公司治理
业务
数据泄露
公司
会计
信息技术
信息安全
公共关系
财务
计算机安全
法学
计算机科学
政治学
作者
Julia L. Higgs,Robert Pinsker,Thomas Smith,George R. Young
出处
期刊:Journal of Information Systems
[American Accounting Association]
日期:2016-01-01
卷期号:30 (3): 79-98
被引量:147
摘要
ABSTRACT After several high-profile data security breaches (e.g., Target Corporation, Michaels Stores, Inc., The Home Depot), corporate boards are prioritizing the oversight of Information Technology (IT) risk. Firms are also increasingly faced with disclosure decisions regarding IT security breaches. This study proposes that firms can use the creation of a board-level technology committee as part of the firm's information technology governance (ITG) to signal the firm's ability to detect and respond to security breaches. Using reported security breaches during the time period 2005–2014, results indicate that firms with technology committees are more likely to have reported breaches in a given year than are firms without the committee. Further analysis suggests that this positive association is driven by relatively young technology committees and external source breaches. Specifically, as a technology committee becomes more established, its firm is not as likely to be breached. To obtain further evidence on the perceived value of a technology committee, this study uses a returns analysis and finds that the presence of a technology committee mitigates the negative abnormal stock returns arising from external breaches. Findings add to the evolving ITG literature, as well to the signaling theory and disclosure literatures.
科研通智能强力驱动
Strongly Powered by AbleSci AI