Draft- It Governance and compliance 11 pages pages with references and conclusions
1. Journal of Hospitality and Tourism Technology
Berezina, K. (2010). Journal of Hospitality and Tourism Technology. Emerald Group Publishing Limited.
The purpose of this paper is to explore the main barriers and key issues that the hotel industry professionals face during the Payment Card Industry Data Security Standards PCI DSS & compliance process. This paper will help to understand weaknesses and gaps in the PCI compliance process within the hotel industry that will provide a foundation to develop strategies and methods to address those issues in the future. The paper presents an exploratory study using a stage design. The first stage of the study was designed utilizing the Delphi technique to identify the issues that take place in the PCI compliance process in hotels. After analyzing the results of the first stage of the study, a list of PCI issues was compiled and incorporated in the web hosted questionnaire. In total, 30 hotel executives participated in the second stage of the study providing their evaluation of the importance of the identified PCI compliance issues. A list of 20 PCI compliance issues that hotel executives face during the process was compiled as an outcome of the first stage of the study. The second stage of the study showed high financial cost of implementing and maintaining, lack of qualified staff, inadequate staff training, ambiguous terms in PCI DSS language, and lack of vendors support and compliance to be the top five issues in PCI compliance in hotels. The paper provides a useful insight into the issues that take place in the hotel industry during the PCI compliance process. This field has not been studied well in the literature. This paper presents the problems in PCI compliance that need to be addressed in order to make the process more efficient and effective.
2. Handbook for HIPAA-HITECH Security
Amatayakul, M. (2013). Handbook for HIPAA-HITECH Security. Chicago: Americal Medical Association.
Handbook for HIPAA-HITECH Security, second edition details the final regulations brought about by HITECH changes to the HIPAA security rule and to the privacy rule as it applies to security. This essential guide will help you learn practical and pragmatic ways to interpret the new regulations and ensure compliance. The handbook and accompanying downloadable material enable health care professionals to successfully implement the systems necessary to establish and maintain the latest requirements. This new edition of a favorite AMA publication offers even more support, including: Case Studies—Enhance your understanding of health information technology and the electronic health record Question and Answer Sections—Test the comprehension of you and your staff on all the important security concepts Customizable Tables and Checklists (downloadable)—Effectively document the evidence of your compliance activities. Being in compliance with HIPAA involves not only ensuring that you provide the appropriate patient rights and controls on your uses and disclosures of Protected Health Information; but that you also have the proper policies and procedures in place. If audited or the subject of a compliance review, you will be required to show the government you have all the necessary documentation in place for safeguarding patient Protected Health Information and indicate how you addressed all required security safeguards. This starts with the fundamentals of a HIPAA compliance program.
3. Ramifications of the Sarbanes Oxley (SOX) Act on IT governance
Karanja, E. (2014). Ramifications of the Sarbanes Oxley (SOX) Act on IT governance. International Journal of Accounting & Information Management.
Purpose – In most firms, accounting and financial information and reporting systems are either incorporated or embedded in computer-based information systems (IS). Despite the important roles that these computer-based IS play in facilitating the SOX Act compliance initiatives, the act is silent on the roles of the CIOs, although it does stipulate specific functions for the CEOs, CFOs, and the auditors. Based on a detailed analysis of the extant literature, this article argues that IT units, under the leadership of the CIOs, contribute significantly in the procurement, design, implementation, and the governance of these computer-based IS. The paper aims to discuss these issues. Design/methodology/approach – The researchers generate and empirically test hypotheses using a panel data set obtained from press releases issued by firms following the hiring of CIOs between 1999 and 2005. Findings – The results reveal that, after the enactment of the SOX Act in 2002, many firms hired new CIOs in the post-SOX Act period. Also, many of these executives were hired to fill newly created Chief information officer (CIO) positions. The results support the argument that the SOX Act has influenced the roles of senior IT executives and IT governance. Research limitations/implications – Although this study focused on hiring trends, there are other characteristics associated with CIOs that might have an impact on corporate IT governance. Future studies could investigate whether or not, for instance, firms reported fewer IT material weaknesses before or after the hire of the CIOs. Originality/value – This research presents the argument and detailed discussion that while the SOX Act does not explicitly require the CIOs to sign off on the accounting/financial statements and reports, their role is fundamental in making the firm meet the SOX Act compliance standards.
4. Research on IT Governance, Risk and Value: Challenges and Opportunities
Debreceny, R. S. (2013). Research on IT Governance, Risk and Value: Challenges and Opportunities. Journal of Information Systems.
An introduction is presented in which the editor discusses various reports within the issue on topics including the risk of information technology governance (ITG), the level of knowledge of ITG, and the future of ITG research. This theme issue on IT governance, risk, and value arose from traditions in AIS research and as a natural extension to the research synthesized in Wilkin and Chenhall (2010). The call for papers reflected the wide range of research interests within the ITG domain. The call emphasized more recent concerns with areas such as value management, value delivery, risk management, and integration of ITG with corporate governance. There are seven papers in the theme issue. Thanks to the efforts put in by the authors and an impressive and hard-working group of reviewers drawn internationally from the AIS and MIS domains, the theme issue was completed in less than a year. The papers traverse the complete range of research dimensions within ITG. Ali et al. (2013) address the issue of the level of knowledge on ITG held by the top management team (TMT) and the ability of the TMT to turn this knowledge into competitive advantage. The authors adopt and adapt constructs in the literature for knowledge ‘‘adaptive capacity’’ to the ITG domain. What knowledge does the TMT have about ITG? How is this knowledge communicated within the TMT? How does the TMT undertake environmental scanning on ITG? In a survey of members of TMTs in Australian private-sector entities, they associate these factors with the ‘‘absorptive capacity’’ of ITG (i.e., ITG implementation outcomes). Ali et al. (2013) find that prior ITG knowledge and the quality of inter-TMT communication are most strongly associated with ITG outcomes.
PR Newswire. (2014). DataMotion Survey Shows IT Management "Disconnect" with Non-IT Employees on Security and Compliance Policies. Morristown, NJ.
DataMotion (www.datamotion.com), an established email encryption provider, today released results of its second annual survey on corporate email and file transfer habits. Among the findings is a far-reaching communication disconnect between IT management and non-IT employees on security and compliance policies. This encompasses such critical areas as effective communication of policies, as well as the use of free consumer-type file transfer tools and corporate email on mobile devices. Additionally, the survey showed a disturbing percentage in IT management knowingly taking compliance risks and even turning off essential capabilities due to technology issues. At a time when very significant penalties are being levied against organizations of all sizes for non-compliance and data breaches, C-level executives should take notice.
ISS