SciELO - Scientific Electronic Library Online

 
vol.22 special issueSupply Chain resilience and design in retail supermarketsThe future is female: Femvertising and attitude formation towards beauty brands author indexsubject indexarticles search
Home Pagealphabetic serial listing  

Services on Demand

Journal

Article

Indicators

    Related links

    • On index processCited by Google
    • On index processSimilars in Google

    Share


    Journal of Contemporary Management

    On-line version ISSN 1815-7440

    Abstract

    SIYAYA, Mvelo Comfort; DUBIHLELA, Jobo  and  SIBANDA, Mabutho. A literature review of internal auditing involvement in cybersecurity risk management of the organisation. JCMAN [online]. 2025, vol.22, n.spe, pp.89-115. ISSN 1815-7440.  https://doi.org/10.35683/jcm24.030.293.

    PURPOSE OF THE STUDY: It is evident that internal auditing plays a crucial role in the governance, risk management and internal control processes of the organisation. Given the recent digitalisation of these processes, cybersecurity risk remains a serious challenge. The involvement of internal auditing in cybersecurity risk management is a new research area that requires urgent attention. Therefore, the purpose of this paper is to investigate the involvement of internal auditing in the cybersecurity risk management of the organisation DESIGN/METHODOLOGY/APPROACH: A non-empirical research study was conducted to examine the involvement of internal auditing in cybersecurity risk management. Data were collected from a variety of sources, including journal articles, books, professional websites, conference papers and theses/dissertations. The PRISMA flow diagram was utilised to guide the selection of relevant data for the study. A thematic qualitative research approach was used for data analysis and guiding the discussion of findings FINDINGS: The study found that the internal audit function (third line of defence) is crucial for joining forces with the information technology (IT) function (first line of defence) and risk management function (second line of defence) in the fight against cybersecurity risk. In addition, the internal audit function has a role in informing the audit committee and the board of directors whether security controls are adequate and operating effectively for mitigating cybersecurity risk RECOMMENDATIONS/VALUE: A collaborative effort between internal audit, risk management and IT functions is recommended in the fight against cybersecurity risk within the organisation. A clear set of roles and responsibilities between these functions must be determined in the cybersecurity strategy to minimise duplication of effort and promote good cybersecurity governance MANAGERIAL IMPLICATIONS: A distinct role of internal auditing in cybersecurity risk management was revealed to assist organisational management. Understanding internal audit assurance and its consulting role in cybersecurity risk should assist industry practitioners and policymakers to better utilise internal auditing in the cybersecurity strategy of the organisation JEL CLASSIFICATION: M42

    Keywords : Cybersecurity risk; cybersecurity risk management; governance; internal auditing; internal audit function; internal control; organisation.

            · text in English     · English ( pdf )