The Mediating Role of Security Controls between Information-technology Risks and the Security of Accounting Information Systems: A Field Study in Telecommunication Companies Operating in the Republic of Yemen

Authors

  • Sultan Ali Ahmed Al-Sorihi Department of Accounting, Faculty of Administrative Sciences, University of Science and Technology, Yemen
  • Mohammed A. Alrubaidi Department of Accounting, Faculty of Administrative Sciences, University of Science and Technology, Yemen
  • Nabil Hassan Abdo Al-Hemyari Department of Accounting, Faculty of Administrative Sciences, University of Science and Technology, Yemen

DOI:

https://doi.org/10.35516/jjba.v21i1.270

Keywords:

Information Technology Risks, Security Controls, Security of Accounting Information Systems

Abstract

This study aims to test Security Controls (SCs) as a mediator between information-technology risks (ITR) and the security of AISs in telecommunication companies operating in Yemen (TCOY). To achieve this objective, a questionnaire was used to collect data according to the comprehensive method, where (356) questionnaire forms were distributed and the validated questionnaire forms for analysis were (218). To analyze the data, (SmartPLS) was used in assessing the measurement model and the structural model, as well as in the evaluation of path coefficients and testing the hypotheses of the study. It has been concluded that ITRs negatively affect the security of AISs before the mediation of SCs (47.6%). The results indicate that the mediation of SCs between ITRs and security of AISs is a partial mediation. Also, ITRs have an indirect negative impact on the security of AISs after the mediation of SCs (25.3%), as part of the impact is transferred through SCs from ITRs to the security of AISs (indirect impact). The study concluded with a set of recommendations, most notably: paying more attention to the confidentiality, integrity and availability of information, keeping abreast of technological developments, implementing SCs and updating them constantly, supporting the information security by the higher management, improving security-response activities, accelerating the implementation of robust authentication, giving great attention to access control, and effectively monitoring security policy-implementation. This is to raise the level of security of AISs and reduce the negative impact of ITRs.

Downloads

Published

2025-01-13

How to Cite

Al-Sorihi, S. A. A. . ., Alrubaidi, M. A. . ., & Al-Hemyari, N. H. A. . . (2025). The Mediating Role of Security Controls between Information-technology Risks and the Security of Accounting Information Systems: A Field Study in Telecommunication Companies Operating in the Republic of Yemen. Jordan Journal of Business Administration, 21(1), 1–28. https://doi.org/10.35516/jjba.v21i1.270

Issue

Section

Articles