...
首页> 外文期刊>Information Technology >Towards data-driven decision support for organizational IT security audits
【24h】

Towards data-driven decision support for organizational IT security audits

机译:迈向数据驱动的决策支持,使组织IT安全审核

获取原文
获取原文并翻译 | 示例
           

摘要

As the IT landscape of organizations increasingly needs to comply with various laws and regulations, organizations manage a plethora of security-related data and have to verify the adequacy and effectiveness of their security controls through internal and external audits. Existing Governance, Risk and Compliance (GRC) approaches provide little support for auditors or are tailored to the needs of auditors and do not fully support required management activities of the auditee. To address this gap and move towards a holistic solution, a data-driven approach is proposed. Following the design science research paradigm, a data-driven approach for audit data management and analytics that addresses organizational needs as well as requirements for audit data analytics was developed. We contribute workflow support and associated data models to support auditing and security decision making processes. The evaluation shows the viability of the proposed IT artifact and its potential to reduce costs and complexity of security management processes and IT security audits. By developing a model and associated decision support workflows for the entire IT security audit lifecycle, we present a solution for both the auditee and the auditor. This is useful to developers of GRC tools, vendors, auditors and organizational decision makers.
机译:由于组织的IT景观越来越需要遵守各种法律法规,组织管理一流的安全相关数据,并且必须通过内部和外部审计验证其安全控制的充分性和有效性。现有的治理,风险和合规(GRC)方法对审计师提供很少的支持,或者根据审计员的需求量身定制,并没有完全支持审计员所需的管理活动。为了解决这个差距并朝向整体解决方案移动,提出了一种数据驱动方法。遵循设计科学研究范式,开发了一种解决组织需求的审计数据管理和分析的数据驱动方法以及对审计数据分析的要求。我们为支持审计和安全决策过程提供工作流支持和相关数据模型。评估显示了提议的IT工件的可行性及其降低安全管理流程的成本和复杂性和IT安全审计的可能性。通过开发用于整个IT安全审计生命周期的模型和相关决策支持工作流,我们为审计员和审计员提供了解决方案。这对GRC工具,供应商,审计师和组织决策者的开发人员有用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号