Current IT technology in the rapid development of computers and the Internet in the business of our real life and getting a lot of help, and that is becoming increasingly dependent.
Development of computer technology and can easily handle the vast ...
Current IT technology in the rapid development of computers and the Internet in the business of our real life and getting a lot of help, and that is becoming increasingly dependent.
Development of computer technology and can easily handle the vast amounts of information stored and can take advantage of numerous materials via the Internet a place of discovery and information exchange has been used. The added development of smart devices, especially mobile banking and social issues by taking advantage of the free-wheeling discussion on forming public opinion may be brought out.
The recent wave of disclosure of personal information, such as misuse, abuse, invasion of privacy cases continue to occur as the personally identifiable information and sensitive information such as telephone fraud and identity theft using the mental and financial damage has resulted. To prevent this damage from the source to the last year, September 30, 2011 in accordance with the Privacy Act implementation of all public and private sector organizations must handle personal information must be encrypted as it should perform.
Through this study, DB encrypts your personal information in the administrative building to maximize the efficiency of the overall Risk IT framework is to promote the expansion.
This study group of experts to target information security professionals for statistical analysis (50 people), Information Security Governance Specialist (20 people), Risk IT framework, professionals (30 people), IT-related services personnel (50 people) who 2012 year 21 May to 3 June 15 days e-mail (E-mail) through the survey was conducted. As a result, the total number of 108 questionnaire responses were analyzed.
The significance of this study performed in accordance with the Privacy Act personal information of related organizations and businesses plan effective management of DB encryption Risk IT framework domains of the three kinds of 'risk governance', 'risk evaluation', 'Risk Response' of the with three kinds of information sector by constructing a sub-element of the sector through nine kinds of business processes enterprise-wide Risk Management within the enterprise to systematically build / run is being conducted silmunjosaro comment on.
The first three domains, risk governance, senior management sector in their decision by considering all aspects of IT risk and decide whether, IT risk managers in the design or execution, and operating at steady state is considered as a trusted advisor IT departments and business operational risk and enterprise risk services to perform key roles in business and was placed on whether the criteria.
Second, the risk assessment sector IT decision makers in favor of transparency, risk probability of loss and gain new opportunities for exposure and the best available information, and facilitate the actual operation of the physical risk factors aggressively through the extended enterprise is passed, the staff at all levels of business risk factors directly responsible for determining relevance and companies collecting data on the formal Risk, risk analysis and profiling techniques of how to perform the continuous improvement of the standards placed.
Third, the risk categories corresponding to the total risk requirement and are ready for how to deal with is aware of strategies and plans, actively corresponding risks and threats for current operations extended across the entire enterprise is being passed, the entire fashion companies typically respond to risk issues in partnership with external organizations to mitigate risk exposure and was placed on whether the criteria.
Firstly, the risks identified in the governance sector are as follows.
Senior management of the IT risk, but the interest in higher education IT systems for risk managers and human resource development was relatively low. Personal information in order to perform DB encryption are scattered a number of risks and effectively manage these risks for senior management to be high interest and talent in a systematic risk management education training could find that you need.
Second, the sector identified in the risk assessment information for IT-related risk identification, analysis and reporting for effective data collection and analysis, but the periodic determines the judgment process, and Risk of Risk due to the absence of risk, as well as up-to-date profiling, continuous improvement does not be done that could be found.
Third, the risk in the corresponding sector in a timely manner after the occurrence of risk reports and risk, but a clear analysis and transparent reporting was found to not be made. Since the onset of risk for the monitoring of residual risk and acceptable levels, but to reduce the lack of systematic management and lessons learned since the onset of risk is not being systematically managed also was found.
This efficient management of personal information for DB encryption system of the enterprise-wide IT risk management plan may be a need. Beyond the limits of this study have the research focus is on this that trend continues, please future research.