{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T09:43:54Z","timestamp":1766137434563,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":74,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,3,31]],"date-time":"2020-03-31T00:00:00Z","timestamp":1585612800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,3,31]]},"DOI":"10.1145\/3386723.3387843","type":"proceedings-article","created":{"date-parts":[[2020,5,25]],"date-time":"2020-05-25T18:06:11Z","timestamp":1590429971000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["IT Security and IT Governance Alignment"],"prefix":"10.1145","author":[{"given":"Norli","family":"Shariffuddin","sequence":"first","affiliation":[{"name":"Universiti Teknologi MARA (UiTM), Shah Alam, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Azlinah","family":"Mohamed","sequence":"additional","affiliation":[{"name":"Universiti Teknologi MARA (UiTM), Shah Alam, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,5,18]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"ISACA Board Briefing on IT Governance","year":"2003","unstructured":"ISACA Board Briefing on IT Governance 2 nd Edition. ( 2003 ) Retrieved from http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/Board-Briefing-on-IT-Governance-2nd-Edition.aspx ISACA Board Briefing on IT Governance 2nd Edition. (2003) Retrieved from http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/Board-Briefing-on-IT-Governance-2nd-Edition.aspx","edition":"2"},{"key":"e_1_3_2_1_2_1","volume-title":"IT Governance on One Page","author":"Weill","year":"2004","unstructured":"Weill , Peter and Ross, Jeanne W. , IT Governance on One Page ( 2004 ). MIT Sloan Working Paper No. 4517-04; CIS Research Working Paper No . 349 Weill, Peter and Ross, Jeanne W., IT Governance on One Page (2004). MIT Sloan Working Paper No. 4517-04; CIS Research Working Paper No. 349"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2005.362"},{"key":"e_1_3_2_1_4_1","first-page":"3143","volume-title":"Designing information technology governance processes: diagnosing contemporary practices and competing theories,\" Proceedings of the 35th Annual Hawaii International Conference on System Sciences","author":"Ribbers R. R.","year":"2002","unstructured":"P. M. A. Ribbers , R. R. Peterson and M. M. Parker ( 2002 ), \" Designing information technology governance processes: diagnosing contemporary practices and competing theories,\" Proceedings of the 35th Annual Hawaii International Conference on System Sciences , Big Island , HI , pp. 3143 -- 3154 . P. M. A. Ribbers, R. R. Peterson and M. M. Parker (2002), \"Designing information technology governance processes: diagnosing contemporary practices and competing theories,\" Proceedings of the 35th Annual Hawaii International Conference on System Sciences, Big Island, HI, pp. 3143--3154."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-14547-1_2"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.25300\/MISQ\/2015\/39.2.10"},{"key":"e_1_3_2_1_7_1","volume-title":"The Impact of IT Governance on Business Performance\" Association for Information Systems AIS Electronic Library (AISeL)","author":"Lazic","year":"2011","unstructured":"Lazic , Miroslav; Groth, Martin ; Schillinger, Christian ; and Heinzl, Armin ( 2011 ), \" The Impact of IT Governance on Business Performance\" Association for Information Systems AIS Electronic Library (AISeL) . Lazic, Miroslav; Groth, Martin; Schillinger, Christian; and Heinzl, Armin (2011), \"The Impact of IT Governance on Business Performance\" Association for Information Systems AIS Electronic Library (AISeL)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.accinf.2013.02.001"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.5555\/3018601.3018608"},{"key":"e_1_3_2_1_10_1","volume-title":"The Influence of IT Investment and IT Governance on Corporate Performance of Multibusiness Firms.\" Proceedings of the 2015 International Conference on Big Data Applications and Services - BigDAS '15","author":"Ryu K. S.","year":"2015","unstructured":"Ryu , K. S. , Park , J. S. , & Park , J. H. ( 2015 ). \" The Influence of IT Investment and IT Governance on Corporate Performance of Multibusiness Firms.\" Proceedings of the 2015 International Conference on Big Data Applications and Services - BigDAS '15 . Ryu, K. S., Park, J. S., & Park, J. H. (2015). \"The Influence of IT Investment and IT Governance on Corporate Performance of Multibusiness Firms.