<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Initial Due Diligence of Information Technology as Risk Identi cation before Capital Investment in Finance Industry</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>M.Sc.Bostjan Delak</string-name>
          <email>bostjan.delak@nlb.si</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Nova Ljubljanska banka d.d.</institution>
          ,
          <addr-line>Ljubljana Smartinska 130, 1520 Ljubljana</addr-line>
          ,
          <country country="SI">Slovenia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2008</year>
      </pub-date>
      <fpage>95</fpage>
      <lpage>105</lpage>
      <abstract>
        <p>This paper summarizes a research on IT initial due diligence, which I want to submit as a proposal for PhD thesis. The main objective of the research will be to show that based on the experiences with due diligences that I have gained while evaluating tens of companies in nancial sector, a general framework for IT due diligence can be developed, which will facilitate evaluation of IT also in other industries. I believe such a framework would be a valuable contribution to the IS community as currently there is no general or widely accepted approach that one could use for initial due diligence of IT. In this proposal I brie y describe various practical concepts, models, frameworks and standards for evaluating IT, which are used worldwide in everyday activities. Then I introduce the approach for an initial IT due diligence that we use in the NLB fNova Ljubljanska bank1, Ljubljana, Sloveniag.</p>
      </abstract>
      <kwd-group>
        <kwd>Due Diligence</kwd>
        <kwd>Information Technology</kwd>
        <kwd>Information Systems</kwd>
        <kwd>IT Analysis</kwd>
        <kwd>IT Research</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Initial due diligence of a nancial company is one of the most important
activities to be carried out prior to any capital investment. In most cases initial
due diligences focus on reviewing liquidity, investments (credit and capital) and
risk management. Recently, with an ever growing impact of information systems
(IS) on daily company's business support, reviewing this segment of the reviewed
company has become very important and vital as well. This is mainly due to
large dependency of nancial companies on their IS and substantial investments
in more quality and up-to-date support ensuring integrity, con dentiality and
availability of information.</p>
      <p>Initial IT due diligence is a very comprehensive and demanding task, as it
covers a wide range of segments, such as information security and operational risk</p>
    </sec>
    <sec id="sec-2">
      <title>1 http://www.nlb.si</title>
      <p>assessment. In this paper I describe the research topic that I want to submit as
PhD research proposal.</p>
      <p>The paper is structured as follows: rstly, the notion of IT due diligence is
explained together with comparison between initial IT due diligence, general IT
due diligence and IS audit. The next section is dedicated to related work. Several
tools, frameworks, standards and methods for IT analysis are brie y described.
The third part of the paper gives more details on the research, i.e. the research
hypothesis and the research approach.
2
2.1</p>
      <sec id="sec-2-1">
        <title>Description of Scienti c Area and Related Problems</title>
        <sec id="sec-2-1-1">
          <title>Initial IT Due Diligence</title>
          <p>
            One Due Diligence explanation is [
            <xref ref-type="bibr" rid="ref1">1</xref>
            ]:
Due diligence in a corporate merger and acquisition close examination of the
books to examine the quality of both assets and liabilities of a target company.
The terminology of due diligence emerged or started to be widely used more
than 75 years ago, when the US Congress adopted the Securities Act in 1933.
In the beginning, pre-merger and acquisition activities focused on legal [
            <xref ref-type="bibr" rid="ref2">2</xref>
            ] and
nancial (bookkeeping) due diligences [
            <xref ref-type="bibr" rid="ref3">3</xref>
            ]. As nowadays IS plays a part in almost
every process in the modern company, IT due diligence has become a vital part
of a complete due diligence process.
          </p>
          <p>
            Shareholders of the company deciding to make an investment need to get a
complete picture of the investments, time required to complete the task and potential
risks of all activities and domains of the target company. Generally, initial due
diligence is conducted prior to the merger and acquisition of any company,
irrespective of the industry or region of the globe. This activity should protect
investors and shareholders from making any wrong decisions or underestimating
the resources before acquiring the target company. Initial due diligence results
and reports represent valuable information for shareholders and negotiators to
get adequate data for purchase share value at the nal negotiations.
