Show simple item record

dc.contributor.authorWesterman, George
dc.date.accessioned2007-12-07T20:28:32Z
dc.date.available2007-12-07T20:28:32Z
dc.date.issued2007-12-07T20:28:32Z
dc.identifier.urihttp://hdl.handle.net/1721.1/39809
dc.description.abstractWith information technology becoming an increasingly important part of every enterprise, managing IT risk has become critically important for CIOs and their business counterparts. However, the complexity of IT makes it very difficult to understand and make good decisions about IT risks. CISR research has identified four business risks - Availability, Access, Accuracy, and Agility - that are most affected by IT. Since nearly every major IT decision involves conscious or unconscious tradeoffs among the four IT risks, IT and business executives must understand and prioritize their enterprise's position on each. Three core disciplines - IT foundation, risk governance process, and risk aware culture - constitute an effective risk management capability. Enterprises that build the three core disciplines manage risk more effectively and their business executives have better understanding of their IT risk profile and risk tradeoffs. When done well, IT risk management matures from a set of difficult compliance and threat-reduction activities to become a true source of agility and business value.en
dc.language.isoen_USen
dc.relation.ispartofseriesMIT Sloan School of Management Working Paperen
dc.relation.ispartofseries4658-07en
dc.subjectIT related risken
dc.subjectIT governanceen
dc.subjectIT architectureen
dc.subjectbusiness agilityen
dc.titleIt Risk Management: From IT Necessity to Strategic Business Valueen
dc.typeWorking Paperen


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record