SciELO - Scientific Electronic Library Online

vol.12 issue1Celebrity endorsements versus created spokespersons in advertising: A survey among studentsTheory building trends in international management research: An archival review of preferred methods author indexsubject indexarticles search
Home Pagealphabetic serial listing  

South African Journal of Economic and Management Sciences

On-line version ISSN 2222-3436
Print version ISSN 1015-8812


JOKONYA, Osden  and  LUBBE, Sam. Using information technology governance, risk management and compliance (GRC) as a creator of business values - A case study. S. Afr. j. econ. manag. sci. [online]. 2009, vol.12, n.1, pp.115-125. ISSN 2222-3436.

The relationship between information technology (IT) governance, risk management and compliance (GRC) and organisation business values continues to interest academics and practitioners (IT Governance Institute, 2003). Like governance, risk management and compliance generally, IT GRC is about the decision rights and accountabilities that encourage desirable behaviour in the use of IT (IT Governance Institute, 2003). A case study approach was used in an organisation with many business units. The organisation selected is a mining company, RioZim, situated in Zimbabwe. Data was collected from business units on IT issues and business values. The interviews centred on the IT GRC practices based on responsibility and authority for IT decision-making. The results suggest that IT GRC does not adequately support business values. The study revealed that business values should drive IT GRC and IT GRC should be the responsibility of executives and all business units.

        · text in English     · English ( pdf )


Creative Commons License All the contents of this journal, except where otherwise noted, is licensed under a Creative Commons Attribution License