\" Proceedings of the 2015 International Conference on Big Data Applications and Services - BigDAS '15."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1057\/palgrave.dam.3650033"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/S2212-5671(15)01440-9"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the First Italian Conference on Cybersecurity (ITASEC17)","author":"Maria Cristina Arcuri","year":"2017","unstructured":"Maria Cristina Arcuri , Marina Brogi and Gino Gandolfi ( 2017 ). \" How does cyber crime affect firms? The effect of information security breaches on stock returns \". In Proceedings of the First Italian Conference on Cybersecurity (ITASEC17) Maria Cristina Arcuri, Marina Brogi and Gino Gandolfi (2017). \"How does cyber crime affect firms? The effect of information security breaches on stock returns\". In Proceedings of the First Italian Conference on Cybersecurity (ITASEC17)"},{"key":"e_1_3_2_1_14_1","volume-title":"The extreme risk of personal data breaches and the erosion of privacy. The European Physical Journal B, 89(1)","author":"Wheatley S.","year":"2016","unstructured":"Wheatley , S. , Maillart , T. , & Sornette , D. ( 2016 ). The extreme risk of personal data breaches and the erosion of privacy. The European Physical Journal B, 89(1) . Wheatley, S., Maillart, T., & Sornette, D. (2016). The extreme risk of personal data breaches and the erosion of privacy. The European Physical Journal B, 89(1)."},{"key":"e_1_3_2_1_15_1","first-page":"5","volume-title":"Ransomware attacks: detection, prevention and cure. Network Security","author":"Brewer R.","year":"2016","unstructured":"Brewer , R. ( 2016 ). \" Ransomware attacks: detection, prevention and cure. Network Security \", 2016(9), pp. 5 -- 9 . Brewer, R. (2016). \"Ransomware attacks: detection, prevention and cure. Network Security\", 2016(9), pp. 5--9."},{"key":"e_1_3_2_1_16_1","unstructured":"Savita Mohurle Manisha Patil 2017. \" A brief study of Wannacry Threat: Ransomware Attack \" International Journal of Advanced Research in Computer Science.  Savita Mohurle Manisha Patil 2017. \" A brief study of Wannacry Threat: Ransomware Attack \" International Journal of Advanced Research in Computer Science."},{"key":"e_1_3_2_1_17_1","volume-title":"Viswanath Venkatesh and Susan A. Brown","author":"Sigi Goode","year":"2017","unstructured":"Sigi Goode , Hartmut Hoehle , Viswanath Venkatesh and Susan A. Brown ( 2017 ). \"User Compensation As A Data Breach Recovery Action: An Investigation Of The Sony Playstation Network Breach\".MIS Quarterly Vol . 41 No. 3, pp. 703--727 Sigi Goode, Hartmut Hoehle, Viswanath Venkatesh and Susan A. Brown (2017). \"User Compensation As A Data Breach Recovery Action: An Investigation Of The Sony Playstation Network Breach\".MIS Quarterly Vol. 41 No. 3, pp. 703--727"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1503\/cmaj.1095434"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.bushor.2016.01.002"},{"key":"e_1_3_2_1_20_1","unstructured":"The Guardian Revealed: 50 million Facebook profiles harvested for Cambridge Analytica in major data breach. Retrieved from https:\/\/www.theguardian.com\/news\/2018\/mar\/17\/cambridge-analytica-facebook-influence-us-election  The Guardian Revealed: 50 million Facebook profiles harvested for Cambridge Analytica in major data breach. Retrieved from https:\/\/www.theguardian.com\/news\/2018\/mar\/17\/cambridge-analytica-facebook-influence-us-election"},{"key":"e_1_3_2_1_21_1","article-title":"Corporate Information Technology Governance Under Fire","author":"Lawrence Trautman","year":"2013","unstructured":"Lawrence Trautman , Jason Triche & James Wetherbe ( 2013 ). \" Corporate Information Technology Governance Under Fire \". Journal of Strategic Information and Studies Lawrence Trautman, Jason Triche & James Wetherbe (2013). \"Corporate Information Technology Governance Under Fire\". Journal of Strategic Information and Studies","journal-title":"Journal of Strategic Information and Studies"},{"key":"e_1_3_2_1_22_1","volume-title":"IT Governance for Cyber-Physical Systems: The Case of Industry 4.0","author":"Savtschenko M.","year":"2017","unstructured":"Savtschenko , M. , Schulte , F. , & Vo\u00df , S. ( 2017 ). \" IT Governance for Cyber-Physical Systems: The Case of Industry 4.0 \". Savtschenko, M., Schulte, F., & Vo\u00df, S. (2017). \"IT Governance for Cyber-Physical Systems: The Case of Industry 4.0\"."