{"id":{"repo_id":"lsu-thes","oai_identifier":"oai:repository.lsu.edu:gradschool_dissertations-2206"},"canonical_url":"https://search.dev.ndltd.org/etd/lsu-thes/oai:repository.lsu.edu:gradschool_dissertations-2206","repository":{"repo_id":"lsu-thes","name":"Lousiana State University","base_url":"https://repository.lsu.edu/do/oai/"},"display":{"title":"IT governance in small and medium enterprise post Sarbanes Oxley","abstract":"The history of IT governance research has been dichotomous in that research either focused on the IT governance structural arrangements or the contingencies that affect IT organizational decisions. Weill and Ross’s (2004) seminal text on IT governance represents a synthesis of these two streams of research and thus establishes a new trajectory in the discourse related to IT governance. Their study included analysis from both survey data and case studies. However, the case study sites included were of large capitalized companies. Moreover, the cases were conducted prior to the mandated implementation of Section 404 of Sarbanes Oxley (SOX), which oversees the requirements for companies to ensure they have adequate controls in place to safeguard financial data and reporting. Compliance efforts with SOX have disproportionately impacted the finances of small publicly traded companies; consequently, the compliance efforts of small and medium publicly traded companies may differ from that of large companies. Most small companies have taken SOX seriously and complied with the requirements mandated by the legislation by implementing the controls that demonstrate that the organization has reasonable assurance of governance over the company’s IT function. Still other small companies have chosen to use SOX as a catalyst for systemic change throughout the company’s IT function. While the latter may seem the logical progression of a company’s IT governance effort, that is not always the case. This study seeks to understand the reasons behind why some companies extend compliance efforts to invoke positive systemic change while others only do enough to comply with regulatory requirements. Using a multiple-case methodology, this study attempts to build upon the existing body of IT governance research by examining how the aforementioned IT governance concepts discussed by Weill and Ross are manifest in small and medium publicly traded companies. Additionally, the reason(s) why or why not those concepts may be present is examined using the theoretical lens of institutional theory. Findings of the study include an identification of differences small and medium publicly traded companies and large publicly traded companies in establishing enterprise-wide IT governance.","abstract_html":"The history of IT governance research has been dichotomous in that research either focused on the IT governance structural arrangements or the contingencies that affect IT organizational decisions. Weill and Ross’s (2004) seminal text on IT governance represents a synthesis of these two streams of research and thus establishes a new trajectory in the discourse related to IT governance. Their study included analysis from both survey data and case studies. However, the case study sites included were of large capitalized companies. Moreover, the cases were conducted prior to the mandated implementation of Section 404 of Sarbanes Oxley (SOX), which oversees the requirements for companies to ensure they have adequate controls in place to safeguard financial data and reporting. Compliance efforts with SOX have disproportionately impacted the finances of small publicly traded companies; consequently, the compliance efforts of small and medium publicly traded companies may differ from that of large companies. Most small companies have taken SOX seriously and complied with the requirements mandated by the legislation by implementing the controls that demonstrate that the organization has reasonable assurance of governance over the company’s IT function. Still other small companies have chosen to use SOX as a catalyst for systemic change throughout the company’s IT function. While the latter may seem the logical progression of a company’s IT governance effort, that is not always the case. This study seeks to understand the reasons behind why some companies extend compliance efforts to invoke positive systemic change while others only do enough to comply with regulatory requirements. Using a multiple-case methodology, this study attempts to build upon the existing body of IT governance research by examining how the aforementioned IT governance concepts discussed by Weill and Ross are manifest in small and medium publicly traded companies. Additionally, the reason(s) why or why not those concepts may be present is examined using the theoretical lens of institutional theory. Findings of the study include an identification of differences small and medium publicly traded companies and large publicly traded companies in establishing enterprise-wide IT governance.","abstract_has_math":false,"creators":["Thomas, Carlos Anthony"],"institution":"Information Systems and Decision Sciences (Business Administration)","degree_name":"Doctor of Philosophy (PhD)","degree_level":"Dissertation","degree_discipline":"Business","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2010,"date_issued":"2010-01-01T08:00:00Z","date_published":"2010-01-01T08:00:00Z","updated_at":"2026-07-24T02:59:15Z","subjects":["IT governance","Sarbanes Oxley","case study"],"languages":[],"rights":["unrestricted","Release the entire work immediately for access worldwide."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["etd-01182010-210857","https://repository.lsu.edu/gradschool_dissertations/1207"],"render_values":[{"text":"etd-01182010-210857","href":null,"code":true},{"text":"https://repository.lsu.edu/gradschool_dissertations/1207","href":"https://repository.lsu.edu/gradschool_dissertations/1207","code":true}]}]},"links":{"outbound_url":"https://doi.org/10.31390/gradschool_dissertations.1207","outbound_label":"DOI","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Thomas, Carlos Anthony"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2009-12-11"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2022-05-12T23:11:22Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Business"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy (PhD)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Information Systems and Decision Sciences (Business Administration)"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["IT governance","Sarbanes Oxley","case study"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["unrestricted","Release the entire work immediately for access worldwide."