摘要
随着企业的信息化建设,企业信息安全在持续、可靠和稳定运行中面临着巨大考验,因此企业急需开展信息安全治理。论文从企业信息安全治理的实践出发,概述了目前企业信息安全治理存在的问题和困惑,总结了企业实现有效信息安全治理的关注领域和实施内容,为企业建立良好的信息安全治理提供了基本框架。
With the information const,uction of enterprise, the information secudty is facing challenges of continual, reliable and stable operation, so the information security governance construction is an emergency to all the enterprises. This article overviewed the problems and confusions of information security governance, as well as summarized the focus areas and contents of realizing effective information secudty governance based on author' s practical experience, which provided a basic framework of information security governance to enterprise.
关键词
信息安全
安全治理
框架
风险管理
information security
security governance
framework
risk management