Mapping of Enterprise Governance of IT Practices Metamodels.

Lecture Notes in Business Information Processing(2017)

引用 6|浏览16
暂无评分
摘要
The paper proposes a metamodel for ISO 27001 and its mapping with COBIT 5 using ArchiMate, an Enterprise Architecture (EA) modeling language. The metamodel's purpose is to reduce the perceived complexity of implementing these Enterprise Governance of IT (EGIT) practices simultaneously. For the ontological mapping to be complete, the metamodel is extended with the ISO Technical Specification 33052 and 33072 which propose a Process Reference Model and a Process Assessment Model respectively, specifying Base Practices and Information Items from the ISO TS 33072 - composing the ISO TS 33052 processes - mapped to ISO 27001 controls. By applying best-known metamodeling techniques and modeling principles in conjunction with the use of EA models we further simplify the understanding of different EGIT practices by providing a standard based visualization on how these practices work together. Furthermore, we present the mapping and modeling of a COBIT 5 process and respective ISO 27001 controls as an example. The paper concludes by summarizing the considerations and techniques used in this research, as well as discussing limitations and future work in this domain.
更多
查看译文
关键词
ArchiMate,COBIT 5,Enterprise Architecture,Enterprise Governance of Information Technology,ISO 27001,ISO TS 33072
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要