Reference health

A Pathway Model to Five Lines of Accountability in Cybersecurity Governance

https://doi.org/10.2139/ssrn.4176559
CiteStamped reference-health badge
38/38 checkable references clean · checked 2026-08-27

Every reference with a DOI in the deposited reference list resolved to a known work in Crossref or DataCite at the dated check, and none carried a retraction, withdrawal, or removal notice.

45 without a DOI — not checked. A reference deposited without a DOI is never matched by title or guessed at; it stays outside the checked set, and this line discloses that.

The 38 checked references that resolve
resolves10.1086/262063
Formal and Real Authority in Organizations
resolves10.1109/ACCESS.2020.3024784
Security Challenges and Cyber Forensic Ecosystem in IoT Driven BYOD Environment
resolves10.1016/j.cose.2016.02.007
Information system security commitment: A study of external influences on senior management
resolves10.25300/MISQ/2017/41.3.04
Operational IT Failures, IT Value Destruction, and Board-Level IT Governance Changes1
resolves10.1007/s10551-018-3981-4
Institutional Theory and Evolution of ‘A Legitimate’ Compliance Culture: The Case of the UK Financial Service Sector
resolves10.1080/10580530902794786
An Exploratory Study into IT Governance Implementations and its Impact on Business/IT Alignment
resolves10.2307/2095101
The Iron Cage Revisited: Institutional Isomorphism and Collective Rationality in Organizational Fields
resolves10.2308/isys-51315
The Current State and Future Direction of IT Audit: Challenges and Opportunities
resolves10.22495/cocv18i2art15
The new three lines model for structuring corporate governance – A critical discussion of similarities and differences
resolves10.1111/j.1467-9299.2007.00683.x
PERFORMING GOVERNANCE: A PARTNERSHIP BOARD DRAMATURGY
resolves10.1016/j.cose.2022.102840
Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead
resolves10.1177/1094428112452151
Seeking Qualitative Rigor in Inductive Research
resolves10.1016/j.jaccpubpol.2009.06.006
Enterprise risk management and firm performance: A contingency perspective
resolves10.1086/228311
Economic Action and Social Structure: The Problem of Embeddedness
resolves10.2308/isys-51294
Repairing Organizational Legitimacy Following Information Technology (IT) Material Weaknesses: Executive Turnover, IT Expertise, and IT System Upgrades
resolves10.2308/isys-52530
The Influences of CEO IT Expertise and Board-Level Technology Committees on Form 8-K Disclosure Timeliness
resolves10.1287/isre.2020.0986
The Impact of Executives’ IT Expertise on Reported Data Security Breaches
resolves10.2308/CIIA-2020-034
Academic Research on the Role of Corporate Governance and IT Expertise in Addressing Cybersecurity Breaches: Implications for Practice, Policy, and Research
resolves10.1002/jcaf.22414
What is the role of the board‐level technology committee?
resolves10.2308/isys-50331
The Internal Audit Function in Information Technology Governance: A Holistic Perspective
resolves10.2308/isys-51402
The Relationship between Board-Level Technology Committees and Reported Security Breaches
resolves10.1080/10919392.2020.1776033
Institutional Isomorphism in Organizational Cybersecurity: A Text Analytics Approach
resolves10.1108/MAJ-02-2018-1804
Cyber security assurance process from the internal audit perspective
resolves10.2308/isys-18-071
Cybersecurity Breaches and the Role of Information Technology Governance in Audit Committee Charters
resolves10.21314/JOP.2018.201
Bridging networks, systems and controls frameworks for cybersecurity curriculums and standards development
resolves10.1016/j.im.2021.103507
Informing cybersecurity strategic commitment through top management perceptions: The role of institutional pressures
resolves10.1111/j.1467-8551.1995.tb00090.x
The Performance of an NHS Trust Board: Actors' Accounts, Minutes and Observation
resolves10.4018/978-1-59140-140-7.ch002
Integration Strategies and Tactics for Information Technology Governance
resolves10.1016/j.aos.2009.06.001
The risk management of nothing
resolves10.1287/isre.11.2.105.11780
Research Commentary: The Organizing Logic for an Enterprise's IT Activities in the Digital Era—A Prognosis of Practice and a Call for Research
resolves10.1016/j.accinf.2021.100532
The impact of CIO characteristics on data breaches
resolves10.1016/j.ijinfomgt.2015.11.009
Information security management needs more holistic approach: A literature review
resolves10.1108/MAJ-07-2017-1596
