Assessing an information security governance of an enterprise

Systems and methods for assessing an information security governance of an enterprise are disclosed. The method includes classifying the information security governance into a plurality of sub-information security governances. The method further comprises defining a plurality of governance focus are...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Vinnakota Tirumala Rao, Mandaleeka Narayana Guru Prasada Lakshmi
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Systems and methods for assessing an information security governance of an enterprise are disclosed. The method includes classifying the information security governance into a plurality of sub-information security governances. The method further comprises defining a plurality of governance focus areas and a plurality of governance control dimensions for a sub-information security governance. The method further comprises checking a compliance, by a processor, of the governance practices of users in the sub-information security governances, in the plurality of governance focus areas, and in the plurality of governance control dimensions. The method further comprises assigning weights to the plurality of governance focus areas, to the plurality of governance control dimensions, and to the sub-information security governances. The method further comprises determining a score for sub-information security governance based on the compliance and the weights.