Using an Enterprise Information Management System to Enhance IT Compliance and Information Value

被引:0
|
作者
Dameri, Renata Paola [1 ]
机构
[1] Univ Genoa, Dept Business Adm, Genoa, Italy
关键词
IT governance; IT management; IT compliance; knowledge management;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
During the latest years, IT governance has become more and more important, for several reasons: the increasing pervasivity of IT in business organization, management and administration requires a veritable governance activity, to strategically orient decision making about IT investments and management; - the role of information systems in administrative data processing requires a special focus on information security and process control; - the need to keep down IT budget forces to balance IT capital expenditure and operational expenditure and to increase IT systems productivity and information value. More of the attention on IT Governance is captured by compliance, owing to the recent financial scandals and the severe rules regarding information systems audit and control. Companies need to comply with these rules, but it requires important investments, considered not strategic but only necessary (Remenyi et. Al. 2000). However, companies should analyse the compliance requirements and to implement an IT governance system, not only to comply with legal rules, but also to improve the strategic alignment between IT and business and to optimise value creation by IT compliance investments (Ventrakaman and Henderson 1996, Van Grembergen 2003). Therefore, IT governance should have a complex set of goals, such as: - to standardize and unify processes; - to align information delivery with business needs; to control IT initiatives cost; - to comply with external requirements. These goals are often opposed and difficult to pursue, because: - they regard cross functional enterprise systems; - they are strictly linked; - they concern large databases and applications, very difficult to control. To optimise IT compliance it is useful to define a roadmap to IT compliance, orienting these activity to value creation, by realising scale, scope and experience economies in IT compliance activities. The accomplishment of this roadmap is the automation of IT compliance processes, using Governance, Risk and Compliance (GRC) standard solutions or developing in house systems, such as Enterprise Information Management (EIM) systems, to automatically manage processes, data and information security, access control, system performance and to data usability. In this paper, IT compliance topic is introduced, to define how to orient IT compliance to value creation; GRC systems and EIM systems are described, with their different cost and benefits for companies. Aim of the paper is to define how to develop compliance automated systems, to save money and enhance information integration and value. Observations and conclusions derive from practical experience of the author, participating to a project of EIM implementation in a major Italian company.
引用
收藏
页码:111 / 121
页数:11
相关论文
共 50 条
  • [41] Study on the Design and Application of Enterprise Information Management System
    Xu, Youfeng
    2013 3RD INTERNATIONAL CONFERENCE ON EDUCATION AND EDUCATION MANAGEMENT (EEM 2013), 2013, 27 : 616 - 620
  • [42] Study on technology management information system for foundry enterprise
    Wang, J.Q.
    Kang, J.W.
    Huang, T.Y.
    Tang, Y.Z.
    Hu, Y.M.
    Lei, P.
    Zhuzao/Foundry, 2001, 50 (10):
  • [43] Distributed jewelry enterprise resource management information system
    School of Education Science and Technology, Zhejiang University of Technology, Hangzhou, China
    Int. Conf. Electron., Commun. Control, ICECC - Proc., 2011, (3672-3674):
  • [44] Research on enterprise management information system for mass customization
    Xu, XS
    Gu, XJ
    Proceedings of the 2005 International Conference on Management Science & Engineering (12th), Vols 1- 3, 2005, : 17 - 22
  • [45] Study on the Design of Enterprise Comprehensive Information Management System
    Dan, Wang
    PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON EDUCATION, MANAGEMENT, COMPUTER AND SOCIETY, 2016, 37 : 1288 - 1291
  • [46] A Novel Approach for Optimizing Governance, Risk management and Compliance for Enterprise Information security using DEMATEL and FoM
    Ramalingam, Dharmalingam
    Arun, Shivasankarappa
    Anbazhagan, Neelamegam
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 365 - 370
  • [47] Information management for the agile enterprise
    Wainwright, CER
    Leonard, R
    Barber, KD
    DESIGN OF COMPUTING SYSTEMS: COGNITIVE CONSIDERATIONS, 1997, 21 : 325 - 330
  • [48] Enterprise information systems interoperability for asset lifecycle management to enhance circular manufacturing
    Polenghi, Adalberto
    Acerbi, Federica
    Roda, Irene
    Macchi, Marco
    Taisch, Marco
    IFAC PAPERSONLINE, 2021, 54 (01): : 361 - 366
  • [49] Collaborative infrastructure using enterprise information portals and value webs
    Davis, BC
    Ellison-McGee, S
    INTERNATIONAL CONFERENCE ON POLITICS AND INFORMATION SYSTEMS: TECHNOLOGIES AND APPLICATIONS, PROCEEDINGS, 2003, : 306 - 312
  • [50] Design and implementation of enterprise information management system and dynamic cost management
    Gao, LinHua
    Lin, Min
    PROCEEDINGS OF THE 2017 7TH INTERNATIONAL CONFERENCE ON ADVANCED DESIGN AND MANUFACTURING ENGINEERING (ICADME 2017), 2017, 136 : 347 - 353