建议的框架:信息技术风险管理的原则和实践拨款

Urairat Maneerattanasak, Nitaya Wongpinunwatana
{"title":"建议的框架:信息技术风险管理的原则和实践拨款","authors":"Urairat Maneerattanasak, Nitaya Wongpinunwatana","doi":"10.1109/ICRIIS.2017.8002513","DOIUrl":null,"url":null,"abstract":"This study proposed the appropriation for principle and practice in information technology risk management (ITRM). Due to the various patterns of cyber threat against the advanced information systems and technologies, the well-practiced ITRM is expected from an organization's stakeholders. The well-established principle is the starting point of the practice. The methodology employed in this study is the theoretical review of relevant theories such as principle, practice and task-technology fit, and the review of general ITRM principle and framework documents. Additionally, content analysis method is applied to obtain keywords and classified into groups as derived success factors. The derived success factors for the appropriation consist of a suitable general principle and framework, an organization's well-established principle, a well-designed process, team structure, expertise of team, level of task complexity, and level of interdependence. Additionally, strong risk culture, good communication, training, and tools and techniques. The contribution of the proposed framework is to provide the factors for the appropriate assessment in ITRM principle development and practice.","PeriodicalId":384130,"journal":{"name":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","volume":"17 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"A proposed framework: An appropriation for principle and practice in information technology risk management\",\"authors\":\"Urairat Maneerattanasak, Nitaya Wongpinunwatana\",\"doi\":\"10.1109/ICRIIS.2017.8002513\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This study proposed the appropriation for principle and practice in information technology risk management (ITRM). Due to the various patterns of cyber threat against the advanced information systems and technologies, the well-practiced ITRM is expected from an organization's stakeholders. The well-established principle is the starting point of the practice. The methodology employed in this study is the theoretical review of relevant theories such as principle, practice and task-technology fit, and the review of general ITRM principle and framework documents. Additionally, content analysis method is applied to obtain keywords and classified into groups as derived success factors. The derived success factors for the appropriation consist of a suitable general principle and framework, an organization's well-established principle, a well-designed process, team structure, expertise of team, level of task complexity, and level of interdependence. Additionally, strong risk culture, good communication, training, and tools and techniques. The contribution of the proposed framework is to provide the factors for the appropriate assessment in ITRM principle development and practice.\",\"PeriodicalId\":384130,\"journal\":{\"name\":\"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)\",\"volume\":\"17 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICRIIS.2017.8002513\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference on Research and Innovation in Information Systems (ICRIIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICRIIS.2017.8002513","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

本研究提出资讯科技风险管理(ITRM)的原则与实务。由于针对先进信息系统和技术的各种网络威胁模式,组织的利益相关者期望良好实践的ITRM。既定的原则是实践的起点。本研究采用的方法是对原则、实践、任务-技术契合等相关理论的理论回顾,以及对一般ITRM原则和框架文献的回顾。另外,运用内容分析法获得关键词,并将关键词分组作为衍生成功因素。拨款的成功因素包括合适的一般原则和框架、组织已建立的原则、设计良好的过程、团队结构、团队的专业知识、任务复杂程度和相互依赖程度。此外,强烈的风险文化,良好的沟通,培训,工具和技术。建议的框架的贡献是为ITRM原则的发展和实践提供适当的评估因素。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A proposed framework: An appropriation for principle and practice in information technology risk management
This study proposed the appropriation for principle and practice in information technology risk management (ITRM). Due to the various patterns of cyber threat against the advanced information systems and technologies, the well-practiced ITRM is expected from an organization's stakeholders. The well-established principle is the starting point of the practice. The methodology employed in this study is the theoretical review of relevant theories such as principle, practice and task-technology fit, and the review of general ITRM principle and framework documents. Additionally, content analysis method is applied to obtain keywords and classified into groups as derived success factors. The derived success factors for the appropriation consist of a suitable general principle and framework, an organization's well-established principle, a well-designed process, team structure, expertise of team, level of task complexity, and level of interdependence. Additionally, strong risk culture, good communication, training, and tools and techniques. The contribution of the proposed framework is to provide the factors for the appropriate assessment in ITRM principle development and practice.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信