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["etd-01182010-210857","10.31390/gradschool_dissertations.1207","https://repository.lsu.edu/gradschool_dissertations/1207"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The history of IT governance research has been dichotomous in that research either focused on the IT governance structural arrangements or the contingencies that affect IT organizational decisions. Weill and Ross’s (2004) seminal text on IT governance represents a synthesis of these two streams of research and thus establishes a new trajectory in the discourse related to IT governance. Their study included analysis from both survey data and case studies. However, the case study sites included were of large capitalized companies. Moreover, the cases were conducted prior to the mandated implementation of Section 404 of Sarbanes Oxley (SOX), which oversees the requirements for companies to ensure they have adequate controls in place to safeguard financial data and reporting. Compliance efforts with SOX have disproportionately impacted the finances of small publicly traded companies; consequently, the compliance efforts of small and medium publicly traded companies may differ from that of large companies. Most small companies have taken SOX seriously and complied with the requirements mandated by the legislation by implementing the controls that demonstrate that the organization has reasonable assurance of governance over the company’s IT function. Still other small companies have chosen to use SOX as a catalyst for systemic change throughout the company’s IT function. While the latter may seem the logical progression of a company’s IT governance effort, that is not always the case. This study seeks to understand the reasons behind why some companies extend compliance efforts to invoke positive systemic change while others only do enough to comply with regulatory requirements. Using a multiple-case methodology, this study attempts to build upon the existing body of IT governance research by examining how the aforementioned IT governance concepts discussed by Weill and Ross are manifest in small and medium publicly traded companies. Additionally, the reason(s) why or why not those concepts may be present is examined using the theoretical lens of institutional theory. Findings of the study include an identification of differences small and medium publicly traded companies and large publicly traded companies in establishing enterprise-wide IT governance."]},{"key":"dc:title","label":"Title","values":["IT governance in small and medium enterprise post Sarbanes Oxley"]}]}],"canonical_facts":{"dc:creator":["Thomas, Carlos Anthony"],"dc:date":["2009-12-11"],"dc:date.available":["2022-05-12T23:11:22Z"],"dc:description.abstract":["The history of IT governance research has been dichotomous in that research either focused on the IT governance structural arrangements or the contingencies that affect IT organizational decisions. Weill and Ross’s (2004) seminal text on IT governance represents a synthesis of these two streams of research and thus establishes a new trajectory in the discourse related to IT governance. Their study included analysis from both survey data and case studies. However, the case study sites included were of large capitalized companies. Moreover, the cases were conducted prior to the mandated implementation of Section 404 of Sarbanes Oxley (SOX), which oversees the requirements for companies to ensure they have adequate controls in place to safeguard financial data and reporting. Compliance efforts with SOX have disproportionately impacted the finances of small publicly traded companies; consequently, the compliance efforts of small and medium publicly traded companies may differ from that of large companies. Most small companies have taken SOX seriously and complied with the requirements mandated by the legislation by implementing the controls that demonstrate that the organization has reasonable assurance of governance over the company’s IT function. Still other small companies have chosen to use SOX as a catalyst for systemic change throughout the company’s IT function. While the latter may seem the logical progression of a company’s IT governance effort, that is not always the case. This study seeks to understand the reasons behind why some companies extend compliance efforts to invoke positive systemic change while others only do enough to comply with regulatory requirements. Using a multiple-case methodology, this study attempts to build upon the existing body of IT governance research by examining how the aforementioned IT governance concepts discussed by Weill and Ross are manifest in small and medium publicly traded companies. Additionally, the reason(s) why or why not those concepts may be present is examined using the theoretical lens of institutional theory. Findings of the study include an identification of differences small and medium publicly traded companies and large publicly traded companies in establishing enterprise-wide IT governance."],"dc:identifier":["etd-01182010-210857","10.31390/gradschool_dissertations.1207","https://repository.lsu.edu/gradschool_dissertations/1207"],"dc:rights":["unrestricted","Release the entire work immediately for access worldwide."],"dc:subject":["IT governance","Sarbanes Oxley","case study"],"dc:title":["IT governance in small and medium enterprise post Sarbanes Oxley"],"thesis:degree_discipline":["Business"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Doctor of Philosophy (PhD)"],"thesis:institution_name":["Information Systems and Decision Sciences (Business Administration)"]},"updated_at":"2026-07-24T02:59:15Z"}