From It Audit Findings to Cybersecurity Governance: A Risk-Based Remediation Framework for Critical Digital Infrastructure
Main Article Content
Abstract
Article Details
Section
How to Cite
References
1. Alqahtani, N., & Almukaynizi, M. (2026). VulnScore: A deployed system for patch prioritization combining human input and temporal threat intelligence. International Journal of Information Security, 25, Article 2. https://doi.org/10.1007/s10207-025-01164-3
2. Amani, F., Magnan, M., & Moldovan, R. (2025). Cybersecurity risks and incidents disclosure: A literature review. Accounting Perspectives. https://doi.org/10.1111/1911-3838.12411
3. Büyüközkan, G., & Güler, M. (2025). Cybersecurity maturity model: Systematic literature review and a proposed model. Technological Forecasting and Social Change, 213, 123996. https://doi.org/10.1016/j.techfore.2025.123996
4. Calvin, C., Cybersecurity and Infrastructure Security Agency. (n.d.). Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA): Frequently asked questions. Retrieved August 19, 2026, from https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs
5. Chen, C., Hartmann, C. C., & Gottfried, A. (2022). The impact of audit committee IT expertise on data breaches. Journal of Information Systems. https://doi.org/10.2308/isys-2020-076
6. Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/tqm-09-2020-0202
7. Eulerich, M., & Holt, M. (2025). Characteristics of cybersecurity and IT involvement by the IA activity. International Journal of Accounting Information Systems, 56, 100726. https://doi.org/10.1016/j.accinf.2025.100726
8. Eulerich, M., Huang, Q., Pawlowski, J., & Vasarhelyi, M. A. (2025). Using process mining as an assurance tool in the three-lines-model. International Journal of Accounting Information Systems, 56, 100731. https://doi.org/10.1016/j.accinf.2025.100731
9. Gale, M., Bongiovanni, I., & Slapničar, S. (2022). Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead. Computers & Security, 121, 102840. https://doi.org/10.1016/j.cose.2022.102840
10. Haapamäki, E., & Sihvonen, J. (2026). Mandatory cybersecurity disclosure: Early evidence from 10-K reports. International Journal of Accounting Information Systems, 57, 100775. https://doi.org/10.1016/j.accinf.2026.100775
11. Héroux, S., & Fortin, A. (2024). How the three lines of defense can contribute to public firms’ cybersecurity effectiveness. International Journal of Disclosure and Governance, 22(2), 377–396. https://doi.org/10.1057/s41310-024-00226-7
12. Imdieke, A. J. (2022). The role of timing and management’s remediation actions in preventing failed remediation of material weaknesses in internal controls. Contemporary Accounting Research, 39(1), 157–198. https://doi.org/10.1111/1911-3846.12725
13. Institute of Internal Auditors. (2020). The IIA’s three lines model: An update of the three lines of defense. The Institute of Internal Auditors.
14. Institute of Internal Auditors. (2026). Statement of position: The three lines model. The Institute of Internal Auditors.
15. ISACA. (2018). COBIT 2019 framework: Introduction and methodology. ISACA.
16. Jacobs, J., Romanosky, S., Adjerid, I., & Baker, W. (2020). Improving vulnerability remediation through better exploit prediction. Journal of Cybersecurity, 6(1). https://doi.org/10.1093/cybsec/tyaa015
17. Jacobs, J., Romanosky, S., Edwards, B., Adjerid, I., & Roytman, M. (2021). Exploit prediction scoring system (EPSS). Digital Threats: Research and Practice, 2(3), 1–17. https://doi.org/10.1145/3436242
18. Lois, P., Drogalas, G., Karagiorgos, A., Thrassou, A., & Vrontis, D. (2021). Internal auditing and cyber security: Audit role and procedural contribution. International Journal of Managerial and Financial Accounting, 13(1), 25. https://doi.org/10.1504/ijmfa.2021.116207
19. Lowry, M. R., Vance, A., & Vance, M. D. (2025). Inexpert supervision: Field evidence on boards’ oversight of cybersecurity. Management Science. https://doi.org/10.1287/mnsc.2023.04147
20. Mentzelou, K., Chountalas, P. T., Kitsios, F. C., Magoutas, A. I., & Dasaklis, T. K. (2025). Identifying and modeling barriers to compliance with the NIS2 directive: A DEMATEL approach. Journal of Cybersecurity and Privacy, 5(4), 97. https://doi.org/10.3390/jcp5040097
21. Miller, T., Staves, A., Maesschalck, S., Sturdee, M., & Green, B. (2021). Looking back to look forward: Lessons learnt from cyber-attacks on industrial control systems. International Journal of Critical Infrastructure Protection, 35, 100464. https://doi.org/10.1016/j.ijcip.2021.100464
