IT安全和IT治理一致性:回顾

Norli Shariffuddin, A. Mohamed
{"title":"IT安全和IT治理一致性:回顾","authors":"Norli Shariffuddin, A. Mohamed","doi":"10.1145/3386723.3387843","DOIUrl":null,"url":null,"abstract":"This paper review and align IT Security (ITS) and IT Governance (ITG) that would address ITS strategic and its operational issues. These issues if not addressed accordingly, would lead to a financial aftermath that would put the business at risk and jeopardize the organization's sustainability in both short and long run. There have been studies that show, the lack of technical controls, lack of solid governance and improper oversight at the enterprise stakeholders' level would result to disastrous events. Thus, ITS and ITG has to go hand in hand in order to fortify the security posture of an enterprise. The goal is to roll out an ITS program that would have the best of ITG and ITS best practices. Rather than reinventing the wheel, the affected managers or organizations can adopt and adapt the existing frameworks available easily. There are a few common frameworks available, however there is lack of essential elements especially on ITS management and technical controls. This paper will look into these common ITS frameworks and lists its shortcomings to further understand the need for a better framework. In addition, frameworks that govern ITG will also be studied looking at its advantages and disadvantages. Thus, elements from ITS frameworks will be identified, analyzed and certain aspects extracted as common themes. The analysis shows, the themes depicted are strong management support, fit for purpose context that suits the organization, essential risk management, clearly defined of roles and responsibilities, the importance of training and awareness and the implementation of a quick win strategy. These five themes will be put into ITG practice blocks with respect to the Structure, Process and Relational Mechanisms that spans across People, Process and Technology domains. Finally, the construct named NORLI is proposed to align both ITG and ITS. In the future, NORLI will be tested for its ease of use, effectiveness and efficiency.","PeriodicalId":139072,"journal":{"name":"Proceedings of the 3rd International Conference on Networking, Information Systems & Security","volume":"70 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-03-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"IT Security and IT Governance Alignment: A Review\",\"authors\":\"Norli Shariffuddin, A. Mohamed\",\"doi\":\"10.1145/3386723.3387843\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This paper review and align IT Security (ITS) and IT Governance (ITG) that would address ITS strategic and its operational issues. These issues if not addressed accordingly, would lead to a financial aftermath that would put the business at risk and jeopardize the organization's sustainability in both short and long run. There have been studies that show, the lack of technical controls, lack of solid governance and improper oversight at the enterprise stakeholders' level would result to disastrous events. Thus, ITS and ITG has to go hand in hand in order to fortify the security posture of an enterprise. The goal is to roll out an ITS program that would have the best of ITG and ITS best practices. Rather than reinventing the wheel, the affected managers or organizations can adopt and adapt the existing frameworks available easily. There are a few common frameworks available, however there is lack of essential elements especially on ITS management and technical controls. This paper will look into these common ITS frameworks and lists its shortcomings to further understand the need for a better framework. In addition, frameworks that govern ITG will also be studied looking at its advantages and disadvantages. Thus, elements from ITS frameworks will be identified, analyzed and certain aspects extracted as common themes. The analysis shows, the themes depicted are strong management support, fit for purpose context that suits the organization, essential risk management, clearly defined of roles and responsibilities, the importance of training and awareness and the implementation of a quick win strategy. These five themes will be put into ITG practice blocks with respect to the Structure, Process and Relational Mechanisms that spans across People, Process and Technology domains. Finally, the construct named NORLI is proposed to align both ITG and ITS. In the future, NORLI will be tested for its ease of use, effectiveness and efficiency.\",\"PeriodicalId\":139072,\"journal\":{\"name\":\"Proceedings of the 3rd International Conference on Networking, Information Systems & Security\",\"volume\":\"70 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-03-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 3rd International Conference on Networking, Information Systems & Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3386723.3387843\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 3rd International Conference on Networking, Information Systems & Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3386723.3387843","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

本文回顾并调整了IT安全(ITS)和IT治理(ITG),它们将解决ITS的战略和操作问题。这些问题如果没有得到相应的解决,将导致财务后果,使业务处于风险之中,并危及组织的短期和长期可持续性。有研究表明,在企业利益相关者层面,缺乏技术控制,缺乏坚实的治理和不当的监督会导致灾难性事件。因此,为了加强企业的安全态势,ITS和ITG必须携手并进。目标是推出一个具有ITG和ITS最佳实践的最佳ITS程序。受影响的管理人员或组织可以轻松地采用和调整现有的框架,而不是重新发明轮子。有一些通用框架可用,但是缺乏基本元素,特别是在ITS管理和技术控制方面。本文将研究这些常见的ITS框架,并列出其缺点,以进一步了解对更好框架的需求。此外,还将研究管理ITG的框架,以了解其优点和缺点。因此,将识别、分析ITS框架中的元素,并提取某些方面作为共同主题。分析表明,所描述的主题是强有力的管理支持,适合组织的目的背景,必要的风险管理,明确定义的角色和责任,培训和意识的重要性以及实施快速取胜战略。这五个主题将放在ITG实践块中,涉及跨越人员、过程和技术领域的结构、过程和关系机制。最后,提出了将ITG和ITS结合起来的NORLI结构。在未来,NORLI将测试其易用性,有效性和效率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
IT Security and IT Governance Alignment: A Review
This paper review and align IT Security (ITS) and IT Governance (ITG) that would address ITS strategic and its operational issues. These issues if not addressed accordingly, would lead to a financial aftermath that would put the business at risk and jeopardize the organization's sustainability in both short and long run. There have been studies that show, the lack of technical controls, lack of solid governance and improper oversight at the enterprise stakeholders' level would result to disastrous events. Thus, ITS and ITG has to go hand in hand in order to fortify the security posture of an enterprise. The goal is to roll out an ITS program that would have the best of ITG and ITS best practices. Rather than reinventing the wheel, the affected managers or organizations can adopt and adapt the existing frameworks available easily. There are a few common frameworks available, however there is lack of essential elements especially on ITS management and technical controls. This paper will look into these common ITS frameworks and lists its shortcomings to further understand the need for a better framework. In addition, frameworks that govern ITG will also be studied looking at its advantages and disadvantages. Thus, elements from ITS frameworks will be identified, analyzed and certain aspects extracted as common themes. The analysis shows, the themes depicted are strong management support, fit for purpose context that suits the organization, essential risk management, clearly defined of roles and responsibilities, the importance of training and awareness and the implementation of a quick win strategy. These five themes will be put into ITG practice blocks with respect to the Structure, Process and Relational Mechanisms that spans across People, Process and Technology domains. Finally, the construct named NORLI is proposed to align both ITG and ITS. In the future, NORLI will be tested for its ease of use, effectiveness and efficiency.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信