Implications of Cybersecurity on Accounting Information

IF 0.4 Q4 COMPUTER SCIENCE, INFORMATION SYSTEMS African Journal of Information Systems Pub Date : 2019-09-01 DOI:10.2308/isys-10715
Diane J. Janvrin, T. Wang
{"title":"Implications of Cybersecurity on Accounting Information","authors":"Diane J. Janvrin, T. Wang","doi":"10.2308/isys-10715","DOIUrl":null,"url":null,"abstract":"R ecent high-profile cybersecurity incidents, such as Equifax, Sony, and Target, have increased professional and regulatory attention. For example, organizations are under pressure to demonstrate that they are managing cybersecurity threats, and that they have effective processes and controls in place to detect, respond to, mitigate, and recover from breaches and other security events. Cybersecurity risk management involves not only improving internal controls, but also includes a wide range of factors from strategy, IT management, investment decisions, human behavior, disaster recovery/business continuity, and technical solutions to actual implementation and practices. From the regulatory perspective, the PCAOB explicitly included the assessment of cybersecurity risks in its 2018–2022 strategic plan (PCAOB 2018). Further, the Securities and Exchange Commission (SEC) recently issued reporting guidelines on cybersecurity risk disclosures (SEC 2018), while the AICPA proposed an assurance framework for auditors to use to evaluate an organization’s cybersecurity risk management policies and procedures (AICPA 2017). Accounting information systems (AIS) researchers, who stand at the intersection between information systems and accounting, can contribute to understanding the impact of cybersecurity on accounting information from different theoretical or empirical perspectives. For example, our emphasis on understanding how behavior impacts action may provide insight to managers as they develop and implement cybersecurity policies and work to prevent and detect cybersecurity breaches. Further, our knowledge of how financial and nonfinancial information impacts organizational value may be helpful to investigate how investors and auditors react to disclosed data security breaches. Finally, we offer this special-theme issue to encourage cybersecurity research by the broader accounting community. To illustrate, Banker and Feng (2019) and Richardson, Smith, and Watson (2019) demonstrate how archival financial methodology can be used to examine important cybersecurity issues. Accounting behavioral researchers are encouraged to follow the lead of Cheng and Walton (2019) and Frank, Grenier, and Pyzoha (2019) in using experiments to provide insights into cybersecurity challenges. Further, managerial researchers may find Curry, Marshall, Correia, and Crossler’s (2019) work helpful in generating ideas on how applicable theories and skills can be applied to this important topic.","PeriodicalId":42112,"journal":{"name":"African Journal of Information Systems","volume":"33 1","pages":""},"PeriodicalIF":0.4000,"publicationDate":"2019-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"African Journal of Information Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.2308/isys-10715","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 5

Abstract

R ecent high-profile cybersecurity incidents, such as Equifax, Sony, and Target, have increased professional and regulatory attention. For example, organizations are under pressure to demonstrate that they are managing cybersecurity threats, and that they have effective processes and controls in place to detect, respond to, mitigate, and recover from breaches and other security events. Cybersecurity risk management involves not only improving internal controls, but also includes a wide range of factors from strategy, IT management, investment decisions, human behavior, disaster recovery/business continuity, and technical solutions to actual implementation and practices. From the regulatory perspective, the PCAOB explicitly included the assessment of cybersecurity risks in its 2018–2022 strategic plan (PCAOB 2018). Further, the Securities and Exchange Commission (SEC) recently issued reporting guidelines on cybersecurity risk disclosures (SEC 2018), while the AICPA proposed an assurance framework for auditors to use to evaluate an organization’s cybersecurity risk management policies and procedures (AICPA 2017). Accounting information systems (AIS) researchers, who stand at the intersection between information systems and accounting, can contribute to understanding the impact of cybersecurity on accounting information from different theoretical or empirical perspectives. For example, our emphasis on understanding how behavior impacts action may provide insight to managers as they develop and implement cybersecurity policies and work to prevent and detect cybersecurity breaches. Further, our knowledge of how financial and nonfinancial information impacts organizational value may be helpful to investigate how investors and auditors react to disclosed data security breaches. Finally, we offer this special-theme issue to encourage cybersecurity research by the broader accounting community. To illustrate, Banker and Feng (2019) and Richardson, Smith, and Watson (2019) demonstrate how archival financial methodology can be used to examine important cybersecurity issues. Accounting behavioral researchers are encouraged to follow the lead of Cheng and Walton (2019) and Frank, Grenier, and Pyzoha (2019) in using experiments to provide insights into cybersecurity challenges. Further, managerial researchers may find Curry, Marshall, Correia, and Crossler’s (2019) work helpful in generating ideas on how applicable theories and skills can be applied to this important topic.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
网络安全对会计信息的影响
最近备受瞩目的网络安全事件,如Equifax、索尼和Target,引起了专业人士和监管机构的关注。例如,组织在压力下证明他们正在管理网络安全威胁,并且他们有有效的流程和控制措施来检测、响应、减轻和从漏洞和其他安全事件中恢复。网络安全风险管理不仅涉及改进内部控制,还包括从战略、IT管理、投资决策、人类行为、灾难恢复/业务连续性、技术解决方案到实际实施和实践的广泛因素。从监管角度来看,PCAOB明确将网络安全风险评估纳入其2018 - 2022年战略计划(PCAOB 2018)。此外,美国证券交易委员会(SEC)最近发布了关于网络安全风险披露的报告指南(SEC 2018),而美国注册会计师协会(AICPA)提出了一个保证框架,供审计师用于评估组织的网络安全风险管理政策和程序(AICPA 2017)。会计信息系统(AIS)研究人员站在信息系统和会计之间的交叉点,可以从不同的理论或实证角度帮助理解网络安全对会计信息的影响。例如,我们强调理解行为如何影响行动,这可能为管理人员制定和实施网络安全政策以及预防和检测网络安全漏洞的工作提供见解。此外,我们对财务和非财务信息如何影响组织价值的了解可能有助于调查投资者和审计师对披露的数据安全漏洞的反应。最后,我们提供这个专题问题,以鼓励更广泛的会计界进行网络安全研究。为了说明这一点,Banker和Feng(2019)以及Richardson, Smith和Watson(2019)展示了如何使用档案财务方法来检查重要的网络安全问题。鼓励会计行为研究人员跟随Cheng和Walton(2019)以及Frank、Grenier和Pyzoha(2019)的领导,使用实验来提供对网络安全挑战的见解。此外,管理研究人员可能会发现Curry、Marshall、Correia和Crossler(2019)的工作有助于产生关于如何将适用的理论和技能应用于这一重要主题的想法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
African Journal of Information Systems
African Journal of Information Systems COMPUTER SCIENCE, INFORMATION SYSTEMS-
自引率
14.30%
发文量
0
审稿时长
30 weeks
期刊最新文献
The Informativeness of Sentiment Types in Risk Factor Disclosures: Evidence from Firms with Cybersecurity Breaches Does XBRL Tagging Indicate Disclosure Quality? The Relationship Between XBRL Standard and Extension Tags and Stock Return Synchronicity Constituent Input on Regulatory Initiatives: A Machine-Learning Approach to Efficiently and Effectively Analyze Unstructured Data Application of Latent Semantic Analysis in Accounting Research Designing a Classifying System for Nonprofit Organizations Using Textual Contents from the Mission Statement
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1