazarro-Malecela, and E. Michael, “Integrated Health Information Systems in Tanzania: Experience and Challenges,” Electronic Journal of Information Systems in Developing Countries, vol. 33, no. 1, pp. 1–21, Feb. 2008, doi: 10.1002/J.1681-4835.2008.TB00227.X.

[74] [74]E. Heo, J. Kim, and S. Cho, “Selecting hydrogen production methods using fuzzy analytic hierarchy process with opportunities, costs, and risks,” Int J Hydrogen Energy, vol. 37, no. 23, pp. 17655–17662, Dec. 2012, doi: 10.1016/j.ijhydene.2012.09.055.

[75] [75]J. C. Pham et al., “The harm susceptibility model: a method to prioritise risks identified in patient safety reporting systems,” Qual Saf Health Care, vol. 19, no. 5, pp. 440–445, Oct. 2010, doi: 10.1136/qshc.2009.035444.

[76] [76]H. Cao and Z. Zhu, “Research on future accounting information system in the Internet of Things era,” ICSESS 2012 - Proceedings of 2012 IEEE 3rd International Conference on Software Engineering and Service Science, pp. 741–744, 2012, doi: 10.1109/ICSESS.2012.6269573.

[77] [77]M. A. Piette, S. K. Kinney, and P. Haves, “Analysis of an information monitoring and diagnostic system to improve building operations,” Energy Build, vol. 33, no. 8, pp. 783–791, Oct. 2001, doi: 10.1016/S0378-7788(01)00068-8.

[78] [78]F. K. Kirogo, “Effect of Risk- Based Audit on Financial Perfomance: A Survey of Insurance Companies in Nakuru Town, Kenya,” IOSR Journal of Business and Management, vol. 16, no. 10, pp. 84–91, 2014, doi: 10.9790/487X-161038491.

[79] [79]T. Greenhalgh and R. Peacock, “Effectiveness and efficiency of search methods in systematic reviews of complex evidence: Audit of primary sources,” Br Med J, vol. 331, no. 7524, pp. 1064–1065, Nov. 2005, doi: 10.1136/BMJ.38636.593461.68.

[80] [80]D. Helbing, “Globally networked risks and how to respond,” Nature, vol. 497, no. 7447, pp. 51–59, 2013, doi: 10.1038/NATURE12047.

[81] [81]T. K. Mackey and B. A. Liang, “The global counterfeit drug trade: Patient safety and public health risks,” J Pharm Sci, vol. 100, no. 11, pp. 4571–4579, 2011, doi: 10.1002/JPS.22679.

[82] [82]S. Aral, E. Brynjolfsson, and M. Van Alstyne, “Information, technology and information worker productivity task level evidence,” Inf. Syst. Res., vol. 23, no. 3, part 2, pp. 849–867, 2012, doi: 10.1287/isre.1110.0408.

[83] [83]V. Cho, “A study of the roles of trusts and risks in information-oriented online legal services using an integrated model,” Inf. Manag., vol. 43, no. 4, pp. 502–520, Jun. 2006, doi: 10.1016/j.im.2005.12.002.

[84] [84]M. Tarafdar and R. M. Davison, “Research in Information Systems: Intra-Disciplinary and Inter-Disciplinary Approaches,” J Assoc Inf Syst, vol. 19, no. 6, pp. 523–551, 2018, doi: 10.17705/1JAIS.00500.

[85] [85]J. Cardoso, J. Pt, R. P. Bostrom, and A. Sheth, “Workflow Management Systems and ERP Systems: Differences, Commonalities, and Applications,” Information Technology and Management 2004 5:3, vol. 5, no. 3, pp. 319–338, Jun. 2004, doi: 10.1023/B:ITEM.0000031584.14039.99.

[86] [86]L. Willcocks, M. Lacity, and A. Craig, “Robotic process automation: strategic transformation lever for global business services?,” journals.sagepub.comL Willcocks, M Lacity, A CraigJournal of Information Technology Teaching Cases, 2017•journals.sagepub.com, vol. 7, no. 1, pp. 17–28, May 2017, doi: 10.1057/S41266-016-0016-9.

