Emerging issues in IT governance: implementing the corporate IT risks management model

  • Authors:
  • Mario Spremic;Matija Popovic

  • Affiliations:
  • Faculty of Economics and Business Zagreb, University of Zagreb, Zagreb, Croatia;Ernst & Young, Technology & Security Risk Services, Senior IT Auditor, Zagreb, Croatia

  • Venue:
  • WSEAS TRANSACTIONS on SYSTEMS
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Most organizations in all sectors of industry, commerce and government are fundamentally dependent on their information systems (IS) and would quickly cease to function should the technology (preferably information technology - IT) that underpins their activities ever come to halt [15]. The IT developments may have enormous implications for the operation, structure and strategy of organizations. IT may contribute towards efficiency, productivity and competitiveness improvements of both inter-organizational and intra-organizational systems [1]. Successful organizations manage IT function in much the same way that they manage their other strategic functions and processes. This in particular means that they understand and manage risks associated with growing IT opportunities as well as critical dependence of many business processes on IT and vice-versa. IT risk management issues are not only any more marginal or 'technical' problems and become more and more a 'business problem'. Therefore, in this paper a Corporate IT Risk Management model is proposed and contemporary frameworks of IT Governance and IT Audit explained. Also the methodologies for their implementation (CobiT, ISO 27000 'family', ITIL) is shown and explained.