IT due diligence is an IS analysis with the objective to get information about
the current status of IT assets, IT resources, company's documentation
compliance, compliance with regulation, risk identi cation, etc. IT due diligence is
very similar to general IT audit process [
            <xref ref-type="bibr" rid="ref4">4</xref>
            ],[
            <xref ref-type="bibr" rid="ref5">5</xref>
            ]. In comparison to general IT due
diligence or IS audit, the scope of initial IT due diligence is much wider. Initial
IT due diligence must provide valuable information about the current status of
IS, risk assessment and estimates of the resources required for harmonization
activities during the merger process. Some analyses have shown that information
about the value of IT is underestimated. According to the analyses only 15 % of
company's market value accounts for tangible assets, whilst 85 % of company's
market value consists of intangible assets [
            <xref ref-type="bibr" rid="ref6">6</xref>
            ].
          </p>
          <p>
            Unlike the general IS audit, initial IT due diligence has to provide general risk
assessments. There are several types of risks in nancial institutions [
            <xref ref-type="bibr" rid="ref7">7</xref>
            ].
Operational risks are of particular importance [
            <xref ref-type="bibr" rid="ref8">8</xref>
            ]. For banks Basel Committee on
Banking Supervision had issued practices for managing these risks, well known
in European banking industry as BASEL II 2 regulations [
            <xref ref-type="bibr" rid="ref9">9</xref>
            ]. Internal control on
how to manage operational risks has been provided by each national bank [
            <xref ref-type="bibr" rid="ref10">10</xref>
            ].
In 2004 IT Governance Institute conducted a questionnaire and its results are
available on [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ]. Similar to banking industry in EU there are plans to
implement restrictive risk management in insurance business - the so-called Solvency II
framework. This information can be found at various web pages (e.g. Wikipedia
3, European Commission 4 ).
          </p>
          <p>
            Risk analysis related to the IS risks accounts represents very important
information for shareholders and management board in view of their nal decisions
about potential capital investments - acquisition or merger. Information security
is another important segment of initial IT due diligence. Data, information and
information assets are the most important supporting components of nancial
business processes. Information is an asset and has, just like any other business
asset, its own value in the company. As such it requires proper protection. These
activities refer to safeguarding information against: loss, abuse, disclosure and
destruction [
            <xref ref-type="bibr" rid="ref12">12</xref>
            ] which is provided through con dentiality, integrity and
availability. The objectives of protecting the IS are to assure business continuity
and to restrict business losses to the minimum possible level through prevention
and security incident e ect reduction. Information security can be achieved by
implementing adequate controls, which enable compliance with the ISO/ IEC
27001:2005 standard. Information security and utilisation of security metrics is
of vital importance in initial IT due diligences [
            <xref ref-type="bibr" rid="ref13">13</xref>
            ]
2.2
          </p>
        </sec>
        <sec id="sec-2-1-2">
          <title>Initial IT Due Diligence as IS Research</title>
          <p>
            In the last two or three decades information technology has reached the same
level of scienti c research as other disciplines and a number of studies on
information system research have been carried out. Several articles in science magazines
describe di erent approaches to IS research. Design science plays and will play
an important role in IS profession also in the future [
            <xref ref-type="bibr" rid="ref14">14</xref>
            ]. There is a lively
discussion going on in academic circles about IT Artifact and its role [
            <xref ref-type="bibr" rid="ref15">15</xref>
            ] and IS
work system framework [
            <xref ref-type="bibr" rid="ref16">16</xref>
            ].
          </p>
          <p>
            There is a gap between the IS academic researches and practice waiting to be
closed [
            <xref ref-type="bibr" rid="ref17">17</xref>
            ]. Therefore it is di cult to determine whether initial IT due diligence
is closer to design or behavioural science. The process of initial IT due diligence
has similarities with practice driven research, which is explained by Zmud [
            <xref ref-type="bibr" rid="ref18">18</xref>
            ].
Initial IT due diligence could be de ned as IS work system framework.
