• DocumentCode
    1566174
  • Title

    Applications for IT-Risk Management – Requirements and Practical Evaluation

  • Author

    Grob, Heinz Lothar ; Strauch, Gereon ; Buddendick, Christian

  • Author_Institution
    Eur. Res. Center for Inf. Syst., Muenster Univ., Munster
  • fYear
    2008
  • Firstpage
    758
  • Lastpage
    764
  • Abstract
    Nowadays the importance of a dedicated information security management (ISM) is undisputedly. One essential task in realizing a company´s ISM is to implement a compulsory operational risk management (ORM) aiming also at ensuring the compliance with certain standards. The risks addressed by ORM prevalently result from information systems. A promising approach is to focus on business processes to combine the technical system focused perspective of security management with the more centralized perspective of operational risk management. Within this paper first we will deliver an introduction an integrated IT risk management and its corresponding decisions. Afterwards we will derive requirements for application systems in order to supporting decisions in IT-Risk Management. For this purpose a catalogue of requirements will be developed. Based on this catalogue software systems for IT security management and operational risk management were examined with regard to their adequacy for decision support in IT-Risk Management.
  • Keywords
    DP management; risk management; security of data; IT-risk management; business processes; catalogue software systems; information security management; operational risk management; Application software; Availability; Conference management; Content management; Information management; Information security; Management information systems; Risk analysis; Risk management; Software systems; IT-Compliance; IT-risk management; information security management; software market analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-0-7695-3102-1
  • Type

    conf

  • DOI
    10.1109/ARES.2008.168
  • Filename
    4529420