Department

Information Systems and Security

Document Type

Article

Publication Date

2026

Embargo Period

8-24-2026

Abstract

This paper evaluates the perceived effectiveness of the security risk management (SRM) programs at a Fortune 500 firm. Layers of management and staff participated in the study. Perceived effectiveness of their SRM programs was based on nine critical success factors (CSFs). Interviews confirmed six initial CSFs (Executive Management Support, Organizational Maturity, Open Communication, Risk Management Stakeholders, Team Member Empowerment, and Holistic View of an Organization) that were extracted from the literature. They were confirmed and synthesized with three additional CSFs (Security Maintenance, Corporate Security Strategy, and Human Resource Development). Implications for SRM are discussed.

Journal Title

International Journal of Information Security and Privacy (IJISP)

Journal ISSN

1930-1669

Volume

20

Issue

1

Digital Object Identifier (DOI)

10.4018/IJISP.404388

Comments

This article received funding through Kennesaw State University's Faculty Open Access Publishing Fund, supported by the KSU Libraries and KSU Office of Research.

Share

COinS