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.2308\/isys-10339"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1540-6210.2008.00981.x"},{"key":"e_1_3_2_1_25_1","volume-title":"Towards a Taxonomy of Challenges in an Integrated IT Governance Framework Implementation.Journal of International Technology and Information Management","author":"Mathew Nicho","year":"2016","unstructured":"Mathew Nicho , Suadad Muamaar ( 2016 ). \" Towards a Taxonomy of Challenges in an Integrated IT Governance Framework Implementation.Journal of International Technology and Information Management Volume 25 Issue 2 Mathew Nicho, Suadad Muamaar (2016). \"Towards a Taxonomy of Challenges in an Integrated IT Governance Framework Implementation.Journal of International Technology and Information Management Volume 25 Issue 2"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Selig G. J. (2018). \"IT Governance --- An Integrated Framework and Roadmap: How to Plan Deploy and Sustain for Competitive Advantage.\" 2018 Portland International Conference on Management of Engineering and Technology (PICMET).  Selig G. J. (2018). \"IT Governance --- An Integrated Framework and Roadmap: How to Plan Deploy and Sustain for Competitive Advantage.\" 2018 Portland International Conference on Management of Engineering and Technology (PICMET).","DOI":"10.23919\/PICMET.2018.8481957"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2016.27"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CICN.2015.216"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/B978-0-12-803843-7.00038-7"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1108\/IJAIM-02-2013-0017"},{"key":"e_1_3_2_1_31_1","volume-title":"The Information Content of Sarbanes-Oxley in Predicting Security Breaches\". Computers & Security","author":"Westland J. C.","year":"2019","unstructured":"Westland , J. C. ( 2019 ). \" The Information Content of Sarbanes-Oxley in Predicting Security Breaches\". Computers & Security . Westland, J. C. (2019). \"The Information Content of Sarbanes-Oxley in Predicting Security Breaches\". Computers & Security."},{"key":"e_1_3_2_1_32_1","volume-title":"Health IT Legislation in the United States: Guidelines for IS Researchers\". Communications of the Association for Information Systems","author":"Cousins K.","year":"2016","unstructured":"Cousins , K. ( 2016 ). \" Health IT Legislation in the United States: Guidelines for IS Researchers\". Communications of the Association for Information Systems . Cousins, K. (2016). \"Health IT Legislation in the United States: Guidelines for IS Researchers\". Communications of the Association for Information Systems."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.25"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-27813-7"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11623-018-0971-8"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-018-2479-2"},{"key":"e_1_3_2_1_37_1","volume-title":"Government regulations in cyber security: Framework, standards and recommendations.\" Future Generation Computer Systems","author":"Srinivas J.","year":"2018","unstructured":"Srinivas , J. , Das , A. K. , & Kumar , N. ( 2018 ). \" Government regulations in cyber security: Framework, standards and recommendations.\" Future Generation Computer Systems . Srinivas, J., Das, A. K., & Kumar, N. (2018). \"Government regulations in cyber security: Framework, standards and recommendations.\" Future Generation Computer Systems."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(18)30043-6"},{"key":"e_1_3_2_1_39_1","unstructured":"About\n      ISACA\n   (\n  2019\n  ). Retrieved from https:\/\/www.isaca.org\/about-isaca\/Pages\/default.aspx  About ISACA (2019). Retrieved from https:\/\/www.isaca.org\/about-isaca\/Pages\/default.aspx"},{"key":"e_1_3_2_1_40_1","unstructured":"(ISC)2: The World's Leading Cybersecurity Professional Organization. (2019) Retrieved from https:\/\/www.isc2.org\/About  (ISC)2: The World's Leading Cybersecurity Professional Organization. (2019) Retrieved from https:\/\/www.isc2.org\/About"},{"key":"e_1_3_2_1_41_1","unstructured":"Certified Information Security Manager (CISM) Retrieved from http:\/\/www.isaca.org\/Certification\/CISM-Certified-Information-Security-Manager\/Pages\/default.aspx  Certified Information Security Manager (CISM) Retrieved from http:\/\/www.isaca.org\/Certification\/CISM-Certified-Information-Security-Manager\/Pages\/default.aspx"},{"key":"e_1_3_2_1_42_1","unstructured":"CISSP - The World's Premier Cybersecurity Certification Retrieved from