期刊论文详细信息
Risk Governance & Control: Financial Markets & Institutions
RISK ASSESSMENT AND MITIGATION AT THE INFORMATION TECHNOLOGY COMPANIES
关键词: Software Patches;    Software Patch Management;    Software Flaws;    Risk Assessment;    Risk Mitigation;    Confidentiality;    Integrity;    Availability;    Downtime;    Information Security;   
DOI  :  10.22495/rcgv6i2art6
学科分类:社会科学、人文和艺术(综合)
来源: Virtus Interpress
PDF
【 摘 要 】

Developing computer software that is free from material defects is the ultimate goal for software developers; however, due to the cost and complexity of software development, it is a goal that is unlikely to be achieved. As a consequence of the inevitable defects that manifest within computer software, the task of software patch management becomes a key focus area for software companies, IT departments, and even end users. Audit departments, as part of their responsibilities, are required to provide assurance on the patching process and therefore need to understand the various decision-making factors. Software flaws that exist within computer systems may put confidential information at risk and may also compromise the availability of such systems. The study investigated the recommended approaches for the task of software patching, with a view to balancing the sometimes conflicting requirements of security and system availability. The study found that there are a number of key aspects that are required to ensure a successful patching process and that the internal auditors of the ‘big four’ South African banks considered most of these factors to be important.

【 授权许可】

CC BY-NC   

【 预 览 】
附件列表
Files Size Format View
RO201901215982121ZK.pdf 594KB PDF download
  文献评价指标  
  下载次数:27次 浏览次数:17次