首页> 外文会议>Latest trends in applied informatics and computing >Governing Information System Security: Review of Approaches to Information System Security Assurance and Auditing
【24h】

Governing Information System Security: Review of Approaches to Information System Security Assurance and Auditing

机译:治理信息系统安全:审查信息系统安全保证和审计方法

获取原文
获取原文并翻译 | 示例

摘要

Over the past decade information system security issues has been treated mainly from technology perspective. That model of information security management was reactive, mainly technologically driven and rarely aligned to business needs. This paper goes a step further and considers it from the governance view, mainly aligning it with the risk management activities and stressing the necessity for a holistic approach in which the executive management should be involved. The main objective of the paper is to stress the importance of implementing information system security governance model as a proactive and holistic approach which aligns security mechanisms, procedures and metrics with governance principles, business drivers and enterprise strategic objectives. Information system security governance model is constructed, explained and discussed. Approaches to for information system security assurance are analysed and the phases and processes of its regular reviews (audits) explained in further details. The standards and legislation activities that help in that sense are evaluated. The holistic model of governing information system security risks as business risks is explained and discussed.
机译:在过去的十年中,信息系统安全问题主要从技术角度进行了处理。信息安全管理模型是被动的,主要是技术驱动的,很少满足业务需求。本文更进了一步,从治理的角度进行了研究,主要是使其与风险管理活动保持一致,并强调了采取一种包括执行管理人员在内的整体方法的必要性。本文的主要目的是强调实施信息系统安全性治理模型的重要性,这种模型是一种主动的整体方法,可将安全性机制,过程和度量标准与治理原则,业务驱动力和企业战略目标保持一致。信息系统安全治理模型的构建,解释和讨论。分析了用于信息系统安全保证的方法,并进一步详细解释了其定期检查(审核)的阶段和过程。对在这种意义上有帮助的标准和立法活动进行了评估。解释和讨论了将信息系统安全风险作为业务风险进行管理的整体模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号