首页> 外文学位 >An investigation of a COBIT systems security IT governance initiative in higher education.
【24h】

An investigation of a COBIT systems security IT governance initiative in higher education.

机译:对高等教育中的COBIT系统安全IT治理计划的调查。

获取原文
获取原文并翻译 | 示例

摘要

The problem investigated, in this study, was the difficulty in implementing COBIT's Systems Security, an Information Technology governance program, at South Louisiana Community College (SLCC). The goal of the researcher was to examine the managerial aspects of introducing COBIT's fifth Delivery and Support process (DS5), successes, and the needs of a medium sized institution of higher education. The DS5 process pertains to ensuring network security. The researcher used COBIT's critical success factors, key goal indicators, key performance indicators, maturity models, audit guidelines, and diagnostic tools. In order for the researcher to develop an overall security plan that covered the building of awareness, established clear policies and standards, identified a cost-effective and sustainable implementation, and defined monitoring and enforcement processes, potential risk was balanced with the investment in resources. The plan was also made to align with the needs of all functional areas and the willingness of each functional area to tolerate the constraints the plan introduced. Prior research and theoretical literature has contributed much to the study of IT governance programs and much had been learned. The available literature surrounds six topics pertaining to IT governance including IT management, auditing, alignment, network security, IT governance, and COBIT. An exploratory case-study design was used by the researcher to answer the research questions. The general analytical strategy that was used by the researcher to answer the research questions was the development of a descriptive framework for organizing the case-study. Despite the myriad of literature on COBIT, there existed very little rigorous research. The researcher addressed this shortage and introduced the unexplored challenges of medium sized institutions of higher learning. The researcher also provided guidance to practitioners for implementing IT governance programs to medium sized institutions of higher education.; The researcher presented conclusions from the data collected to answer the research questions. The COBIT DS5 CSFs matched the environment at SLCC with a few exceptions. The four main exceptions were listed. SLCC has accepted most of the CSFs with modifications. Seventeen positive and negative management issues surfaced during the study. The nine positive issues either enhanced the support of the CSF or facilitated enhancements to the original plan. Eight negative issues prompted change. The leadership at SLCC was willing to commit to the program, but many were not sure how they could help. Ten methods for demonstrating support were listed. SLCC used six strategies to ensure compliance. Twenty-three management needs emerged at SLCC. A list was provided that summarized these needs, quantified how often they surfaced, and explained each of them. Eight leadership needs with the potential to hinder the COBIT initiative were also listed. In addition, 16 changes during the COBIT DS5 initiative were documented. Several conclusions, practitioner implications, academic implications, and suggestions for future research were presented.
机译:在这项研究中,调查的问题是在南路易斯安那州社区学院(SLCC)实施COBIT的系统安全(信息技术治理计划)的困难。研究人员的目的是研究介绍COBIT的第五个交付和支持流程(DS5)的管理方面,成功的经验以及中型高等教育机构的需求。 DS5流程与确保网络安全有关。研究人员使用了COBIT的关键成功因素,关键目标指标,关键绩效指标,成熟度模型,审计准则和诊断工具。为了使研究人员能够制定涵盖意识建设,制定清晰的政策和标准,确定具有成本效益的可持续实施方案以及定义监控和执行流程的总体安全计划,将潜在风险与资源投资相平衡。还制定了计划,以适应所有职能领域的需求以及每个职能领域容忍计划引入的限制的意愿。先前的研究和理论文献为IT治理计划的研究做出了很大贡献,并且学到了很多东西。现有文献围绕着与IT治理有关的六个主题,包括IT管理,审计,调整,网络安全,IT治理和COBIT。研究人员使用了探索性案例研究设计来回答研究问题。研究人员用来回答研究问题的一般分析策略是开发用于组织案例研究的描述性框架。尽管有大量关于COBIT的文献,但很少进行严格的研究。研究人员解决了这一短缺问题,并介绍了中型高等院校尚未探索的挑战。研究人员还为从业人员在中型高等教育机构实施IT治理计划提供了指导。研究人员从收集到的数据中得出了结论,以回答研究问题。除了少数例外,COBIT DS5 CSF与SLCC的环境匹配。列出了四个主要例外。 SLCC已接受大多数CSF的修改。在研究过程中出现了十七个积极和消极的管理问题。这九个积极问题或者增强了CSF的支持,或者促进了对原始计划的增强。八个负面问题促使人们做出了改变。 SLCC的领导愿意参与该计划,但是许多人不确定他们将如何提供帮助。列出了十种证明支持的方法。 SLCC使用六种策略来确保合规性。 SLCC产生了23种管理需求。提供了一个列表,总结了这些需求,量化了它们出现的频率,并解释了每个需求。还列出了八种可能阻碍COBIT计划的领导能力需求。此外,在COBIT DS5计划中记录了16项更改。提出了一些结论,从业者的含义,学术意义以及对未来研究的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号