Back to Search Start Over

Centralized IT Decision Making and Cybersecurity Breaches: Evidence from U.S. Higher Education Institutions.

Authors :
Liu, Che-Wei
Huang, Peng
Lucas, Henry C.
Source :
Journal of Management Information Systems; 2020, Vol. 37 Issue 3, p758-787, 30p, 8 Charts, 1 Graph
Publication Year :
2020

Abstract

Despite the consensus that information security should become an important consideration in information technology (IT) governance rather than the sole responsibility of the IT department, important IT governance decisions are often made on the basis of fulfilling business needs with a minimal amount of attention paid to their implications for information security. We study how an important IT governance mechanism—the degree of centralized decision making—affects the likelihood of cybersecurity breaches. Examining a sample of 504 U.S. higher-education institutions over a four-year period, we find that a university with centralized IT governance is associated with fewer breaches. Interestingly, the effect of centralized IT governance is contingent on the heterogeneity of a university's computing environment: Universities with more heterogeneous IT infrastructure benefit more from centralized IT decision making. In addition, we find the relationship between centralized governance and cybersecurity breaches is most pronounced in public universities and those with more intensive research activities. Collectively, these findings highlight the tradeoff between granting autonomy and flexibility in the use of information systems and enforcing standardized, organization-wide security protocols. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
07421222
Volume :
37
Issue :
3
Database :
Complementary Index
Journal :
Journal of Management Information Systems
Publication Type :
Academic Journal
Accession number :
147067413
Full Text :
https://doi.org/10.1080/07421222.2020.1790190