          </p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>2 http://www.bis.org/publ/bcbsca.htm</title>
    </sec>
    <sec id="sec-4">
      <title>3 http://en.wikipedia.org/wiki/Solvency II</title>
    </sec>
    <sec id="sec-5">
      <title>4 http://ec.europa.eu/internal market/insurance/solvency/index en.htm</title>
      <sec id="sec-5-1">
        <title>Motivation</title>
        <p>
          Bhatia explained and con rmed that there is no IT Due diligence framework
generally used worldwide [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]. And as there are no worldwide used frameworks
and concepts of conducting initial IT due diligences, my objective is to identify
the most appropriate concept, de ne the hypothesis and prove - verify the
identi ed concept by one or more research cases in independent nancial institutions
outside the banking industry.
4
        </p>
      </sec>
      <sec id="sec-5-2">
        <title>Related work</title>
        <p>This chapter gives a brief description of several methods, models, frameworks,
best practices and standards, which are used for conducting di erent types of IS
analyses in a company.</p>
        <p>
          BCM Analysis. One of the most important processes in contemporary
companies is Business Continuity Management (BCM) which is also determined by
obligatory principle issued by BASEL II. It sets out 10 domains of BCM [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ].
One of the tools for the BCM analysis that can provide adequate certi cation is
Publicly Available Speci cation 56 (PAS56) 5, composed of 6 scorecards
representing a complete life cycle of BCM.
        </p>
        <p>
          COBIT (Control Objectives for Information and related Technology) Model
provides good practices across a domain and process framework and presents
activities in a manageable and logical structure. These practices will help
optimize IT-enabled investments, ensure service delivery and provide a measure
against which to judge when things go wrong [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ]. For IT to be successful in
delivering against business requirements, management should put an internal
control system or framework in place.
        </p>
        <p>To govern IT e ectively, it is important to appreciate the activities and risks
within IT that need to be managed. They are usually ordered into the
responsibility domains of: plan, build, run and monitor. Within the COBIT framework
these domains are called: Plan and Organize, Acquire and Implement, Deliver
and Support, Monitor and Evaluate.</p>
        <p>
          Each of the 34 IT processes has corresponding control objectives. Based on the
broader quality, duciary and security requirements, seven distinct, certainly
overlapping, information criteria are de ned (e ectiveness, e ciency, con
dentiality, integrity, availability, compliance and reliability). The COBIT framework
is well accepted by IS auditors, and they are using it in IT audit activities.
According to Bajec [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ] the COBIT framework can help you achieve e ective and
secure usage of information assets in order to meet business objectives.
        </p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>5 http://www.pas56.com</title>
      <p>CMM (Capability Maturity Model) is used for improvement and quality
effectiveness assessments for software development companies. It is a maturity
model or framework that helps companies improve their software life-cycle
process. The model prevents excessive projects schedule delays and costs overruns by
providing the appropriate infrastructure and necessary support to avoid these
problems. If a company has de ned di erent levels, CMM can be used as an
assessment tool in IS during initial IT due diligence.</p>
      <p>
        INFAUDITOR. Expert systems are also used for evaluation of information
systems. INFAUDITOR is one of them. Since information systems assessment
is a multi criterion decision, INFAUDITOR methodology structures the audit
domains and tests of control as a hierarchical audit tree following an analytic
hierarchical process. It is based on several expert systems. The system can be
used as a guideline to judge the su ciency of evidence [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]. INFAUDITOR assists
IS auditors in every step of the audit process.
      </p>
      <p>
        Information Technology Assessment Due Diligence Framework (ITADD)
was developed in 2005 as student project at Red McCombs Business School of the
University of Texas at Austin (USA). The ITADD framework provides IT
managers with a focused method of conducting due diligence assessment of the IT
function in companies that are the targets of corporate mergers and acquisitions
[
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. ITADD is more than a framework. It is composed of ITADD methodology
and ITADD toolkit. Another implication is that ITADD is able to add to IT
professionals a framework that is speci c to the acquisition of companies and
can be used for such processes [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]. The ITADD framework can be successfully
used for IT and initial IT due diligences.
