已收录 271055 条政策
 政策提纲
  • 暂无提纲
Using assurance models to aid the risk and governance lifecycle
[摘要] In this paper we describe an enterprise assurance model allowing many layers of the enterprise architecture from the business processes; supporting applications and the IT infrastructure and operational processes to be represented and related from a control and risk perspective. This provides a consistent way of capturing and relating the risk views for the various stakeholders within the organisation. At the low-level we use assurance models to provide automated testing of controls and policies and at the higher level these results are related across the enterprise architecture. This enables a repository for manual and automated test results that can be used to derive different (but consistent) views for the various stakeholders. Publication Info: BT Technology Journal, Vol 25, no.1, Jan. 07 18 Pages
[发布日期]  [发布机构] HP Development Company
[效力级别]  [学科分类] 计算机科学(综合)
[关键词] trust;assurance;risk;compliance;governance;security [时效性] 
   浏览次数:39      统一登录查看全文      激活码登录查看全文