Assessing an information security governance of an enterprise
Systems and methods for assessing an information security governance of an enterprise are disclosed. The method includes classifying the information security governance into a plurality of sub-information security governances. The method further comprises defining a plurality of governance focus are...
Gespeichert in:
Hauptverfasser: | , |
---|---|
Format: | Patent |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | Systems and methods for assessing an information security governance of an enterprise are disclosed. The method includes classifying the information security governance into a plurality of sub-information security governances. The method further comprises defining a plurality of governance focus areas and a plurality of governance control dimensions for a sub-information security governance. The method further comprises checking a compliance, by a processor, of the governance practices of users in the sub-information security governances, in the plurality of governance focus areas, and in the plurality of governance control dimensions. The method further comprises assigning weights to the plurality of governance focus areas, to the plurality of governance control dimensions, and to the sub-information security governances. The method further comprises determining a score for sub-information security governance based on the compliance and the weights. |
---|