18.12.2012 Views

Proceedings

Proceedings

Proceedings

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Aspect Focus<br />

Systems<br />

Development<br />

A systems<br />

development unit or<br />

department, or a<br />

particular systems<br />

development project.<br />

Issues<br />

Probed<br />

in order to meet those<br />

requirements. Threats from the<br />

network are represented by<br />

virus attacks and phishing<br />

attempts, and vulnerabilities<br />

pertain to the ill-managed acces<br />

authorisations in the<br />

enterprises’ own network and<br />

inadequate encryptions for<br />

inbound and outbound<br />

transmissions.<br />

How business requirements<br />

(including information security<br />

requirements) are identified;<br />

and how systems are designed<br />

and built to meet those<br />

requirements. Vulnerabilities<br />

can be caused by inadequate<br />

testing in the development<br />

stage of the systems and<br />

products and threats can arise<br />

from fatal errors neglected in<br />

the development phase.<br />

~ 451 ~<br />

How they affect the perspectives<br />

set in BSC<br />

Internal process perspective:<br />

through the efficiency of<br />

transmissions between terminals in<br />

the programming dept.<br />

Financial perspective: through the<br />

costs required to build and mentain<br />

the network<br />

Learning and innovation: through<br />

the WAN acces to international<br />

scientific databases<br />

User perspective: through concern<br />

shown towards their needs before<br />

setting changes<br />

Internal process perspective:<br />

through internal procedures used to<br />

identify and encounter possible<br />

threats.<br />

Financial perspective: through the<br />

value added to the market value of<br />

the enterprise by the implemented<br />

system<br />

Learning and innovation: through<br />

the percentage of innovation in the<br />

actual development<br />

*As Cisco Systems shows, the rising prices of IT sector stocks are volatile and depends on competitors’<br />

decisions as well as the brokers’ negotiation skills (R.D. Loghin, „Implicaţiile contabile ale achiziţiilor<br />

de fotbalişti de către cluburile de fotbal,” 2010).<br />

The ever-present shadow of vulnerabilities and threats to the system, as well as<br />

classical problems, can prevent meeting organisational objectives, a fact that can be<br />

checked through a set of measures meant to support active performance monitoring<br />

efforts, and revealed through statistical, operational and accounting evidence.<br />

Measuring performance and risk converge at a common ground, through different<br />

trajectories: measuring performance becomes more risk-oriented through a set of<br />

performance measures that can detect signals of weakness from the enviroment in a<br />

timely fashion; risk measurement becomes more performance-oriented as it connects<br />

potential threats and opportunities to the enterprises’ strategic objectives.<br />

There are different studies in which, besides the classical performance oriented BSC,<br />

there are references to approaches regarding enterprise-wide risk management.<br />

(Mamoru, 2004; Nagumo, 2004; Beasley et. al. 2006; Woods, 2007). The set of<br />

measures, in order for a more efficient layout, are structured into four perspectives,<br />

and those are: user perspective, financial perspective, internal process perspective and<br />

a learning and innovation perspective.<br />

3.1. User perspective<br />

We chose to replace the customer perspective with the user perspective, as the<br />

recipients of information technology aren’t restricted to customers. Users is a term to<br />

include all those who use information systems developed and mantained by the<br />

enterprise. They have the ability to interact with the supplier and notify it about the<br />

degree of those interactions. The GUI interface is intuitive, but for many users there<br />

needs to be a support system capable of receiving calls and complaints. The enterprise

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!