The role of internal audit and user training in information security policy compliance
resolves10.2308/isys-52229
Board and Management-Level Factors Affecting the Maturity of IT Risk Management Practices
resolves10.1108/ICS-04-2017-0025
Cybersecurity and information security – what goes where?
resolves10.2308/jis.2011.25.1.185
Information Security and Sarbanes-Oxley Compliance: An Exploratory Study
resolves10.2308/ISYS-19-033
An Integrative Review and Analysis of Cybersecurity Research: Current State and Future Directions
resolves10.2308/isys-52632
Information Technology Governance: Reflections on the Past and Future Directions
The 45 references without a DOI — listed, not checked
no DOI — not checkedref1
no DOI — not checkedref3
no DOI — not checkedReporting on an entity's cybersecurity risk management program and controls
no DOI — not checkedref7
no DOI — not checkedref8
no DOI — not checkedCommittee of Sponsoring Organizations of the Tredway Commission (COSO). 2013. Internal Control-Integrated Framework
no DOI — not checkedref12
no DOI — not checkedref14
no DOI — not checkedGLs%20on%20ICT%20and%20 security% 20risk%20management/872936/Final%20draft%20Guidelines%20on%20ICT%20and%20security %20risk%20management.pdf EY, and Institute of Internal Auditors., 2021. The risky six. Key questions to expose gaps in board understanding of organizational cyber resiliency
no DOI — not checkedDoes CIO risk appetite matter? Evidence from information security breach incidents
no DOI — not checkedref22
no DOI — not checkedInstitute of Internal Auditors (IIA), 2020. The IIA's Three lines model. An update of the Three Lines of Defense
no DOI — not checkedref34
no DOI — not checkedref35
no DOI — not checkedref36
no DOI — not checkedref39
no DOI — not checkedThe 2016 SIM IT issues and trends study
no DOI — not checkedref41
no DOI — not checkedref43
no DOI — not checkedCybersecurity: Risk management framework and investment cost analysis
no DOI — not checkedref45
no DOI — not checkedUnderstanding the roles of institutional pressures and organizational innovativeness in contextualized transformation toward e-business: Evidence from agricultural firms
no DOI — not checkedref47
no DOI — not checkedref48
no DOI — not checkedref49
no DOI — not checkedref51
no DOI — not checkedref52
no DOI — not checkedref53
no DOI — not checkedref54
no DOI — not checkedBoardroom operational and financial control: An insider view
no DOI — not checkedref57
no DOI — not checkedApplying the five lines of defense in managing risk
no DOI — not checkedIntegrating transaction cost and institutional theories: Toward a constrained-efficiency framework for understanding organizational design adoption
no DOI — not checkedThe board's role in managing cybersecurity risks
no DOI — not checkedref66
no DOI — not checkedCybersecurity and remote working: Croatia's (non-)response to increased cyber threats
no DOI — not checkedEffectiveness of cybersecurity audit
no DOI — not checkedThe influence of a good relationship between the internal audit and information security functions on information security outcomes, Accounting, Organizations and Society
no DOI — not checked) standards; Framework for Improving Critical Infrastructure Cybersecurity. Version 1.1
no DOI — not checkedref75
no DOI — not checkedref78
no DOI — not checkedref79
no DOI — not checkedref80
no DOI — not checkedCyber Resilience Playbook for public-private collaboration
no DOI — not checkedref83
What this badge says. CiteStamped means the CHECKABLE references of this work were clean at the dated check: each resolved to a known work in a public registry, and none carried a retraction notice at that time. It says nothing about the quality, findings, or importance of the work itself, and nothing about references deposited without a DOI.

checked 2026-08-27 — re-checked daily as this page is visited; titles and statuses come from Crossref and DataCite and are not part of the signed record

Embed this badge

Both snippets point at the live badge image and link back to this page. The badge re-renders from the daily check, so an embed never goes stale by more than a day of visits.

<a href="https://citestamp.com/citestamped/10.2139/ssrn.4176559"><img src="https://citestamp.com/citestamped/10.2139/ssrn.4176559/badge.svg" alt="CiteStamped reference-health badge" width="460" height="64"></a>
[![CiteStamped reference-health badge](https://citestamp.com/citestamped/10.2139/ssrn.4176559/badge.svg)](https://citestamp.com/citestamped/10.2139/ssrn.4176559)