Using information technology governance, risk management and compliance (GRC) as a creator of business values – a case study

South African Journal of Economic and Management Sciences

 
 
Field Value
 
Title Using information technology governance, risk management and compliance (GRC) as a creator of business values – a case study
 
Creator Lubbe, Sam Jokonya, Osden
 
Description The relationship between Information Technology (IT) Governance, Risk Management and Compliance (GRC) and organisation business values continues to interest academics and practitioners (IT Governance Institute, 2003). Like governance, risk management and compliance generally, IT GRC is about the decision rights and accountabilities that encourage desirable behaviour in the use of IT (IT Governance Institute, 2003). A case study approach was used in an organisation with many business units. The organisation selected is a mining company, RioZim, situated in Zimbabwe. Data was collected from business units on IT issues and business values. The interviews centred on the IT GRC practices based on responsibility and authority for IT decision making. The results suggest that IT GRC does not adequately support business values. The study revealed that business values should drive IT GRC and IT GRC should be the responsibility of executives and all business units.
 
Publisher AOSIS Publishing
 
Contributor
Date 2011-08-12
 
Type info:eu-repo/semantics/article info:eu-repo/semantics/publishedVersion —
Format application/pdf
Identifier 10.4102/sajems.v12i1.264
 
Source South African Journal of Economic and Management Sciences; Vol 12, No 1 (2009); 115-125 2222-3436 1015-8812
 
Language eng
 
Relation
The following web links (URLs) may trigger a file download or direct you to an alternative webpage to gain access to a publication file format of the published article:

https://sajems.org/index.php/sajems/article/view/264/88
 
Rights Copyright (c) 2011 Sam Lubbe, Osden Jokonya https://creativecommons.org/licenses/by/4.0
ADVERTISEMENT