首页> 外文会议>IEEE International Conference on Enabling Technologies >A new approach of information system security governance: A proposition of the continuous improvement process model of information system security risk management: 4D-ISS
【24h】

A new approach of information system security governance: A proposition of the continuous improvement process model of information system security risk management: 4D-ISS

机译:一种新的信息系统安全治理方法:信息系统安全风险管理持续改进过程模型的命题:4D-IS

获取原文

摘要

nowadays the information system security (ISS) has become the main lever of the world economy, it is the keystone for the creation of value, and its unavailability has an undeniable technical, human and financial impact. Mastering this discipline, comes down to three pillars (1) securing the content of the risks to which it is exposed (Risk Management of the ISS, ISSRM), (2) defining the stakeholders that contribute to its management and its governance (Governance of the ISS, ISSG) and (3) complying with the regulations in force, law, standards and contractual obligations (Compliance Management of ISS, ISSCM). Satisfying this structure, means developing a holistic approach of ISS governance (ISSG) across the entire target organization. The ISSG that have emerged lately in the world of business and information technology remains a difficult subject to demystify. To develop this approach it is essential to handle the three disciplines each as a separate entity, which will constitute the main building blocks of a new ISSG concept. Then, explore the synergies of their cohabitations in a transverse way, in order to guarantee the business profits. This article focuses on the first brick of our ISSG Framework; which is the ISSRM, by the proposing a new model of process, called 4D-ISS. This model breaks down into four phases named respectively, Define, Direct, Deploy and Decide. This work also proposes the conceptualizing of its deployment using the Business Process Modeling Notation (BPMN), defining the requirements for its implementation, and giving future actions to explore.
机译:如今,信息系统安全(ISS)已成为世界经济的主要杠杆,它是创造价值的基石,它的可用性有一个不可否认的技术,人力和财务影响。掌握这门学科,归结为三大支柱(1)固定到其所暴露(国际空间站,ISSRM的风险管理),风险(2)的内容,规定有助于其管理中的利益相关者及其治理(治理国际空间站,ISSG)和(3)现行,法律,标准和合同义务(ISS的合规性管理,ISSCM)的法规。满足这种结构,意味着开发ISS治理(ISSG)整个目标组织的整体方法。在业务和信息技术的世界已经出现了最近仍然ISSG一个棘手的问题神秘化。制定本办法有必要处理三个学科各为一个独立的实体,这将构成一个新的概念ISSG的主要组成部分。然后,探索其在横向的方式同居的协同效应,以保证业务的利润。本文重点介绍我们ISSG框架的第一块砖;这是ISSRM,通过工艺的建议新的模型,称为4D-ISS。该模型分解成分别命名为四个阶段,定义,直接,部署和决定。这项工作也提出了使用业务流程建模符号(BPMN),其部署的概念化,定义及其实施要求,并给予未来的行动去探索。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号