Risk and Compliance

Risk and Compliance
复制标题

风险与合规

DOI:
10.1002/9781119549000.ch15
复制
发表时间:
2018
期刊:
Social Science Research Network
影响因子:
--
通讯作者:
Jordan VanHoy
Jordan VanHoy
中科院分区:
--
文献类型:
--
作者:
Jordan VanHoy

文献摘要

被引文献

相似文献

许多组织都面临着复杂的风险管理问题,没有足够的能力以有重点的方式充分降低风险。研究表明,令人惊讶的是,57%的高级管理人员将“风险和合规”列为他们觉得最不准备解决的两大类别(量化,2019年,第1段)。因此,只有6%的董事相信他们的组织正在有效地管理风险(Guis,Mieszala,Panayiotou&Amp;Poppensieker,2018年,第4段)。由于有如此多的组织面临着事关生存的风险管理危机,这就引发了这样一个问题:有多少组织通过使用集中的风险评估来实施成熟的信息安全风险管理计划,以推动信息安全计划的创建和维护,并通过IT审计来实施(Streff,2019)。评估风险的存在以及利用评估结果创建和维护信息安全计划以及通过审计强制执行的重要性按顺序或相对重要性列出。本文旨在讨论每一支柱的重要性,并解释这三个概念之间优先顺序背后的理由。
Many organizations are facing complex risk management issues and are ill equipped to sufficiently mitigate risk in a focused manner. Studies have shown that an astonishing 57% of senior level executives label “risk and compliance” as the two top categories they feel least prepared to address (Quantivate, 2019, para. 1). Consequently, only 6% of directors maintain confidence that their organization is effectively managing risk (Guis, Mieszala, Panayiotou & Poppensieker, 2018, para. 4). With so many organizations facing an existential risk management crisis, this beckons the question how many organizations have implemented a mature information security risk management program through the use of a focused risk assessment to drive the creation and maintenance of the information security program and are enforced through IT auditing (Streff, 2019). The existence of assessing risk and using the results to create and maintain the information security program and enforcing through auditing are listed in order or relative importance. This paper will aim to discuss the importance of each pillar and explain the reasoning behind the priority between the three concepts.