期刊论文详细信息
Australasian Journal of Information Systems
Applying the Australian and New Zealand Risk Management Standard to Information Systems in SMES
Robyn Davidson1  Susan Lambert1 
[1] Robyn Davidson
关键词: Australia;    New Zealand;    SME;    risk;    standard;   
DOI  :  10.3127/ajis.v12i1.101
学科分类:计算机科学(综合)
来源: University of Canberra * Faculty of Information Sciences and Engineering
PDF
【 摘 要 】

This paper advocates the use of the Australia/New Zealand Risk Management Standard (SA/SNZ, 1999) in conjunction with of a modified version of Birch and McEvoy’s (1992) Structured Risk Analysis for Information Systems (SRA-IS) to identify information systems security risks in SMEs. The use of Internet based commerce by SMEs exposes them to information systems security risks that they are ill equipped to recognise let alone mitigate. Unlike the identification of some business risks, identification of risks associated with information systems requires certain technical expertise. The structure of the existing information system must be understood and modelled before risks can be identified and it is acknowledged that the required technical expertise may not be present in SMEs, thus the involvement of information systems consultants may be necessary. Once the information system has been modelled little information systems expertise is required to complete the analysis, keeping consultant involvement to a minimum and maximising owner/manager involvement.

【 授权许可】

Unknown   

【 预 览 】
附件列表
Files Size Format View
RO201912020430881ZK.pdf 244KB PDF download
  文献评价指标  
  下载次数:12次 浏览次数:28次