The purpose of studying the success factors of principle and practice in Information Technology Risk Management (ITRM) is initiated from the proposition that appropriate ITRM principle and practice can mitigate IT risks and losses which is a result of security threats. The literature showed that various general principles and frameworks are widely published but the established principle cannot be put into the practice. Additionally, there is a research study regarding the difficulty to maintain independent in identifying, reviewing and reporting tasks of IT risk and internal audit functions. The methodology consisted of the review of general principles and frameworks' documents and the interview from case studies. The general principles and frameworks in this research collected from the question "Which principles and frameworks are applied to ITRM in your organization?". The question was asked to people in IT risk and IT internal audit functions from banking organizations and other industries which advanced information technologies
IntroductionNowadays the financial institutions have obviously adopted the advantage of the internet or other electronic channels to provide accurate and reliable services (Omariba et al., 2012;Malami et al., 2012;Khrais, 2015). Nevertheless, there has been frequently updated news regarding various patterns of cybercrime causing abundant individual or financial institution's losses. Security threats are events that damage the information system resources or reduce the confidentiality, integrity and availability of information (Geriè and Hutinski, 2007). The proposition in the study is an appropriate Information Technology Risk Management (ITRM) principle and practice can mitigate IT risks and losses which is a result of security threats.From our review, several ITRM principles and frameworks have been developed and updated by various well-known professional associations and organizations. Nevertheless, there were some issues in the adoption of those principles and frameworks into the practice (Bandyopadhyay et al., 1999;Suh and Han, 2003;Pereira and Santos, 2012;Shameli-Sendi et al., 2015;Agrawal, 2016).Furthermore, another issue was that the fast developed principles and frameworks cannot be effectively practiced in real circumstances (Gelbstein, 2016).As a result, the study of ITRM practice seems to be essential and contributed to an organization to acknowledge the success factors for appropriation in the ITRM principle and practice. The organization of this paper starts with introduction. The theoretical background is explained followed by the research methodology. Subsequently, the research results are explained. The success factors from reviewing documents and the interviews were compared as a triangulation in analysis and interpretation. Finally, the conclusion and suggestion for future work are described.
Theoretical BackgroundAccording to the review of relevant documents, there are several ITRM principle and framework
Research MethodologyWe designed the methods t...