Information security governance and how to accomplish it

作者: Ivan Sedinic , Mario Sajko , Nikola Hadjina

DOI:

关键词:

摘要: The risks and costs of information security, numerous external internal requirements obligations to customers, are the reason for interest security at highest level in companies. A set activities which describes involvement management board, executive management, specialized committees, ad-hoc groups managers is referred as Security Governance. While principles governance relatively defined, universally accepted methodology its introduction business environment missing. This raises question whether there a connection between other concepts good practices field IT with Outlining process corporate reference aims this work.

参考文章(2)
Julia H. Allen, Jody R. Westby, Governing for Enterprise Security (GES) Implementation Guide Carnegie Mellon University. ,(2007) , 10.1184/R1/6574010.V1
Richard A. Caralli, Managing for Enterprise Security Carnegie Mellon University. ,(2004) , 10.1184/R1/6575252.V1