• DocumentCode
    3203783
  • Title

    A Business Viewpoint for Integrated IT Governance, Risk and Compliance

  • Author

    Vicente, Pedro ; Silva, Miguel Mira da

  • Author_Institution
    Inst. Super. Tecnico, Univ. Tec. de Lisboa, Lisbon, Portugal
  • fYear
    2011
  • fDate
    4-9 July 2011
  • Firstpage
    422
  • Lastpage
    428
  • Abstract
    Due to increasing requirements, standards and tight oversight from governments, along with the immediate need to effectively manage the increasing business and operational risks inherent to competing in a complex global market, integrated Governance, Risk and Compliance (GRC) is becoming one of the most important business requirements for organizations. In particular, IT requirements, standards and best practices play a crucial role in IT organizations/departments. The lack of guidance in this domain, namely scientific research, results in unaided attempts to improve efficiency and effectiveness in organizations. In this paper we propose a business architecture that describes the integration of the main processes for IT Governance, IT Risk Management and IT Compliance (IT GRC). Based on a process model for IT GRC and a conceptual model for GRC, we use ArchiMate to model the behavioural, structural and informational structure of the business viewpoint - business processes, roles and business objects respectively. To end with, we discuss the final result and draw some conclusions about the constructed artifact.
  • Keywords
    business process re-engineering; globalisation; government data processing; information technology; organisational aspects; risk analysis; IT compliance; IT governance; IT organizations; IT requirements; IT risk management; business architecture; business process management; business requirements; business viewpoint; complex global market; Adaptation models; Analytical models; Organizations; Process control; Standards organizations; Unified modeling language; IT GRC; business viewpoint; compliance; governance; integrated; risk;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services (SERVICES), 2011 IEEE World Congress on
  • Conference_Location
    Washington, DC
  • Print_ISBN
    978-1-4577-0879-4
  • Electronic_ISBN
    978-0-7695-4461-8
  • Type

    conf

  • DOI
    10.1109/SERVICES.2011.62
  • Filename
    6012769