{"title":"信息安全治理概述","authors":"M. Asgarkhani, Eduardo Correia, Amitrajit Sarkar","doi":"10.1109/ICAMMAET.2017.8186666","DOIUrl":null,"url":null,"abstract":"IT Governance spans the culture, organization, policy and practices that provide for IT management and control across five key functions including Strategic Alignment, Value Delivery, Resource Management, Performance Management, and Risk Management. The risk management function is concerned with ascertaining that procedures are defined for ensuring that risks have been sufficiently managed, as well as including assessing the risk factors of IT investments. The increased use of networking solutions has meant that the key aspect of risk management function of IT Governance is focused on managing information and network security. The internet has progressed to become the common platform for connecting businesses and communities worldwide. Transferring information through the internet amid sophisticated networked systems and applications is a norm. While some previous research has identified the need for protective measures in operating networked systems, security management of information and networked systems is essential. This paper examines previous research on technology governance, risk management, and IT security management by using a broad risk management framework.","PeriodicalId":425974,"journal":{"name":"2017 International Conference on Algorithms, Methodology, Models and Applications in Emerging Technologies (ICAMMAET)","volume":"35 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"An overview of information security governance\",\"authors\":\"M. Asgarkhani, Eduardo Correia, Amitrajit Sarkar\",\"doi\":\"10.1109/ICAMMAET.2017.8186666\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"IT Governance spans the culture, organization, policy and practices that provide for IT management and control across five key functions including Strategic Alignment, Value Delivery, Resource Management, Performance Management, and Risk Management. The risk management function is concerned with ascertaining that procedures are defined for ensuring that risks have been sufficiently managed, as well as including assessing the risk factors of IT investments. The increased use of networking solutions has meant that the key aspect of risk management function of IT Governance is focused on managing information and network security. The internet has progressed to become the common platform for connecting businesses and communities worldwide. Transferring information through the internet amid sophisticated networked systems and applications is a norm. While some previous research has identified the need for protective measures in operating networked systems, security management of information and networked systems is essential. This paper examines previous research on technology governance, risk management, and IT security management by using a broad risk management framework.\",\"PeriodicalId\":425974,\"journal\":{\"name\":\"2017 International Conference on Algorithms, Methodology, Models and Applications in Emerging Technologies (ICAMMAET)\",\"volume\":\"35 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-02-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 International Conference on Algorithms, Methodology, Models and Applications in Emerging Technologies (ICAMMAET)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICAMMAET.2017.8186666\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference on Algorithms, Methodology, Models and Applications in Emerging Technologies (ICAMMAET)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICAMMAET.2017.8186666","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
IT Governance spans the culture, organization, policy and practices that provide for IT management and control across five key functions including Strategic Alignment, Value Delivery, Resource Management, Performance Management, and Risk Management. The risk management function is concerned with ascertaining that procedures are defined for ensuring that risks have been sufficiently managed, as well as including assessing the risk factors of IT investments. The increased use of networking solutions has meant that the key aspect of risk management function of IT Governance is focused on managing information and network security. The internet has progressed to become the common platform for connecting businesses and communities worldwide. Transferring information through the internet amid sophisticated networked systems and applications is a norm. While some previous research has identified the need for protective measures in operating networked systems, security management of information and networked systems is essential. This paper examines previous research on technology governance, risk management, and IT security management by using a broad risk management framework.