Every reference with a DOI in the deposited reference list resolved to a known
work in Crossref or DataCite at the dated check, and none carried a retraction,
withdrawal, or removal notice.
The 38 checked references that resolve
resolves10.1007/s10551-018-3981-4Institutional Theory and Evolution of ‘A Legitimate’ Compliance Culture: The Case of the UK Financial Service Sector
resolves10.1080/10580530902794786An Exploratory Study into IT Governance Implementations and its Impact on Business/IT Alignment
resolves10.2307/2095101The Iron Cage Revisited: Institutional Isomorphism and Collective Rationality in Organizational Fields
resolves10.2308/isys-51315The Current State and Future Direction of IT Audit: Challenges and Opportunities
resolves10.22495/cocv18i2art15The new three lines model for structuring corporate governance – A critical discussion of similarities and differences
resolves10.1086/228311Economic Action and Social Structure: The Problem of Embeddedness
resolves10.2308/isys-51294Repairing Organizational Legitimacy Following Information Technology (IT) Material Weaknesses: Executive Turnover, IT Expertise, and IT System Upgrades
resolves10.2308/isys-52530The Influences of CEO IT Expertise and Board-Level Technology Committees on Form 8-K Disclosure Timeliness
resolves10.2308/CIIA-2020-034Academic Research on the Role of Corporate Governance and IT Expertise in Addressing Cybersecurity Breaches: Implications for Practice, Policy, and Research
resolves10.2308/isys-50331The Internal Audit Function in Information Technology Governance: A Holistic Perspective
resolves10.2308/isys-51402The Relationship between Board-Level Technology Committees and Reported Security Breaches
resolves10.2308/isys-18-071Cybersecurity Breaches and the Role of Information Technology Governance in Audit Committee Charters
resolves10.21314/JOP.2018.201Bridging networks, systems and controls frameworks for cybersecurity curriculums and standards development
resolves10.1016/j.im.2021.103507Informing cybersecurity strategic commitment through top management perceptions: The role of institutional pressures
resolves10.1287/isre.11.2.105.11780Research Commentary: The Organizing Logic for an Enterprise's IT Activities in the Digital Era—A Prognosis of Practice and a Call for Research
resolves10.2308/isys-52229Board and Management-Level Factors Affecting the Maturity of IT Risk Management Practices
resolves10.2308/ISYS-19-033An Integrative Review and Analysis of Cybersecurity Research: Current State and Future Directions
resolves10.2308/isys-52632Information Technology Governance: Reflections on the Past and Future Directions
The 45 references without a DOI — listed, not checked
no DOI — not checkedref1
no DOI — not checkedref3
no DOI — not checkedReporting on an entity's cybersecurity risk management program and controls
no DOI — not checkedref7
no DOI — not checkedref8
no DOI — not checkedCommittee of Sponsoring Organizations of the Tredway Commission (COSO). 2013. Internal Control-Integrated Framework
no DOI — not checkedref12
no DOI — not checkedref14
no DOI — not checkedGLs%20on%20ICT%20and%20 security% 20risk%20management/872936/Final%20draft%20Guidelines%20on%20ICT%20and%20security %20risk%20management.pdf EY, and Institute of Internal Auditors., 2021. The risky six. Key questions to expose gaps in board understanding of organizational cyber resiliency
no DOI — not checkedDoes CIO risk appetite matter? Evidence from information security breach incidents
no DOI — not checkedref22
no DOI — not checkedInstitute of Internal Auditors (IIA), 2020. The IIA's Three lines model. An update of the Three Lines of Defense
no DOI — not checkedref34
no DOI — not checkedref35
no DOI — not checkedref36
no DOI — not checkedref39
no DOI — not checkedThe 2016 SIM IT issues and trends study
no DOI — not checkedref41
no DOI — not checkedref43
no DOI — not checkedCybersecurity: Risk management framework and investment cost analysis
no DOI — not checkedref45
no DOI — not checkedUnderstanding the roles of institutional pressures and organizational innovativeness in contextualized transformation toward e-business: Evidence from agricultural firms
no DOI — not checkedref47
no DOI — not checkedref48
no DOI — not checkedref49
no DOI — not checkedref51
no DOI — not checkedref52
no DOI — not checkedref53
no DOI — not checkedref54
no DOI — not checkedBoardroom operational and financial control: An insider view
no DOI — not checkedref57
no DOI — not checkedApplying the five lines of defense in managing risk
no DOI — not checkedIntegrating transaction cost and institutional theories: Toward a constrained-efficiency framework for understanding organizational design adoption
no DOI — not checkedThe board's role in managing cybersecurity risks
no DOI — not checkedref66
no DOI — not checkedCybersecurity and remote working: Croatia's (non-)response to increased cyber threats
no DOI — not checkedEffectiveness of cybersecurity audit
no DOI — not checkedThe influence of a good relationship between the internal audit and information security functions on information security outcomes, Accounting, Organizations and Society
no DOI — not checked) standards; Framework for Improving Critical Infrastructure Cybersecurity. Version 1.1
no DOI — not checkedref75
no DOI — not checkedref78
no DOI — not checkedref79
no DOI — not checkedref80
no DOI — not checkedCyber Resilience Playbook for public-private collaboration
no DOI — not checkedref83
checked 2026-08-27 — re-checked daily as this page is visited;
titles and statuses come from Crossref and DataCite and are not part of the signed record
Both snippets point at the live badge image and link back to this page. The
badge re-renders from the daily check, so an embed never goes stale by more than a day of visits.