      </p>
      <p>
        IT Balanced Score Cards (BSC) initially developed by Kaplan and
Norton is a performance management system that should allow companies to drive
their strategies on measurement and follow-up. They proposed a three-layered
structure with four perspectives. Each perspective has to be translated into
corresponding metrics and measures that assess the current position. Assessments
have to be repeated periodically. It is essential that cause and e ect
relationships are established and that after each measurement performance drivers are
clari ed. The methodology of BSC is a measurement and management system
that is very suitable for supporting IT governance processes [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ].
ITIL (Information Technology Infrastructure Library) originated in Europe
more than 20 years ago as the collection of best practices for managing IT
services based on IT service processes. ITIL is a framework for successful
implementation of IT service processes and has become part of the ISO/IEC 20000
standard for IT service management.
IS Risk Assessment is of key importance. There are various assessment
methods to be used [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. An assessor must assess all risks and determine which are
of highest importance and which require additional analysis.
      </p>
      <p>
        The CRAMM program (CCTA Risk Analysis and Management Method) o ers
several possibilities for quality security risk analysis and management [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ].
Val IT is IT governance framework that consists of a set of guiding
principles and a number of processes conforming to those principles that are further
de ned as a set of key management practices. Val IT is based on COBIT. A
key lesson of Val IT is that IT investment is no longer about implementing IT
solutions but it is about implementing IT enabled changes. Val IT enlarges and
supplements COBIT enabling comprehensive control framework for IT
management. It focuses on investment decisions (are we doing the right things?) and on
realization of bene ts (are we getting the bene ts?) while COBIT is focusing on
the execution (are we doing them the right way and are we getting them done
well?). During initial IT due diligence Val IT framework can be e ectively used
for assessing IS investments and managing them.
      </p>
      <p>NLB Approach. 10 years ago there were no IT due diligence frameworks,
models or concepts available. Some consultancy companies were o ering such
activities but did not share their approaches and protected questionnaires and
other documents as their intellectual property. As there were no questionnaires
or recipes for initial IT due diligence available on the internet either, I had no
choice but to develop my own - NLB approach. Thus on the basis of more than 20
initial IT due diligences in Central and Eastern Europe and over 40 IS analyses
(general IT due diligences) conducted in NLB Group within subsidiary
companies, internal NLB framework for initial IT due diligences has been developed.
This approach allows assessor to collect enough data to get valuable information
within a short period of time: on average between 3 and 5 working days on site
of the target company. Brie y the NLB approach framework for initial IT due
diligence process is divided into the following phases:
{ Preparation activities - initial data collecting and preparation/ updating the
list of requirements
{ Delivery - onsite visit - reviews, data gathering and interviews
{ Activities following the onsite visit - collected data analyses and report(s)
preparation
Analysis is based on di erent questionnaires (IS status, transaction statistics,
local prices, IT strengths and weaknesses). The most important and valuable
are two questionnaires - IS status and the Questionnaire for IT strengths and
weaknesses. Information on IS status is collected on the basis of a comprehensive
questionnaire (consisting of some 60 pages) which is sent to IT manager of the
target company at least one week in advance before assessor's on-site visit.</p>
      <p>The content of this document are:
Questionnaire for IS Strengths and Weaknesses is lled during interviews with IT
manager / specialists and End User managers - usually also owners of processes.
It is advisable to have questionnaires completed by respondents from various
organisation units. The questionnaire has more than 50 questions grouped in
nine domains:
{ Functioning of Data Center
{ System Development
{ Sta within IT Department
{ Quality of the Existing System
{ E ective Use of Technology
{ Use of Advance Technology
{ Co-operation / Partnership with the Business or IT
{ Information Security
{ Top Management Perspective
The answers are then analyzed using speci c procedures. The scope of deviation
/ correlation in individual questions shows the assessor what the actual state of
IT a airs is.</p>
      <p>Other questionnaires are also used for assessment of risks and assessment of IT
investments / IT costs projection for next ve years.</p>
      <p>The most important part of the initial IT due diligence comes after a complete
analysis of all the documents and questionnaires based on assessor's experience.