https:\/\/www.isc2.org\/Certifications\/CISSP  CISSP - The World's Premier Cybersecurity Certification Retrieved from https:\/\/www.isc2.org\/Certifications\/CISSP"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(17)30013-1"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICISSEC.2016.7885859"},{"key":"e_1_3_2_1_45_1","volume-title":"Security And Privacy In Computing And Communications\/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE).","author":"Lidster W.","year":"2018","unstructured":"Lidster , W. , & Rahman , S. S. M. ( 2018 ). \" Obstacles to Implementation of Information Security Governance\".17th IEEE International Conference On Trust , Security And Privacy In Computing And Communications\/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE). Lidster, W., & Rahman, S. S. M. (2018). \"Obstacles to Implementation of Information Security Governance\".17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE)."},{"key":"e_1_3_2_1_46_1","volume-title":"Integration of it governance and security risk management: A systematic literature review.\" International Conference on Information Society (i-Society)","author":"De Smet D.","year":"2016","unstructured":"De Smet , D. , & Mayer , N. ( 2016 ). \" Integration of it governance and security risk management: A systematic literature review.\" International Conference on Information Society (i-Society) . De Smet, D., & Mayer, N. (2016). \"Integration of it governance and security risk management: A systematic literature review.\" International Conference on Information Society (i-Society)."},{"key":"e_1_3_2_1_47_1","volume-title":"Dotting the I and Crossing (out) the T in IT Governance: New Challenges for Information Governance.\" 49th Hawaii International Conference on System Sciences (HICSS)","author":"Borgman H.","year":"2016","unstructured":"Borgman , H. , Heier , H. , Bahli , B. , & Boekamp , T. ( 2016 ). \" Dotting the I and Crossing (out) the T in IT Governance: New Challenges for Information Governance.\" 49th Hawaii International Conference on System Sciences (HICSS) . Borgman, H., Heier, H., Bahli, B., & Boekamp, T. (2016). \"Dotting the I and Crossing (out) the T in IT Governance: New Challenges for Information Governance.\" 49th Hawaii International Conference on System Sciences (HICSS)."},{"key":"e_1_3_2_1_48_1","volume-title":"Cybersecurity Governance: How can we measure it?\" IST-Africa Week Conference","author":"De Bruin R.","year":"2016","unstructured":"De Bruin , R. , & von Solms , S. H. ( 2016 ). \" Cybersecurity Governance: How can we measure it?\" IST-Africa Week Conference . De Bruin, R., & von Solms, S. H. (2016). \"Cybersecurity Governance: How can we measure it?\" IST-Africa Week Conference."},{"key":"e_1_3_2_1_49_1","volume-title":"ISACA Board Briefing on IT Governance","year":"2003","unstructured":"ISACA Board Briefing on IT Governance 2 nd Edition. ( 2003 ) Retrieved from http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/Board-Briefing-on-IT-Governance-2nd-Edition.aspx ISACA Board Briefing on IT Governance 2nd Edition. (2003) Retrieved from http:\/\/www.isaca.org\/Knowledge-Center\/Research\/ResearchDeliverables\/Pages\/Board-Briefing-on-IT-Governance-2nd-Edition.aspx","edition":"2"},{"issue":"6","key":"e_1_3_2_1_50_1","article-title":"IT Governance, IT\/Business Alignment and Organization Performance for Public Sectors","volume":"5","author":"Amit Ghildyal","year":"2017","unstructured":"Amit Ghildyal and Elizabeth Chang ( 2017 ) \" IT Governance, IT\/Business Alignment and Organization Performance for Public Sectors \". Journal of Economics, Business and Management , Vol. 5 ( 6 ). Amit Ghildyal and Elizabeth Chang (2017) \"IT Governance, IT\/Business Alignment and Organization Performance for Public Sectors\". Journal of Economics, Business and Management, Vol. 5 (6).","journal-title":"Journal of Economics, Business and Management"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2018.665"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijinfomgt.2015.10.004"},{"key":"e_1_3_2_1_53_1","volume-title":"IT Consumerization And The Transformation Of IT Governance.\" MIS Quarterly","author":"Robert Wayne Gregory","year":"2018","unstructured":"Robert Wayne Gregory , Evgeny Kaganer, Ola Henfridsson & Thierry Jean Ruch ( 2018 ). \" IT Consumerization And The Transformation Of IT Governance.\" MIS Quarterly Vol. 42(4) Robert Wayne Gregory, Evgeny Kaganer, Ola Henfridsson & Thierry Jean Ruch (2018). \"IT Consumerization And The Transformation Of IT Governance.