首页> 外文期刊>Information systems security >Selecting an IT Control Framework
【24h】

Selecting an IT Control Framework

机译:选择 IT 控制框架

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The ultimate goal in adopting a framework is to instill an attitude within the organization embodying a controls approach and improve the performance of compliance management within the organization. The adoption of a framework should not be just an infusion of "academic models" into the organization's processes. These frameworks are built on experience and validated approaches. Frameworks help lay the foundation by articulating a clear approach based on a broad range of inputs and experiences. A validated, time-tested foundation gives the organization confidence in its roots of compliance management. Furthering those frameworks into a context-sensitive, organization-aware approach for the business extends the framework to fit the internal processes and requirements. This can be done by a unified approach of policies, standards, and controls driven by a framework but customized for the organization. This approach will transform the implementation of a framework from mimicking other organizations into a truly focused program built to mature and evolve with the organization.
机译:采用框架的最终目标是在组织内灌输一种体现控制方法的态度,并提高组织内合规管理的绩效。采用框架不应只是将“学术模式”注入组织的流程。这些框架建立在经验和经过验证的方法之上。框架通过阐明基于广泛投入和经验的明确方法来帮助奠定基础。经过验证、久经考验的基础使组织对其合规管理的根源充满信心。将这些框架进一步发展为一种上下文敏感的、组织感知的业务方法,扩展了框架以适应内部流程和要求。这可以通过由框架驱动但为组织定制的策略、标准和控制的统一方法来完成。这种方法将把框架的实施从模仿其他组织转变为一个真正有针对性的计划,以与组织一起成熟和发展。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号