Discussion 6 - Info Tech Import Plan Response to peers

profilePrashanthi
Pushprajsinh-Dicussion6-Post2infotech.docx

Normally IT governance aligns the IT with the business governance policies. IT governance is a broader term, which includes IT policies includes infrastructure, software applications, networking-related applications, infrastructure projects, and IT security of the organization. The organization’s IT governance’s primary goal is to develop the organizations’ IT policy to fulfill business requirements. Mostly, all the organization has some type of information security program in place. This type of program is necessary in the current IT world as the information posses a lot of value.

In the past many years, IT technology has changed a lot. It requires the organization to rethink its business policy. Automation and artificial intelligence has changed the way information across the organization flows, and it has also changed the value of data. Business management is now trying to get the value of this data and bring the business model changes. Due to the change in the business model, the IT governance program needs to be re-designed for an organization. The legacy policy cannot work with the new business model. It also requires changes in the IT policies (Martínez & Gaona, 2015).

The international standard organization is a global organization, which helps to maintain the standard at the world level. ISO develops the standards which organization can follow to establish the trust to their client. Implementing the ISO standard helps the organization to build its reputation in the market with other competitors. ISO has developed 27001standard in particular for information security management system. IT describes an organization’s data control framework. This includes policy and standards on how an organization can control the organization’s data. ISO 27001 standard doesn’t suggest the implementation of any tools, or specific IT solutions, or any methods. This standard helps the organization to develop its IT security program successfully. ISO 27001 breaks down best practices into the following steps. Information security policies cover how the organization can develop its information security management system. Assets management helps the organization with its IT assets management. Access control defines how different data set access should be given to the employees. Operation security helps to collect, store, and analyze data securely (Petters, 2020).

References

Gutiérrez-Martínez, Núñez-Gaona. “Business Model for the Security of a Large-Scale PACS, Compliance with ISO/27002:2013 Standard.” Journal of digital imaging 28.4 (2015): 481–491. Web.

Jeff Petters. (March 29, 2020). What is ISO 27001compliance? Essentials tips and insight. Retrieved from https://www.varonis.com/blog/iso-27001-compliance/.