The assessor has to prepare one or more nal reports. The structures of the
nal reports are prede ned for NLB. Usually two reports (a short and a longer)
are used. The longer report is prepared when the negotiation activities start, it
contains:
{ Basis Requirements for the Initial IT Due Diligence
{ Management Summary
{ Detailed Findings
{ Assessor's Opinion
{ Recommendations
{ Value of IT Assets
{ Interviews' Analysis
{ SWOT
{ Conclusion</p>
      <p>IS Risks
Investment and Cost Estimation for M&amp;A and Harmonization</p>
      <p>NLB Human Resources Required for M&amp;A and Harmonization
Others. Above mentioned are several alternative approaches that can be used
for partial or complete initial IT due diligence. Undoubtedly many other
approaches could be found in the theory or in real life worldwide.
Aforementioned consultancy companies and world known audit companies have their own
methodologies for initial IT due diligences. But they do not share their
methods, frameworks and tools. Most probably large global companies have their own
methods for due diligence as well.
5</p>
      <sec id="sec-6-1">
        <title>Research Proposal</title>
        <p>Almost none of the aforementioned tools, methods, standards and frameworks
could easily be used as universal initial IT due diligence framework. At the
moment two of them are most convenient: ITADD and NLB Approach. Both
approaches share the same goal to capture as much data as possible to provide
correct information about the IS current status and its value.</p>
        <p>My hypothesis is to prepare a universal initial IT due diligence framework based
on NLB Approach framework. I will compare this analysis tool with science
research. The framework with an accompanying tool will be veri ed on real case
studies in one or more nancial institutions.
6</p>
      </sec>
      <sec id="sec-6-2">
        <title>Research Approach</title>
        <p>The framework I would like to develop and prove is based on NLB Approach
which has been proven in many initial and general IT due diligences. The
experiences I have gained by implementing NLB approach will be the basis for
universal initial IT due diligence framework which could generally be used for
conducting initial IT due diligences for nancial institutions and for other
businesses as well.</p>
        <p>The initial IT due diligence process will be compared with research
methodologies and the parallels with currently known science researches will be documented
and presented.</p>
        <p>A prototype tool to support de ned process will be developed. This tool will
help any assessor to repeat processes with the same results.</p>
        <p>The new basic initial IT due diligence framework will be documented and
practically proven in non banking nancial institutions. The con rmed initial IT due
diligence framework could then be e ectively used almost everywhere.</p>
      </sec>
      <sec id="sec-6-3">
        <title>Conclusion</title>
        <p>One could say initial IT due diligence is a very simple task. But reality shows
that in fact it is a very demanding and complex activity. There are no worldwide
used frameworks or standard approaches. Some of the methods, frameworks,
standards and best practices have been presented in the document, including
the NLB approach, which has shown very good results. At this stage the rough
skeleton of universal initial IT due diligence framework is completed with di
erent supporting documents - questionnaires. A corresponding supporting for tool
is under development. In the near future a detailed comparison analysis with
science research methods will start. I will start looking for potential nancial
institutions where this framework could be tested, veri ed and proven.
As mergers and acquisitions are part of daily practice in business, my wishes
are for this framework to be used in di erent business areas.</p>
        <p>After all, initial IT due diligence is only ones due diligence.</p>
        <p>Acknowledgments. I would like to express my thanks to my mentor, assistant
professor Marko Bajec, PhD from Faculty of Computer and Information Systems,
University of Ljubljana, who has informed me about this event, encouraged me
and given me the support.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Fitch</surname>
          </string-name>
          , P.T.:
          <article-title>Dictionary of Banking Terms 2nd edition</article-title>
          .
          <source>Barron's Educational Series</source>
          , page
          <volume>207</volume>
          (
          <year>1993</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Mazovec</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>Legal Due Diligence</article-title>
          .
