Discussion 6 - Info Tech Import Plan Response to peers

profilePrashanthi
AmyDaxenbichler-discussion6infotechpost1.docx

Information technology governance provide framework for who within the organization will be in control of making decisions, so that there is accountability for any illegal or unethical behaviors. The most critical factors that fueled the need for IT governance occurred in the eary 2000s, when several companies were discovered to be engaging in illegal acts, especially in the accounting field. This brought to light the need for better governance in all areas of the organization. As several corruption scandals started to come to the forefront, such as Enron and Worldcom, the federal government realized that they needed to interject and force companies to have more governance over their employees and business processes. In 2002, the Sarbanes-Oxley Act was implemented which required that the CFO or CEO certify the financial statements of e company assuring that they would keep an vigilant eye on their employees to prevent themselves form getting into legal trouble (Pearlson, Saunders, and Gallenta, 2018). This act originally was designed to address the finance and accounting departments, but soon the IT department could also see the value in having a responsible individual ensure control over the department's outputs because they too had a part in the financial data presented by the company (Pearlson, Saunders, & Gallenta, 2018). IT governance developed from this need for IT departments to comply with the federal manadate. It managers then became responsible for identifying risks, complying with the Sarbanes-Oxley Act, and continuously improving IS process maturity (Pearlson, Saunders, & Gallenta, 2019. THe need for more structure and identifiable individuals with control over processes developed from this connection to the Act, and thus IT governance became a must within organizations.

The International Organization for Standardization (ISO) is an international organzation that defines what the standards of practice are for various pprofessions including network security. The ISO creates a foundation for various professionals to know what is standard practice and ensure they are acting in a legal and ethical manner. The ISO provides a standard for which the governance must live by in order to operating in an ethical and appropriate manner. The ISo provided a guide to what network security is and how it must be implemented effectively. In the field of network security, the ISO has seven parts that include network security overview and concepts, guidelines for the design and implementation of network security, reference network scenarios such as threats and control issues, securing communications between netwrok using security gateways, securing communication across netwrks using VPNs, securing wireless IP network access, and guideline for network virtualization security (ISO, 2020). Each ISO for network security assist network security professionals and organizations to know they are complying and operating to the industry standards across the world. The ISO also allow these same individuals to see if there are inefficiencies or inappropriate business processes that are not effective and need to be modified to adhere to the ISOs.

Reference

ISO (2020). ISO/IEC 27033 IT network security standard. Retrieved from Iso27001security.com.

Pearlson, K., Saunders, C.S., Gallenta, D. (2019). Managing and Unsing Information Systems: A Strategic Approach (7th Ed.). John WIley & Sons.