login

Using an Enterprise Architecture for IT Risk Management.

Information Security for South AfricaPublished 1 January 2006
Frank Innerhofer-Oberperfler, Ruth Breu
Citations48

TL;DR

The proposed approach provides a detailed process of security management and defines the necessary responsibilities and roles of the participating stake-holders to bridge the technical and business oriented views on information security.

Abstract

In this paper we propose a novel approach for the systematic assessment and analysis of IT related risks in organisations and projects. The approach is model-driven using an enterprise architecture as the basis for the security management process. Using an enterprise architecture it is possible to provide an integrated description of an organisation’s structure, processes and its underlying IT landscape. That way we want to bridge the technical and business oriented views on information security. The proposed approach provides a detailed process of security management and defines the necessary responsibilities and roles of the participating stake-holders.

Keywords

Computer ScienceBusiness, Management and Accounting