首页> 外文期刊>Communications of the Association for Information Systems >Developments in Practice XXXIII: A Holistic Approach to Managing IT-based Risk
【24h】

Developments in Practice XXXIII: A Holistic Approach to Managing IT-based Risk

机译:实践中的发展XXXIII:管理基于IT的风险的整体方法

获取原文
           

摘要

Not long ago, IT-based risk was a fairly low-key activity focused on whether IT could deliver projects successfully and keep applications up and running. But with the opening up of the organization’s boundaries to external partners, service providers, external electronic communications, and online services, managing IT-based risk has morphed into a “bet the company” proposition. Not only is the scope of the job bigger, the stakes are much higher. As companies have become more dependent on IT for everything they do, the costs of service disruption and inadequate security practices have escalated exponentially. Therefore, the job of managing IT-based risk has become broader and more complex. Whereas in the past companies have sought security through physical or technological means (e.g., locked rooms, virus scanners), there is now growing understanding that managing IT-based risk must be a strategic and holistic activity that is not just the responsibility of a small group of IT specialists, but part of a mindset that extends from partners and suppliers to employees and customers. This paper explores how organizations are addressing and coping with increasing IT-based risk. It presents the results of an in-depth discussion of this issue with 20 senior IT practitioners and the challenges facing them. It proposes a holistic view of risk and examines the characteristics and components needed to develop an effective risk management framework, presenting a generic framework for integrating the growing number of elements involved in it. Finally, it describes successful practices organizations could use for improving their risk management capabilities.
机译:不久以前,基于IT的风险是一项相当低调的活动,专注于IT是否可以成功交付项目并保持应用程序正常运行。但是,随着组织对外部合作伙伴,服务提供商,外部电子通信和在线服务的界限的开放,基于IT的风险管理已演变为“下注公司”的提议。不仅工作范围更大,而且赌注也更高。随着公司在做任何事情时都越来越依赖于IT,服务中断的成本和不充分的安全措施已经成倍增加。因此,管理基于IT的风险的工作变得越来越广泛和复杂。过去,公司通过物理或技术手段(例如,上锁的房间,病毒扫描仪)寻求安全性,但现在人们越来越认识到,管理基于IT的风险必须是一项战略性的整体活动,而不仅仅是小规模的责任由IT专家组成的小组,但思维方式的一部分从合作伙伴和供应商延伸到员工和客户。本文探讨组织如何应对和应对日益增加的基于IT的风险。它提供了与20位资深IT从业人员深入讨论此问题的结果以及他们面临的挑战。它提出了对风险的整体看法,并研究了开发有效的风险管理框架所需的特征和组成部分,并提出了一个通用框架来整合其中涉及的越来越多的要素。最后,它描述了组织可以用来改进其风险管理能力的成功实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号