Using an Enterprise Information Management System to Enhance IT Compliance and Information Value

被引:0
|
作者
Dameri, Renata Paola [1 ]
机构
[1] Univ Genoa, Dept Business Adm, Genoa, Italy
关键词
IT governance; IT management; IT compliance; knowledge management;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the latest years, IT governance has become more and more important, for several reasons: the increasing pervasivity of IT in business organization, management and administration requires a veritable governance activity, to strategically orient decision making about IT investments and management; - the role of information systems in administrative data processing requires a special focus on information security and process control; - the need to keep down IT budget forces to balance IT capital expenditure and operational expenditure and to increase IT systems productivity and information value. More of the attention on IT Governance is captured by compliance, owing to the recent financial scandals and the severe rules regarding information systems audit and control. Companies need to comply with these rules, but it requires important investments, considered not strategic but only necessary (Remenyi et. Al. 2000). However, companies should analyse the compliance requirements and to implement an IT governance system, not only to comply with legal rules, but also to improve the strategic alignment between IT and business and to optimise value creation by IT compliance investments (Ventrakaman and Henderson 1996, Van Grembergen 2003). Therefore, IT governance should have a complex set of goals, such as: - to standardize and unify processes; - to align information delivery with business needs; to control IT initiatives cost; - to comply with external requirements. These goals are often opposed and difficult to pursue, because: - they regard cross functional enterprise systems; - they are strictly linked; - they concern large databases and applications, very difficult to control. To optimise IT compliance it is useful to define a roadmap to IT compliance, orienting these activity to value creation, by realising scale, scope and experience economies in IT compliance activities. The accomplishment of this roadmap is the automation of IT compliance processes, using Governance, Risk and Compliance (GRC) standard solutions or developing in house systems, such as Enterprise Information Management (EIM) systems, to automatically manage processes, data and information security, access control, system performance and to data usability. In this paper, IT compliance topic is introduced, to define how to orient IT compliance to value creation; GRC systems and EIM systems are described, with their different cost and benefits for companies. Aim of the paper is to define how to develop compliance automated systems, to save money and enhance information integration and value. Observations and conclusions derive from practical experience of the author, participating to a project of EIM implementation in a major Italian company.
引用
收藏
页码:111 / 121
页数:11
相关论文
共 50 条
  • [1] ENTERPRISE MANAGEMENT USING THE SYSTEM OF RATIONALIZATION OF INFORMATION PROCESSES
    Legowik-Malolepsza, Malgorzata
    Legowik-Swiacik, Sylwia
    PROCEEDINGS OF THE 3RD BUSINESS & MANAGEMENT CONFERENCE, 2016, : 124 - 133
  • [2] Enterprise crisis information management system
    Zhang, Gang
    Xie, Yangqun
    ISCRAM CHINA 2006: PROCEEDINGS OF THE FIRST INTERNATIONAL WORKSHOP ON INFORMATION SYSTEMS FOR CRISIS RESPONSE AND MANAGEMENT, 2006, : 233 - 238
  • [3] Assessing the benefits of using an enterprise system in accounting information and management
    Spathis, Charalambos
    Ananiadis, John
    JOURNAL OF ENTERPRISE INFORMATION MANAGEMENT, 2005, 18 (02) : 195 - +
  • [4] Integrating Information Technology (IT) to enhance Compliance of Safety Management System in Syrian Shipping Companies
    Lebbadi, Taha
    Adams, Jackson
    2013 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2013, : 41 - 55
  • [5] Enhance the management level of iron and steel enterprise by information technology
    Huang Danhong
    Duan Wanchun
    Research on Organizational Innovation - 2007 Proceedings of International Conference on Enterprise Engineering and Management Innovation, 2007, : 721 - 728
  • [6] Enterprise architecture to enhance security and risk management of information systems
    School of Software, Tsinghua University, Beijing 100084, China
    Qinghua Daxue Xuebao, 2009, SUPPL. 2 (2073-2086):
  • [7] Design and Implementation of Information Management System for Enterprise
    Xin, Dong
    Zhao, Hongxia
    Zhou, Baogang
    PROCEEDINGS OF THE 2015 INTERNATIONAL INDUSTRIAL INFORMATICS AND COMPUTER ENGINEERING CONFERENCE, 2015, : 56 - 60
  • [8] Enterprise Information System and Supply Chain Management
    Wang, Wenxing
    Si, Weidong
    Tu, Yong
    EIGHTH WUHAN INTERNATIONAL CONFERENCE ON E-BUSINESS, VOLS I-III, 2009, : 1115 - 1120
  • [9] The Deconstruction and Reconstruction of Enterprise Management Information System
    Wang Fanlin
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND ENGINEERING, 2009, : 295 - 299
  • [10] Manufacture & management information system of mine enterprise
    Zhang, H
    Lan, FS
    PROCEEDINGS OF THE 4TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-4, 2002, : 3048 - 3052