首页> 外文期刊>Computers & Security >Shifting Information Systems Security Responsibility from User Organizations to Vendor/Publisher Organizations
【24h】

Shifting Information Systems Security Responsibility from User Organizations to Vendor/Publisher Organizations

机译:将信息系统安全责任从用户组织转移到供应商/发布者组织

获取原文
获取原文并翻译 | 示例
           

摘要

An important redefinition of responsibility for information systems security is now underway. The problem is nobody's talking about it, much less planning for it. This shift impacts information security staffing plans, information security project plans, information security architectures, and many other aspects of the information security management process. Traditionally, information systems security has been primarily the user organization's responsibility. User organizations were responsible for doing risk assessments, for identifying and implementing the controls needed to address their organization's unique risks, and for administering and maintaining these controls. While these responsibilities will not disappear, in the future user organizations will orchestrate a team made up of both inside staff members and a variety of outside organizations. Beyond the increasingly large number of outsourcing firms and independent consultants that provide information security related services, these outside team members will be information systems product vendors and information content publishers.
机译:信息系统安全责任的重要重新定义正在进行中。问题是没人在谈论它,更不用说计划了。这种转变会影响信息安全人员配备计划,信息安全项目计划,信息安全体系结构以及信息安全管理过程的许多其他方面。传统上,信息系统安全主要是用户组织的责任。用户组织负责进行风险评估,识别和实施解决组织独特风险所需的控制措施,并负责管理和维护这些控制措施。尽管这些职责不会消失,但将来用户组织将组织由内部人员和各种外部组织组成的团队。除了提供信息安全相关服务的外包公司和独立顾问的数量日益增多之外,这些外部团队成员还将是信息系统产品供应商和信息内容发行商。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号