...
首页> 外文期刊>International Journal of Cyber Warfare and Terrorism >Commissioning Development to Externals: Addressing Infosec Risks Upfront
【24h】

Commissioning Development to Externals: Addressing Infosec Risks Upfront

机译:调试到外部的开发:通过前期解决Infosec风险

获取原文
获取原文并翻译 | 示例

摘要

Bringing externals in the critical business processes and having them assume some or all of the responsibilities associated with the critical business functions comes with information security risks whose impact, if materialized, could be disastrous for business and therefore warrants a meticulous and holistic approach for managing those risks. Compounded with the engagement of externals in the development process, risks facing a development project require robust risk management by the outsourcing organization. The organization should be able influence the security behavior of those externals and induce them to comply with certain secure development principles and practices. Delving deep into those risks brought about by suppliers, this study aims at offering a methodology in addressing the risks associated with commissioning some or all components of a would-be-developed product to externals and shows how those risks can be mitigated by controlling the security behavior of suppliers through well-tailored contractual provisions.
机译:在关键业务流程中带来外部,并让他们假设与关键业务职能相关的一些或所有职责都具有信息安全风险,其影响,如果物化,可能对企业令人灾难性,因此保证了管理这些细致和整体方法风险。在开发过程中的外部参与中,面临发展项目的风险需要外包组织的强大风险管理。该组织应该能够影响那些外部的安全行为,并促使他们遵守某些安全的发展原则和实践。本研究旨在深入了解供应商带来的风险,旨在提供一种方法来解决与将潜在产品的一些或所有组成部分相关联的风险,并展示如何通过控制安全来缓解这些风险供应商通过定制的合同规定行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号