22. Mojtahedi, A., & Zhou, L. (2024). Information technology internal control material weaknesses in financial reporting: Categories, trends, associations, and industry effects. International Journal of Accounting Information Systems, 53, 100679. https://doi.org/10.1016/j.accinf.2024.100679
23. National Institute of Standards and Technology. (2025d). Prioritizing cybersecurity risk for enterprise risk management (NIST Interagency Report 8286B, Update 1). https://doi.org/10.6028/NIST.IR.8286B-upd1
24. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). https://doi.org/10.6028/NIST.CSWP.29
25. National Institute of Standards and Technology. (2025a). Identifying and estimating cybersecurity risk for enterprise risk management (NIST Interagency Report 8286A, Rev. 1). https://doi.org/10.6028/NIST.IR.8286Ar1
26. National Institute of Standards and Technology. (2025b). Integrating cybersecurity and enterprise risk management (ERM) (NIST Interagency Report 8286, Rev. 1). https://doi.org/10.6028/NIST.IR.8286r1
27. National Institute of Standards and Technology. (2025c). Staging cybersecurity risks for enterprise risk management and governance oversight (NIST Interagency Report 8286C, Rev. 1). https://doi.org/10.6028/NIST.IR.8286Cr1
28. Patterson, C. M., Nurse, J. R. C., & Franqueira, V. N. L. (2023). Learning from cyber security incidents: A systematic review and future research agenda. Computers & Security, 132, 103309. https://doi.org/10.1016/j.cose.2023.103309
29. Pollmeier, S., Bongiovanni, I., & Slapničar, S. (2023). Designing a financial quantification model for cyber risk: A case study in a bank. Safety Science, 159, 106022. https://doi.org/10.1016/j.ssci.2022.106022
30. Pursiainen, C., & Kytömaa, E. (2023). From European critical infrastructure protection to the resilience of European critical entities: What does it mean? Sustainable and Resilient Infrastructure, 8(sup1), 85–101. https://doi.org/10.1080/23789689.2022.2128562
31. Sarbanes-Oxley Act of 2002, Pub. L. No. 107-204, 116 Stat. 745 (2002).
32. Sathurshan, M., Saja, A., Thamboo, J., Haraguchi, M., & Navaratnam, S. (2022). Resilience of critical infrastructure systems: A systematic literature review of measurement frameworks. Infrastructures, 7(5), 67. https://doi.org/10.3390/infrastructures7050067
33. Savaş, S., & Karataş, S. (2022). Cyber governance studies in ensuring cybersecurity: An overview of cybersecurity governance. International Cybersecurity Law Review, 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4
34. Slapničar, S., Axelsen, M., Bongiovanni, I., & Stockdale, D. (2023). A pathway model to five lines of accountability in cybersecurity governance. International Journal of Accounting Information Systems, 51, 100642. https://doi.org/10.1016/j.accinf.2023.100642
35. Slapničar, S., Vuko, T., Čular, M., & Drašček, M. (2022). Effectiveness of cybersecurity audit. International Journal of Accounting Information Systems, 44, 100548. https://doi.org/10.1016/j.accinf.2021.100548
36. Steinbart, P. J., Raschke, R. L., Gal, G., & Dilla, W. N. (2012). The relationship between internal audit and information security: An exploratory investigation. International Journal of Accounting Information Systems, 13(3), 228–243. https://doi.org/10.1016/j.accinf.2012.06.007
37. Steinbart, P. J., Raschke, R. L., Gal, G., & Dilla, W. N. (2018). The influence of a good relationship between the internal audit and information security functions on information security outcomes. Accounting, Organizations and Society, 71, 15–29. https://doi.org/10.1016/j.aos.2018.04.005
38. U.S. Securities and Exchange Commission. (2023). Cybersecurity risk management, strategy, governance, and incident disclosure (Release Nos. 33-11216; 34-97989; File No. S7-09-22). https://www.sec.gov/rules/final/2023/33-11216.pdf
39. Valkenburg, B., & Bongiovanni, I. (2024). Unravelling the three lines model in cybersecurity: A systematic literature review. Computers & Security, 139, 103708. https://doi.org/10.1016/j.cose.2024.103708
40. Vuko, T., Slapničar, S., Čular, M., & Drašček, M. (2024). Key drivers of cybersecurity audit effectiveness: A neo-institutional perspective. International Journal of Auditing. https://doi.org/10.1111/ijau.12365
41. Wallis, T., & Dorey, P. (2023). Implementing partnerships in energy supply chain cybersecurity resilience. Energies, 16(4), 1868. https://doi.org/10.3390/en16041868