摘要
随着信息化的发展,信息技术风险已经成为影响企业稳健发展的一个关键因素。从IT风险及其管理的概念出发,提出基于COSO的企业IT风险管理框架,并结合中国石化信息化实践经验,按照IT控制目标的要求,探索建立符合我国企业实际的IT控制体系,以提升信息化给企业带来的价值,提高企业防范风险能力。
Based on the concept of IT risk management and Sinopec IT risk control objective,a COSO-based framework for IT risk management was proposed and the route of establishing IT control system was explored to satisfy the actual requirements of Chinese enterprises,and to add the value of the information technology and enhance the enterprises'ability against any risks.
出处
《化工自动化及仪表》
CAS
北大核心
2010年第4期96-99,共4页
Control and Instruments in Chemical Industry