Towards a Reference Model for Integrated Governance, Risk and Compliance
نویسندگان
چکیده
More regulations are on the way, along with demanding transparency, accurate information about company operations, robust and comprehensive risk management, regulatory compliance and efficient governance. Consequently, organizations are seeking to improve their GRC activities, by implementing integrated GRC solutions that provide a holistic view of the organization and help in the automation of activities. After analysing and researching the emerging domain of integrated GRC, the lack of references that provide guidance to organizations in the implementation and optimization of processes, activities and information is an alarming issue. In this paper we propose a reference model for GRC, combining two architectural layers Business and Information Systems modelled with ArchiMate. The reference model is presented and described through several viewpoints. We then apply a framework to evaluate the quality of the reference model and discuss the obtained results.
منابع مشابه
An ISO Compliant and Integrated Model for IT GRC (Governance, Risk Management and Compliance)
GRC (Governance, Risk and Compliance) is an umbrella acronym covering the three disciplines of governance, risk management and compliance. The main challenge behind this concept is the integration of these three areas, generally dealt with in silos. At the IT level (IT GRC), some research works have been proposed towards integration. However, the sources used for the construction of the resulti...
متن کاملA Frame of Reference for Research of Integrated Governance, Risk & Compliance (GRC)
Governance, Risk and Compliance (GRC) is an emerging topic in the business and information technology world. However to this day the concept behind the acronym has neither been adequately researched, nor is there a common understanding among professionals. The research at hand provides a frame of reference for research of integrated GRC that was derived from the first scientifically grounded de...
متن کاملA Frame of Reference for Research of Integrated Governance, Risk and Compliance (GRC)
Governance, Risk and Compliance (GRC) is an emerging topic in the business and information technology world. However to this day the concept behind the acronym has neither been adequately researched, nor is there a common understanding among professionals. The research at hand provides a frame of reference for research of integrated GRC that was derived from the first scientifically grounded de...
متن کاملA process model for integrated IT governance, risk, and compliance management
Governance, Risk, and Compliance (GRC) is an emerging topic in the world of business and information technology. However to date there is a lack of research on an integrated approach to GRC has hardly been researched. In this paper we construct an integrated process model for high-level IT GRC management. First, we discuss existing process models for integrated GRC. Then we set the scope of our...
متن کاملControl Objectives for DP: Digital Preservation as an Integrated Part of IT Governance
Digital Preservation, often seen as information management with a long-term mission, is recognized as an independent research area, but the field’s maturity is still evolving. Reference models and compliance criteria for archival systems are being developed, but the more general perspective of Governance, Risk and Compliance has yet to be fully considered. In particular, Digital Preservation ca...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011