Thai University RankingsRESEARCH RADAR
← กลับฐานข้อมูลงานวิจัย
มีศักยภาพระดับโลก

Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework

Cybersecurity Governance Deficiencies in External Audit: A Structured Review and Control-to-Assertion Framework

สัญญาณผลกระทบ83/100
01

ข้อมูลจากบทคัดย่อ

ยังไม่มีสรุปภาษาไทยสำหรับระเบียนนี้
ด้านล่างเป็นบทคัดย่อต้นฉบับภาษาอังกฤษจากข้อมูลบรรณานุกรม โปรดตรวจบทความต้นฉบับก่อนอ้างอิง

Digital financial reporting depends on identity services, enterprise systems, cloud platforms, automated controls and system-generated evidence. Cybersecurity weaknesses therefore enter external audit when a governance condition or control deficiency affects a material reporting process, an assertion, a disclosure, an estimate or the reliability of audit evidence. This article develops a non-deterministic control-to-assertion framework through a structured integrative review. The search, completed on 16 July 2026, covered English-language journal work published from 2000 to 15 July 2026 through Google Scholar and publisher search services. The final analytic set contains 32 peer-reviewed journal articles, four institutional sources and two public company filings used for worked application. The revision separates organisation-level cybersecurity governance deficiencies from process-level cyber control deficiencies. It also locates the model against COSO, COBIT 2019, NIST CSF 2.0, IT general control methods and relevant International Standards on Auditing. Existing sources provide taxonomies for governance, internal control, security outcomes and audit procedures. The new framework supplies the missing translation route between those taxonomies: governance condition, control state, financial reporting dependency, assertion-level misstatement risk, audit-evidence reliability, audit response and reassessment. Compensating, detective and corrective controls might interrupt or reduce the route, so no governance deficiency automatically produces a control failure or a material misstatement. Two worked documentary applications, The Clorox Company and MGM Resorts International, show how public incident facts enter account, assertion, evidence and procedure analysis. The framework does not estimate incident probability, expected loss or a cyber risk score. It provides a file-ready reasoning structure for entity-specific risk assessment under the auditing standards. Its main contribution lies in the separate treatment of misstatement risk and evidence reliability, followed by a traceable link to accounts, assertions, evidence sources, specialist input and audit procedures.

02

เหตุผลที่อยู่ในฐานติดตาม

ระเบียนนี้ได้รับ Impact Signal 83/100 จากความใหม่ แหล่งเผยแพร่ ความร่วมมือ และสัญญาณในข้อมูลบรรณานุกรม คะแนนนี้ใช้จัดลำดับการติดตาม ไม่ใช่การตัดสินคุณภาพงานวิจัย

ประเด็นที่เกี่ยวข้อง: Information and Cyber Security · Auditing, Earnings Management, Governance · Cloud Data Security Solutions

03

บทบาทของนักวิจัยและสถาบันไทย

Somkiat Tangjitsitcharoen · Chulalongkorn University

04

ข้อจำกัดของข้อมูล

หน้านี้เป็นระเบียนบรรณานุกรมและข้อมูลจากบทคัดย่อ ยังไม่ใช่บทวิเคราะห์ฉบับเต็มหรือการประเมินคุณภาพงานวิจัย ควรตรวจสอบ DOI และเอกสารต้นฉบับก่อนนำไปอ้างอิง