\" MIS Quarterly Vol. 42(4)"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1201\/1078\/44705.21.4.20040901\/84183.2"},{"key":"e_1_3_2_1_55_1","volume-title":"Principles and Models for Organizing the IT Function\". MIS Quarterly Executive, 1","author":"Agarwal R.","year":"2002","unstructured":"Agarwal , R. , & Sambamurthy , V. ( 2002 ). \" Principles and Models for Organizing the IT Function\". MIS Quarterly Executive, 1 . Agarwal, R., & Sambamurthy, V. (2002). \"Principles and Models for Organizing the IT Function\". MIS Quarterly Executive, 1."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","DOI":"10.4018\/978-1-59140-140-7","volume-title":"Structures, Processes and Relational Mechanisms for IT Governance\" Strategies forInformation Technology Governance","author":"Van Grembergen W.","year":"2004","unstructured":"Van Grembergen , W. , De Haes , S. and Guldentops , E . ( 2004 ), \" Structures, Processes and Relational Mechanisms for IT Governance\" Strategies forInformation Technology Governance Van Grembergen, W., De Haes, S. and Guldentops, E. (2004), \"Structures, Processes and Relational Mechanisms for IT Governance\" Strategies forInformation Technology Governance"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.4018\/IJITBAG.2017070103"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1080\/17517575.2013.804952"},{"key":"e_1_3_2_1_59_1","volume-title":"A Proposed Best-practice Framework for Information Security Governance. 295--301","author":"Gashgari","year":"2017","unstructured":"Gashgari , Ghada & Walters, Robert & Wills, Gary . ( 2017 ). A Proposed Best-practice Framework for Information Security Governance. 295--301 . Gashgari, Ghada & Walters, Robert & Wills, Gary. (2017). A Proposed Best-practice Framework for Information Security Governance. 295--301."},{"key":"e_1_3_2_1_60_1","volume-title":"On the Way to a Minimum Baseline in IT Governance: Using Expert Views for Selective Implementation of COBIT 5.\" 48th Hawaii International Conference on System Sciences","author":"Bartens Y.","year":"2015","unstructured":"Bartens , Y. , Haes , S. de, Lamoen , Y. , Schulte , F. , & Voss , S. ( 2015 ). \" On the Way to a Minimum Baseline in IT Governance: Using Expert Views for Selective Implementation of COBIT 5.\" 48th Hawaii International Conference on System Sciences . Bartens, Y., Haes, S. de, Lamoen, Y., Schulte, F., & Voss, S. (2015). \"On the Way to a Minimum Baseline in IT Governance: Using Expert Views for Selective Implementation of COBIT 5.\" 48th Hawaii International Conference on System Sciences."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"crossref","unstructured":"Laksono H. & Supriyadi Y. (2015). \"Design and implementation information security governance using Analytic Network Process and cobit 5 for Information Security a case study of unit XYZ.\" International Conference on Information Technology Systems and Innovation  Laksono H. & Supriyadi Y. (2015). \"Design and implementation information security governance using Analytic Network Process and cobit 5 for Information Security a case study of unit XYZ.\" International Conference on Information Technology Systems and Innovation","DOI":"10.1109\/ICITSI.2015.7437689"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"crossref","unstructured":"Durachman Y. Chairunnisa Y. Soetarno D. Setiawan A. & Mintarsih F. (2017). \"IT security governance evaluation with use of COBIT 5 framework: A case study on UIN Syarif Hidayatullah library information system.\" 5th International Conference on Cyber and IT Service Management (CITSM).  Durachman Y. Chairunnisa Y. Soetarno D. Setiawan A. & Mintarsih F. (2017). \"IT security governance evaluation with use of COBIT 5 framework: A case study on UIN Syarif Hidayatullah library information system.\" 5th International Conference on Cyber and IT Service Management (CITSM).","DOI":"10.1109\/CITSM.2017.8089302"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1080\/10580530701586136"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(05)70275-X"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.5555\/558724"},{"key":"e_1_3_2_1_66_1","volume-title":"Information Security Architecture---An integrated approach to security in an organization","author":"Tudor J. K.","year":"2000","unstructured":"Tudor , J. K. ( 2000 ). \" Information Security Architecture---An integrated approach to security in an organization \". Boca Raton, FL : Auerbach . Tudor, J. K. (2000). \"Information Security Architecture---An integrated approach to security in an organization\". Boca Raton, FL: Auerbach."