A comprehensive people, process and technology (PPT) application model for Information Systems (IS) risk management in small/medium enterprises (SME)

A comprehensive people, process and technology (PPT) application model for Information Systems (IS) risk management in small/medium enterprises (SME)
复制标题

用于中小型企业 (SME) 信息系统 (IS) 风险管理的全面人员、流程和技术 (PPT) 应用模型

DOI:
10.1109/comtech.2017.8065754
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Mian Muhammad Waseem Iqbal
Mian Muhammad Waseem Iqbal
中科院分区:
--
文献类型:
--
作者:
Muhammad Imran Javaid;Mian Muhammad Waseem Iqbal

文献摘要

参考文献

被引文献

相似文献

随着现代时代的到来。信息技术(IT)在企业的运营、管理和发展中至关重要。现在,信息系统(IS)正在塑造现有的企业战略,并为所有规模的企业创造新的途径。与此同时,他们也受到许多威胁。以前,企业的执行管理层不参与信息技术事务,习惯于将这些威胁留给运营管理。然而,企业对信息系统的依赖性增加改变了这些方面,因为这些未管理的威胁导致了许多甚至可能威胁企业生存的业务风险。为了应对这些风险,已经制定了一些风险管理标准,但其中大多数侧重于大型组织,这些组织拥有结构良好的业务流程,并且已经拥有一些IT风险管理专业知识。其次,这些标准要么是特定于某些特定业务领域的,要么是在战略层面提供通用准则,但缺少业务层面的细节,需要在将其应用于特定企业业务流程和环境之前进行整合和定制。因此,IT风险管理在中小企业中仍然是一个挑战。就中小型企业而言,主要由于缺乏预算和专门知识,很难适用这些标准。此外,在广泛的风险管理标准中选择适当的标准仍然是一个薄弱环节。因此,本文分析的主要问题是:如何在信息系统中应用风险管理在业务层面和集成的各种风险管理框架内的企业上下文?为了回答这些问题,广泛接受的风险管理框架和工具进行了分析,已经确定的挑战和解决方案,提出了通过开发一个风险管理应用模型,其目的是它甚至可以被小企业使用。
With advent of modern era. Information Technology (IT) has turned out to be very critical in operations, management and growth of an enterprise. Now, Information Systems (IS) are shaping the existing corporate strategies and creating new avenues for all size enterprises. At the same time, they are subject to numerous threats. Previously, executive management of enterprises didn't involve themselves in the information technology affairs and used to leave these threats to the operational management. However, increased dependencies of businesses on information systems have changed these dimensions, as these unmanaged threats results into a number of business risks which can even threaten business existence. In order to deal with these risks, a number of risk management standards have been developed but most of them focus on large organizations, who have well-structured business processes and some IT risk management expertise is already there. Secondly, either these standards are specific to some particular business domain or provide generic guidelines at strategic level with missing operational level details, which needs to be integrated and customized before its application to a particular enterprise business processes and environment. Therefore, IT risk management in small and medium enterprises is still a challenge. In case of small or medium size enterprises, application of these standards is difficult, primarily due to lack of budget and expertise. Furthermore, selection of appropriate standard among wide spectrum of risk management standards, remains a weak link. Therefore the main question analyzed in this research paper is: How to Apply Risk Management in information systems at operational level and integration of various risk management frameworks within enterprise context? In order to answer these questions, widely accepted risk management frameworks and tools have been analyzed, challenges have been identified and solution is proposed by developing a risk management application model with the aim that it can even be used by small enterprises.
DOI: --
发表时间: 2006
期刊:
影响因子: --
作者:
Tadashi;Yamada;Tadashi Yamada;岩本武和;Takekazu Iwamoto
通讯作者: Takekazu Iwamoto