<link rel="stylesheet" href="styles.f3b1fba60ec7970c.css">

Governança da segurança: a segurança da informação alinhada aos negócios

Carregando...
Imagem de Miniatura

Título da Revista

ISSN da Revista

Título de Volume

Editor

Universidade Federal do Rio de Janeiro

DOI

Resumo

This work describes the development of a model thought to help the administration board of institutions to consider Information Security Governance as part of their global governance structure. The idea is to provide the proper knowledge about the risks posed by the Information Technology infrastructure in a pragmatic way, allowing for an efficient strategic planning. The model is based on common, proven, decision making strategies used on Information Management Systems. A new dimension is added to those traditional Information Management Systems in order to accomplish: control (what), processes (how), people (who) and technology (automated tools). Through a study of some models of management and governance of Information Technology, the main body of the model was formed. COBIT and the ISO security standard were used to define the control objectives needed in each level. The ITIL model was adapted to define the implementation of the processes, however these solutions have to be proposed for improvement of this work.

Descrição

Citação

Avaliação

Revisão

Suplementado Por

Referenciado Por

Direitos e licensiamento

Acesso Aberto