},{"key":"e_1_3_2_1_67_1","first-page":"1","volume-title":"Models and Applications in Emerging Technologies (ICAMMAET)","author":"Asgarkhani E.","year":"2017","unstructured":"M. Asgarkhani , E. Correia and A. Sarkar , \" An overview of information security governance,\" 2017 International Conference on Algorithms, Methodology , Models and Applications in Emerging Technologies (ICAMMAET) , Chennai , 2017 , pp. 1 -- 4 . M. Asgarkhani, E. Correia and A. Sarkar, \"An overview of information security governance,\" 2017 International Conference on Algorithms, Methodology, Models and Applications in Emerging Technologies (ICAMMAET), Chennai, 2017, pp. 1--4."},{"key":"e_1_3_2_1_68_1","volume-title":"Corporate ICT Governance: A Tool for ICT Best Practice.\" Proceedings of the International Conference on Management, Leadership, and Governance","author":"Asgarkhani M","year":"2013","unstructured":"Asgarkhani , M ( 2013 ).: \" Corporate ICT Governance: A Tool for ICT Best Practice.\" Proceedings of the International Conference on Management, Leadership, and Governance . Asgarkhani, M (2013).: \"Corporate ICT Governance: A Tool for ICT Best Practice.\" Proceedings of the International Conference on Management, Leadership, and Governance."},{"key":"e_1_3_2_1_69_1","unstructured":"BBC. \n      The Chernobyl\n     disaster\n   (\n  2006\n  ). Retrieved from http:\/\/www.bbc.co.uk\/dna\/h2g2\/A2922103.  BBC. The Chernobyl disaster (2006). Retrieved from http:\/\/www.bbc.co.uk\/dna\/h2g2\/A2922103."},{"key":"e_1_3_2_1_70_1","volume-title":"IEEE Conf. International Infrastructure Survivability Workshop","author":"Franz M.","year":"2004","unstructured":"Franz , M. , Miller , D. , Byres , EJ ( 2004 ).: \" The Use of Attack Trees in Assessing Vulnerabilities in SCADA Systems . IEEE Conf. International Infrastructure Survivability Workshop Franz, M., Miller, D., Byres, EJ (2004).: \"The Use of Attack Trees in Assessing Vulnerabilities in SCADA Systems. IEEE Conf. International Infrastructure Survivability Workshop"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.02.009"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(03)00606-0"},{"key":"e_1_3_2_1_73_1","volume-title":"Swiss army knife of software processes generic framework of ISO 27001 and its mapping on resource management.\" International Conference on Communication Technologies (ComTech)","author":"Rukh L.","year":"2017","unstructured":"Rukh , L. , & Malik , A. A. ( 2017 ). \" Swiss army knife of software processes generic framework of ISO 27001 and its mapping on resource management.\" International Conference on Communication Technologies (ComTech) . Rukh, L., & Malik, A. A. (2017). \"Swiss army knife of software processes generic framework of ISO 27001 and its mapping on resource management.\" International Conference on Communication Technologies (ComTech)."},{"key":"e_1_3_2_1_74_1","volume-title":"Adapting ISO 27001 to a Public Institution.\" 14th Iberian Conference on Information Systems and Technologies (CISTI)","author":"Carvalho C.","year":"2019","unstructured":"Carvalho , C. , & Marques , E. ( 2019 ). \" Adapting ISO 27001 to a Public Institution.\" 14th Iberian Conference on Information Systems and Technologies (CISTI) Carvalho, C., & Marques, E. (2019). \"Adapting ISO 27001 to a Public Institution.\" 14th Iberian Conference on Information Systems and Technologies (CISTI)"}],"event":{"name":"NISS2020: The 3rd International Conference on Networking, Information Systems & Security","acronym":"NISS2020","location":"Marrakech Morocco"},"container-title":["Proceedings of the 3rd International Conference on Networking, Information Systems &amp; Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3386723.3387843","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3386723.3387843","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:38:19Z","timestamp":1750199899000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3386723.3387843"}},"subtitle":["A Review"],"short-title":[],"issued":{"date-parts":[[2020,3,31]]},"references-count":74,"alternative-id":["10.1145\/3386723.3387843","10.1145\/3386723"],"URL":"https:\/\/doi.org\/10.1145\/3386723.3387843","relation":{},"subject":[],"published":{"date-parts":[[2020,3,31]]},"assertion":[{"value":"2020-05-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}