[87] [87]F. Benaben, W. Mu, N. Boissel-Dallier, A. M. Barthe-Delanoe, S. Zribi, and H. Pingaud, “Supporting interoperability of collaborative networks through engineering of a service-based mediation information system (mise 2.0),” Enterp Inf Syst, vol. 9, pp. 556–582, Aug. 2015, doi: 10.1080/17517575.2014.928949.

[88] [88]P. C. Tetlock, “Information transmission in finance,” Annual Review of Financial Economics, vol. 6, pp. 365–384, Dec. 2014, doi: 10.1146/ANNUREV-FINANCIAL-110613-034449.

[89] [89]K. Han, Y. Chang, and J. Hahn, “Information technology spillover and productivity: The role of information technology intensity and competition,” J. Manag. Inf. Syst., vol. 28, no. 1, pp. 115–145, Jul. 2011, doi: 10.2753/mis0742-1222280105.

[90] [90]W. F. Boh and D. Yellin, “Using enterprise architecture standards in managing information technology,” Journal of Management Information Systems, vol. 23, no. 3, pp. 163–207, Dec. 2006, doi: 10.2753/MIS0742-1222230307.

[91] [91]D. C. Kaelber and D. W. Bates, “Health information exchange and patient safety,” J Biomed Inform, vol. 40, no. 6 SUPPL., Dec. 2007, doi: 10.1016/J.JBI.2007.08.011.

[92] [92]N. Ebrahim-Khanjari, W. Hopp, and S. M. R. Iravani, “Trust and information sharing in supply chains,” Prod Oper Manag, vol. 21, no. 3, pp. 444–464, May 2012, doi: 10.1111/J.1937-5956.2011.01284.X.

[93] [93]L. Pérez-Lombard, J. Ortiz, and C. Pout, “A review on buildings energy consumption information,” Energy Build, vol. 40, no. 3, pp. 394–398, 2008, doi: 10.1016/J.ENBUILD.2007.03.007.

[94] [94]T. M. Choi, C. H. Chiu, and H. K. Chan, “Risk management of logistics systems,” Transp Res E Logist Transp Rev, vol. 90, pp. 1–6, Jun. 2016, doi: 10.1016/j.tre.2016.03.007.

[95] [95]F. Aqlan and S. S. Lam, “Supply chain risk modelling and mitigation,” Int J Prod Res, vol. 53, no. 18, pp. 5640–5656, Sep. 2015, doi: 10.1080/00207543.2015.1047975.

[96] [96]T. D. Sequist, “Health information technology and disparities in quality of care,” J Gen Intern Med, vol. 26, no. 10, pp. 1084–1085, Oct. 2011, doi: 10.1007/S11606-011-1812-8.

[97] [97]I. G. Cohen and M. M. Mello, “HIPAA and protecting health information in the 21st Century,” JAMA - Journal of the American Medical Association, vol. 320, no. 3, pp. 231–232, Jul. 2018, doi: 10.1001/JAMA.2018.5630.

[98] [98]K. Foerstl, C. Reuter, E. Hartmann, and C. Blome, “Managing supplier sustainability risks in a dynamically changing environment-Sustainable supplier management in the chemical industry,” Journal of Purchasing and Supply Management, vol. 16, no. 2, pp. 118–130, Jun. 2010, doi: 10.1016/j.pursup.2010.03.011.

[99] [99]R. He, X. Li, G. Chen, Y. Wang, S. Jiang, and C. Zhi, “A quantitative risk analysis model considering uncertain information,” Process Safety and Environmental Protection, vol. 118, pp. 361–370, Aug. 2018, doi: 10.1016/j.psep.2018.06.029.

[100] [100]L. Cilliers and S. V. Flowerday, “Health information systems to improve health care: A telemedicine case study,” SA Journal of Information Management, vol. 15, no. 1, Mar. 2013, doi: 10.4102/SAJIM.V15I1.541.

