Using an Enterprise Information Management System to Enhance IT Compliance and Information Value

被引:0
|
作者
Dameri, Renata Paola [1 ]
机构
[1] Univ Genoa, Dept Business Adm, Genoa, Italy
关键词
IT governance; IT management; IT compliance; knowledge management;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the latest years, IT governance has become more and more important, for several reasons: the increasing pervasivity of IT in business organization, management and administration requires a veritable governance activity, to strategically orient decision making about IT investments and management; - the role of information systems in administrative data processing requires a special focus on information security and process control; - the need to keep down IT budget forces to balance IT capital expenditure and operational expenditure and to increase IT systems productivity and information value. More of the attention on IT Governance is captured by compliance, owing to the recent financial scandals and the severe rules regarding information systems audit and control. Companies need to comply with these rules, but it requires important investments, considered not strategic but only necessary (Remenyi et. Al. 2000). However, companies should analyse the compliance requirements and to implement an IT governance system, not only to comply with legal rules, but also to improve the strategic alignment between IT and business and to optimise value creation by IT compliance investments (Ventrakaman and Henderson 1996, Van Grembergen 2003). Therefore, IT governance should have a complex set of goals, such as: - to standardize and unify processes; - to align information delivery with business needs; to control IT initiatives cost; - to comply with external requirements. These goals are often opposed and difficult to pursue, because: - they regard cross functional enterprise systems; - they are strictly linked; - they concern large databases and applications, very difficult to control. To optimise IT compliance it is useful to define a roadmap to IT compliance, orienting these activity to value creation, by realising scale, scope and experience economies in IT compliance activities. The accomplishment of this roadmap is the automation of IT compliance processes, using Governance, Risk and Compliance (GRC) standard solutions or developing in house systems, such as Enterprise Information Management (EIM) systems, to automatically manage processes, data and information security, access control, system performance and to data usability. In this paper, IT compliance topic is introduced, to define how to orient IT compliance to value creation; GRC systems and EIM systems are described, with their different cost and benefits for companies. Aim of the paper is to define how to develop compliance automated systems, to save money and enhance information integration and value. Observations and conclusions derive from practical experience of the author, participating to a project of EIM implementation in a major Italian company.
引用
收藏
页码:111 / 121
页数:11
相关论文
共 50 条
  • [31] Knowledge management in an enterprise-wide information system
    Chan, KCC
    Chung, LML
    WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL 1, PROCEEDINGS: INFORMATION SYSTEMS, 1999, : 109 - 116
  • [32] Thoughts on construction of enterprise crisis information management system
    Sun, Ying
    Zhang, Xin
    Su, Lei
    ISCRAM CHINA 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL WORKSHOP ON INFORMATION SYSTEMS FOR CRISIS RESPONSE AND MANAGEMENT, 2007, : 86 - 89
  • [33] Enterprise energy cost management and information system construction
    Gong, Xingguo
    Song, Xiaozhong
    Li, Zhiming
    Li, Juanliang
    2008 PROCEEDINGS OF INFORMATION TECHNOLOGY AND ENVIRONMENTAL SYSTEM SCIENCES: ITESS 2008, VOL 2, 2008, : 1072 - 1077
  • [34] Knowledge Management and Intellectual Capital in an Enterprise Information System
    Demigha, Souad
    PROCEEDINGS OF THE 16TH EUROPEAN CONFERENCE ON KNOWLEDGE MANAGEMENT (ECKM 2015), 2015, : 213 - 221
  • [35] The Building of Enterprise Human Resource Management Information System
    Xue Xianhua
    MOT2009: PROCEEDINGS OF ZHENGZHOU CONFERENCE ON MANAGEMENT OF TECHNOLOGY, VOLS I AND II, 2009, : 360 - 364
  • [37] Study on the enterprise safety information share and management system
    Chen, GH
    Zhang, WH
    Zhan, HC
    Pan, Y
    Chen, QG
    PROGRESS IN SAFETY SCIENCE AND TECHNOLOGY, VOL III, PTS A AND B, 2002, 3 : 713 - 718
  • [38] Development and Performance Improvement of Enterprise Information Management System
    Wang Hai-Lan
    Jin Hai
    2014 7TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION (ICICTA), 2014, : 186 - 189
  • [39] Developing management information system in international shipping enterprise
    Chen, Q.G.
    Zhang, R.Y.
    Shanghai Haiyun Xueyuan Xuebao/Journal of Shanghai Maritime University, 2001, 22 (02):
  • [40] Distributed Jewelry Enterprise Resource Management Information System
    Mo, Pingping
    Zhang, Fan
    Pan, Fujiang
    2011 INTERNATIONAL CONFERENCE ON ELECTRONICS, COMMUNICATIONS AND CONTROL (ICECC), 2011, : 3672 - 3674