          <article-title>NLB internal documentation</article-title>
          , Ljubljana (
          <year>2001</year>
          ),
          <article-title>(in Slovene language: Pravni Due Diligence</article-title>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Podlesnik</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Contents Analyses of Commercial Bank Operations</article-title>
          .
          <source>In: 6th Banking Conference - Analysis of Bank Risks</source>
          , Slovenian Economist Association, Ljubljana (
          <year>2000</year>
          ),
          <article-title>(in Slovene language: Vsebinska analiza poslovanja poslovne banke)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <source>ISACA: CISA Review Manual 2005. Information System Audit and Control Association</source>
          , (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. ISACA:
          <article-title>IS Auditing Procedures IS Risk Assessment Measurements</article-title>
          .
          <source>Information System Audit and Control Association</source>
          , (
          <year>2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <source>ITGI: COBIT 4</source>
          .
          <article-title>1: Control Objectives for Information and Related Technology</article-title>
          . IT Governance Institute, (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Gornik</surname>
          </string-name>
          , R.:
          <article-title>Operational Risk Management in Banks</article-title>
          .
          <source>MSc thesis</source>
          , University of Maribor, Maribor (
          <year>2004</year>
          ),
          <article-title>(in Slovene language: Upravljanje operativnih tveganj v informatiziranih bankah)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Gornik</surname>
          </string-name>
          , R.:
          <article-title>Operational Risk Management in Banking with Capital Accord Basel II</article-title>
          .
          <source>In: 13th International Conference of Auditing and Control of Information Systems</source>
          , Slovenian Institute for Auditing, pp.
          <fpage>125</fpage>
          -
          <lpage>148</lpage>
          , Ljubljana (
          <year>2005</year>
          ),
          <article-title>(in Slovene language: Upravljanje operativnih tveganj v bankah po novem kapitalskem sporazumu BASEL II)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9. BFIS: Basel Committee on Banking Supervision.
          <article-title>Sound Practices for the Management and Supervision of Operational Risk</article-title>
          . Bank for International Settlements, (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <article-title>Bank of Slovenia and Slovenian Banks Association: Recommendation for setting up and managing the execution of the system for managing operational risks</article-title>
          ,
          <source>Bank of Slovenia</source>
          , Ljubljana (
          <year>2005</year>
          ),
          <article-title>(in Slovene language: Priporocila za vzpostavitev in izvajanje sistema upravljanja z operativnim tveganjem)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Hardy</surname>
          </string-name>
          , G.:
          <article-title>Information Risks: Whose business are they? IT Governance institute</article-title>
          , (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Potocnik</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Risk Assessments and Risk Analysis Methods for Decision Makers</article-title>
          .
          <source>In: 12th International Conference of Auditing and Control of Information Systems</source>
          , Slovenian Institute for Auditing, pp.
          <fpage>111</fpage>
          -
          <lpage>120</lpage>
          , Ljubljana (
          <year>2004</year>
          ),
          <article-title>(in Slovene language: Analiza tveganosti za odlocanje o ravni varovanja informacij)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Gattiker</surname>
          </string-name>
          , U.E.:
          <article-title>Merger and Acquisition E ective Information Security Depends on Security Metrics</article-title>
          .
          <source>ISACA Information System Control Journal 5</source>
          , pp.
          <fpage>51</fpage>
          -
          <lpage>56</lpage>
          , (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Hevner</surname>
            ,
            <given-names>A.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>March</surname>
          </string-name>
          , S.T.,
          <string-name>
            <surname>Park</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ram</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Design Science in Information System Research</article-title>
          .
          <source>MIS Quarterly</source>
          <volume>28</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>75</fpage>
          -
          <lpage>105</lpage>
          , (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Orlikowski</surname>
            ,
            <given-names>J.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Iacono</surname>
            ,
            <given-names>C.S.</given-names>
          </string-name>
          : Research Commentary:
          <article-title>Desperately Seeking the "IT" in IT Research - A Call to Theorizing the IT Artifact</article-title>
          .
          <source>Information System Research</source>
          <volume>12</volume>
          (
          <issue>3</issue>
          ), pp.
