{"title":"最大化信息安全项目的投资回报:项目治理和度量","authors":"Cezar Drugescu, Rafael Etges","doi":"10.1080/10658980601051482","DOIUrl":null,"url":null,"abstract":"Abstract This article provides a discussion of the way organizations currently seek to effectively evaluate their existing information security initiatives and to build realistic business cases to increase executive awareness of risk and regulatory compliance, and, therefore, to secure budgets for new expenditures on internal controls.","PeriodicalId":36738,"journal":{"name":"Journal of Information Systems Security","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2006-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":"{\"title\":\"Maximizing the Return on Investment on Information Security Programs: Program Governance and Metrics\",\"authors\":\"Cezar Drugescu, Rafael Etges\",\"doi\":\"10.1080/10658980601051482\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Abstract This article provides a discussion of the way organizations currently seek to effectively evaluate their existing information security initiatives and to build realistic business cases to increase executive awareness of risk and regulatory compliance, and, therefore, to secure budgets for new expenditures on internal controls.\",\"PeriodicalId\":36738,\"journal\":{\"name\":\"Journal of Information Systems Security\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2006-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"10\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Systems Security\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1080/10658980601051482\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q4\",\"JCRName\":\"Social Sciences\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Systems Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/10658980601051482","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"Social Sciences","Score":null,"Total":0}
Maximizing the Return on Investment on Information Security Programs: Program Governance and Metrics
Abstract This article provides a discussion of the way organizations currently seek to effectively evaluate their existing information security initiatives and to build realistic business cases to increase executive awareness of risk and regulatory compliance, and, therefore, to secure budgets for new expenditures on internal controls.