vix.ing · top · new · best · stats · spec

Data Driven Approaches to Cybersecurity Governance for Board Decision-Making -- A Systematic Review

2023/11/29 by Anita Modi, Modi, Anita, Ievgeniia Kuzminykh +3
Business, Management and Accounting · Computer Science · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information and Cyber Security #Network Security and Intrusion Detection #Supply Chain Resilience and Risk Management

paper · pdf · doi:10.48550/arxiv.2311.17578

openalex publication_date 2023/11/29 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Cybersecurity governance influences the quality of strategic decision-making to ensure cyber risks are managed effectively. Board of Directors are the decisions-makers held accountable for managing this risk; however, they lack adequate and efficient information necessary for making such decisions. In addition to the myriad of challenges they face, they are often insufficiently versed in the technology or cybersecurity terminology or not provided with the correct tools to support them to make sound decisions to govern cybersecurity effectively. A different approach is needed to ensure BoDs are clear on the approach the business is taking to build a cyber resilient organization. This systematic literature review investigates the existing risk measurement instruments, cybersecurity metrics, and associated models for supporting BoDs. We identified seven conceptual themes through literature analysis that form the basis of this study's main contribution. The findings showed that, although sophisticated cybersecurity tools exist and are developing, there is limited information for Board of Directors to support them in terms of metrics and models to govern cybersecurity in a language they understand. The review also provides some recommendations on theories and models that can be further investigated to provide support to Board of Directors.

Related