          <fpage>121</fpage>
          -
          <lpage>134</lpage>
          , (
          <year>June 2001</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Alter</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>18 Reasons why IT-reliant work system should replace the IT Artifact as the core subject matter of the IS Field</article-title>
          .
          <source>Communications of the Association for Information Systems 12</source>
          , pp.
          <fpage>366</fpage>
          -
          <lpage>395</lpage>
          , (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Benbaset</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zmud</surname>
            ,
            <given-names>W.R.</given-names>
          </string-name>
          :
          <source>Empirical Research in Information Systems: The Practice of Relevance. MIS Quarterly</source>
          <volume>23</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>3</fpage>
          -
          <lpage>16</lpage>
          , (
          <year>March 1999</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Zmud</surname>
            ,
            <given-names>W.R.</given-names>
          </string-name>
          :
          <source>Conducting and Publishing Practice-Driven Research. In: IFIP Working groups 8.2 and 8.6 joint Working Conference on Information Systems: Current Issues and Future Changes</source>
          , Helsinki, (
          <year>December 1998</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Bhatia</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <string-name>
            <given-names>IT</given-names>
            <surname>Merger Due Diligence A Blueprint</surname>
          </string-name>
          .
          <source>Information System Control Journal 1</source>
          , pp.
          <fpage>46</fpage>
          -
          <lpage>49</lpage>
          (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20. BCI:
          <article-title>The ten certi cation standard for Business Continuity Practitioners, The Business Continuity Institute</article-title>
          , (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <string-name>
            <surname>Bajec</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Using COBIT as a Model for Delivering a Complete IT Process Review as a Part of the IT/IS Strategy Planning</article-title>
          .
          <source>In: 14th International Conference of Auditing and Control of Information Systems</source>
          , Slovenian Institute for Auditing, pp.
          <fpage>223</fpage>
          -
          <lpage>236</lpage>
          , Ljubljana (
          <year>2006</year>
          ),
          <article-title>(in Slovene language: Uporaba modela COBIT za celovit pregled IT postopkov v okviru strateskega nacrtovanja informatike)</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Akoka</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Comyn-Wattiau</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          :
          <article-title>A Knowledge-Based System for Auditing Computer and Management Information Systems. A Knowledge-Based System for Auditing Computer</article-title>
          and
          <source>Management Information System</source>
          <volume>11</volume>
          (
          <issue>3</issue>
          ), pp.
          <fpage>361</fpage>
          -
          <lpage>375</lpage>
          , (
          <year>1996</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Sundberg</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tan</surname>
            ,
            <given-names>Z-D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Baublits</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stanis</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tandriverdi</surname>
          </string-name>
          , H.:
          <article-title>A Framework for Conducting IT Due Diligence in Mergers and Acquisitions</article-title>
          .
          <source>ISACA Information System Control Journal Online</source>
          <volume>6</volume>
          , (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          24.
          <string-name>
            <surname>Baublits</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lee</surname>
            ,
            <given-names>H.H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stanis</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sundberg</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tan</surname>
            ,
            <given-names>Z-D.</given-names>
          </string-name>
          :
          <article-title>Development of an IT Assessment Program for Acquisition. Final Report of the student project in the IT Audit and Security Course at the Red McCombs Business School</article-title>
          of the University of Texas at Austin (USA), (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          25.
          <string-name>
            <surname>VanGrembergen</surname>
          </string-name>
          , W.:
          <article-title>The Balanced Scorecard and IT Governance</article-title>
          .
          <source>ISACA Information System Control Journal</source>
          <volume>2</volume>
          , (
          <year>2000</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          26.
          <string-name>
            <surname>Umek</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Use of Risk Assessment Methods and Tools</article-title>
          .
          <source>In: 12th International Conference of Auditing and Control of Information Systems</source>
          , Slovenian Institute for Auditing, pp.
          <fpage>99</fpage>
          -
          <lpage>110</lpage>
          , Ljubljana (
          <year>2004</year>
          ),
          <article-title>(in Slovene language: Uporaba metod in orodij pri obvladovanju tveganj)</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>