An examination of the extent of implementation of the information security system and IT audit system in Ghananian Banks

Sylvester Hatsu, Martin B. Ujapka, Enoch D. Mpimwood

Abstract


The study examined the impact of information security and information technology (IT) audit in selected banks in Ghana. The study specifically, ascertained the degree of exposure to threats, it examined the extent of implementation of information security and IT audit system in the bank to protect information from threats, determined the impact, the performance and finally identified the challenges of the banks in managing information security system. A structured questionnaire was used as the main research instrument.  Four banks were selected for the study, including two local and two foreign banks. A total of 20 employees (5 from each) were sampled from the Headquarters of each bank in Accra. Only managers, IT managers, and Risk managers were sampled. The study found that the sampled level exposure of banks to threats to information systems is low. Local banks were however more exposed to threats than foreign banks. Largely the banks managed threats to information system by implementing strategies, including having an information security policy, information security organization, asset and human resource security system, information access control IT Audit system. The performance of banks in information system was moderate. Information security and IT audit system had correlated positively to the overall performance of the banks. Availability of information security policy has significant positive impact on bank performance. The study encouraged the banks to improve upon their information security and IT audit practices to ensure improvement in the performance of the banks in information security management.

Keywords: Employee, Technology, Audit,Management


Full Text: PDF
Download the IISTE publication guideline!

To list your conference here. Please contact the administrator of this platform.

Paper submission email: JIEA@iiste.org
ISSN (Paper)2224-5782 ISSN (Online)2225-0506
Please add our address "contact@iiste.org" into your email contact list.
This journal follows ISO 9001 management standard and licensed under a Creative Commons Attribution 3.0 License.
Copyright © www.iiste.org