首页> 外文期刊>International journal of knowledge management >Integrating Knowledge Management into Information Security: From Audit to Practice
【24h】

Integrating Knowledge Management into Information Security: From Audit to Practice

机译:将知识管理整合到信息安全:从审计到练习

获取原文
获取原文并翻译 | 示例
           

摘要

Repeated information security (InfoSec) incidents have harmed the confidence of people on enterprises' InfoSec capability. While most organisations adopt control frameworks such as ISO27001 and COBIT, the role and contribution of knowledge management on InfoSec was inadequately considered. The authors integrated the concepts of knowledge-centric information security and IT Governance (ITG) into an ITG-driven knowledge framework (ITGKF) for reinforcing InfoSec maturity and auditability of enterprises. The authors also tried to assess whether ITG can embrace proper knowledge circulation within the InfoSec community. The authors confirmed the positive influence of IT governance on knowledge-centric information security (KCIS) and information security maturity and audit result (ISMAR), the positive influence of KCIS on ISMAR, and the mediating role of KCIS between ITG and ISMAR. These indicated the significance of KM in InfoSec area. Based on the findings, they proposed possible changes of integrating KM in different InfoSec practices and audit standard.
机译:重复的信息安全(Infosec)事件损害了人们对企业的信息性能力的信心。虽然大多数组织采用了ISO27001和COBIT等控制框架,但考虑了知识管理的作用和贡献。作者将通过知识中心信息安全和IT治理(ITG)的概念纳入ITG驱动的知识框架(ITGKF),以加强INFOSEC成熟度和企业的审计性。作者还试图评估ITG是否可以在INFOSEC社区内拥抱正确的知识流通。作者证实了IT治理对知识中心信息安全(KCIS)和信息安全成熟度和审计结果(ISMAR)的积极影响,KCIS对ISMAR的积极影响,以及KCIS在ITG和ISMAR之间的中介作用。这些表明了IMOSEC区域的重要性。根据调查结果,他们提出了在不同的INFOSEC实践和审计标准中整合KM的变化。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号