首页> 外文会议>International Conference on Computer and Applications >Managing Information Security Risk Using Integrated Governance Risk and Compliance
【24h】

Managing Information Security Risk Using Integrated Governance Risk and Compliance

机译:使用综合治理风险和合规性管理信息安全风险

获取原文

摘要

This paper aims to demonstrate the building blocks of an IT Governance Risk and Compliance (IT GRC) model as well the phased stages of the optimal integration of IT GRC frameworks, standards and model through a longitudinal study. A qualitative longitudinal single case study methodology through multiple open-ended interviews were conducted over a period of four years (July 2012 to November 2015) in a retail financial institution. Our empirical study contributes to both academic research and practice in IT GRC. First, we identified the various building blocks of IT GRC domain from vertical as well as horizontal perspectives. Second, we methodologically demonstrated the gradual metamorphosis of the evolution of an IT GRC from a single ITG framework to multiple IT GRC building blocks. The journey thus throws light on the gradual staged process of attaining maturity in IT GRC by an organization. The resultant IT GRC model thus, guides managerial actions towards a better understanding of the positioning of IT GRC building blocks in an organization through the understanding of the interaction of vertical and horizontal domains. The results of the paper thus enable practitioners and academics to better understand and evaluate IT GRC implementation for effective governance, reduce risk and ensure compliance in organizations.
机译:本文旨在展示IT治理风险和合规性(IT GRC)模型的构建块,以及通过纵向研究的最佳集成IT GRC框架,标准和模型的相控阶段。通过多个开放式访谈的定性纵向单案研究方法是在零售金融机构(2012年7月至2015年11月)的四年内进行的。我们的实证研究有助于IT GRC的学术研究和实践。首先,我们将IT GRC域的各种构建块从垂直视角识别出来。其次,我们方法论上证明了IT GRC从单个ITG框架到多个IT GRC构建块的逐渐变态。因此,旅程抛出了一个组织在IT GRC中获得成熟度的逐步分阶段的过程。因此,所得到的IT GRC模型,通过理解垂直和水平畴的相互作用来实现对组织中IT GRC构建块的定位的管理行动。因此,本文的结果使从业者和学者能够更好地理解和评估它的GRC实施,以实现有效的治理,降低风险并确保组织的合规性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号