Department
Information Systems and Security
Document Type
Article
Publication Date
2026
Embargo Period
8-24-2026
Abstract
This paper evaluates the perceived effectiveness of the security risk management (SRM) programs at a Fortune 500 firm. Layers of management and staff participated in the study. Perceived effectiveness of their SRM programs was based on nine critical success factors (CSFs). Interviews confirmed six initial CSFs (Executive Management Support, Organizational Maturity, Open Communication, Risk Management Stakeholders, Team Member Empowerment, and Holistic View of an Organization) that were extracted from the literature. They were confirmed and synthesized with three additional CSFs (Security Maintenance, Corporate Security Strategy, and Human Resource Development). Implications for SRM are discussed.
Journal Title
International Journal of Information Security and Privacy (IJISP)
Journal ISSN
1930-1669
Volume
20
Issue
1
Digital Object Identifier (DOI)
10.4018/IJISP.404388
Comments
This article received funding through Kennesaw State University's Faculty Open Access Publishing Fund, supported by the KSU Libraries and KSU Office of Research.