[101] [101]R. Crichton, D. Moodley, A. Pillay, R. Gakuba, and C. J. Seebregts, “An architecture and reference implementation of an open health information mediator: Enabling interoperability in the Rwandan health information exchange,” Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), vol. 7789 LNCS, pp. 87–104, 2013, doi: 10.1007/978-3-642-39088-3_6.

[102] [102]P. E. Mbondji, D. Kebede, E. W. Soumbey-Alley, C. Zielinski, W. Kouvividila, and P. S. Lusamba-Dikassa, “Health information systems in Africa: Descriptive analysis of data sources, information products and health statistics,” J R Soc Med, vol. 107, pp. 34–45, 2014, doi: 10.1177/0141076814531750.

[103] [103]T. Aven, “Risk assessment and risk management: Review of recent advances on their foundation,” Eur J Oper Res, vol. 253, no. 1, pp. 1–13, Aug. 2016, doi: 10.1016/j.ejor.2015.12.023.

[104] [104]T. Deblonde and P. Hartemann, “Environmental impact of medical prescriptions: Assessing the risks and hazards of persistence, bioaccumulation and toxicity of pharmaceuticals,” Public Health, vol. 127, no. 4, pp. 312–317, Apr. 2013, doi: 10.1016/j.puhe.2013.01.026.

[105]  

How to cite this paper

Adetomiwa A. Dosunmu, Peter Olusoji Ogundele "Security Audit and Enterprise Risk Assessment Frameworks for Resilient Information Systems" Iconic Research And Engineering Journals Volume 3 Issue 5 2019 Page 434-447
Adetomiwa A. Dosunmu, Peter Olusoji Ogundele "Security Audit and Enterprise Risk Assessment Frameworks for Resilient Information Systems" Iconic Research And Engineering Journals, vol. 3, no. 5, Nov. 2019
Adetomiwa A. Dosunmu, Peter Olusoji Ogundele (2019). Security Audit and Enterprise Risk Assessment Frameworks for Resilient Information Systems. Iconic Research And Engineering Journals, 3(5).
Adetomiwa A. Dosunmu, Peter Olusoji Ogundele "Security Audit and Enterprise Risk Assessment Frameworks for Resilient Information Systems" Iconic Research And Engineering Journals, vol. 3, no. 5, Nov. 2019.
@article{1713225,
      author = {Adetomiwa A. Dosunmu, Peter Olusoji Ogundele},
      title = {Security Audit and Enterprise Risk Assessment Frameworks for Resilient Information Systems},
      journal = {Iconic Research And Engineering Journals},
      year = {2019},
      volume = {3},
      number = {5},
      pages = {434-447},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1713225.pdf},
      abstract = {The increasing dependence of organisations on complex, interconnected information systems has heightened exposure to cyber threats, operational disruptions, and systemic vulnerabilities. Security breaches, data loss incidents, service outages, and compliance failures have demonstrated that traditional, compliance-oriented security controls are insufficient for ensuring long-term information system resilience. Consequently, security auditing and enterprise risk assessment have evolved from isolated assurance activities into strategic governance mechanisms aimed at strengthening organisational resilience. This paper presents a comprehensive synthesis of security audit and enterprise risk assessment frameworks relevant to resilient information systems, drawing exclusively on literature published. The study reviews foundational audit models, risk assessment methodologies, governance standards, and resilience-oriented security paradigms, highlighting their strengths, limitations, and areas of convergence. By integrating insights from information systems security, risk management, internal control, and organisational resilience research, the paper develops a structured perspective on how security audits and enterprise risk assessments can be aligned to support robust, adaptive, and trustworthy information systems. The findings contribute to both academic and practitioner discourse by clarifying the role of assurance and risk assessment in achieving sustained information system resilience.},
      keywords = {Information Systems Security; Security Audit; Enterprise Risk Assessment; Cyber Resilience; Risk Governance; Information Assurance},
      month = {November},
  }