1,720,956 research outputs found
A structured approach to the identification of the significant risks related to enterprise mobile solutions at a mobile technology component level
Thesis (MComm)--Stellenbosch University, 2015.ENGLISH ABSTRACT: The consumerisation of mobile technology is driving the mobile revolution and
enterprises are forced to incorporate mobile solutions into their business processes
in order to remain competitive. While there are many benefits relating to the
investment in and use of mobile technology, significant risks are also being
introduced into the business. The fast pace of technological innovation and the rate
of adoption of mobile technology by employees has, however, created an
environment where enterprises are deploying mobile solutions on an ad hoc basis.
Enterprises are only addressing the risks as they are occurring and resulting in
losses. The key contributing factor to this lack of governance and management is the
fact that those charged with governance do not understand the underlying mobile
technology components.
The purpose of this research is to improve the understanding of the underlying
components of mobile technology. The research further proposes to use this
understanding to identify the significant risks related to mobile technology and to
formulate appropriate internal controls to address these risks. The findings of the
research identified the following underlying components of mobile technology: mobile
devices; mobile infrastructure, data delivery mechanisms and enabling technologies;
and mobile applications. Based on an understanding of the components and
subcategories of mobile technology, a control framework was used to identify the
significant risks related to each component and subcategory. The significant risks
identified included both risks to the users (including interoperability, user experience,
connectivity and IT support) as well as risks to the enterprise’s strategies (including
continuity, security, cost and data ownership). The research concludes by
formulating internal controls that the enterprise can implement to mitigate the
significant risks. This resulted in two matrixes that serve as quick-reference guides to
enterprises in the identification of significant risks at an enterprise specific mobile
technology component level, as well as the relevant internal controls to consider.
The matrixes also assist enterprises in determining the best mobile solutions to
deploy in their business, given their strategies, risk evaluation and control
environment.AFRIKAANSE OPSOMMING: Die mobiele revolusie word deur die verbruiker van mobiele tegnologie aangedryf en,
ten einde kompeterend te bly, word ondernemings gedwing om mobiele tegnologie
in hul besigheidsprosesse te implementeer. Terwyl daar baie voordele verbonde is
aan die investering in en gebruik van mobiele tegnologie, word die besigheid egter
ook blootgestel aan wesenlike risiko’s. Die vinnige tempo waarteen mobiele
tegnologie ontwikkel en deur werknemers aangeneem word, het egter ʼn omgewing
geskep waarin ondernemings mobiele tegnologie op ʼn ad hoc basis ontplooi.
Besighede spreek eers die risiko’s aan nadat dit reeds voorgekom het en verliese as
gevolg gehad het. Die hoof bydraende faktor tot die tekort aan beheer en bestuur
van mobiele tegnologie is die feit dat diegene verantwoordelik vir beheer, nie
onderliggend mobiele tegnologie komponente verstaan nie.
Die doel van hierdie navorsing is om die begrip van die onderliggende komponente
van mobiele tegnologie te verbeter. Die navorsing poog verder om die wesenlike
risiko’s verbonde aan mobiele tegnologie te identifiseer en om toepaslike interne
beheermaatreëls te formuleer wat die risiko’s sal aanspreek. Die bevindinge van die
navorsing het die volgende onderliggende komponente van mobiele tegnologie
geïdentifiseer: mobiele toestelle; mobiele infrastruktuur, data afleweringsmeganismes,
en bemagtigende tegnologieë; en mobiele toepassings. Gebaseer op
ʼn begrip van die komponente en subkategorieë van mobiele tegnologie, is ʼn kontrole
raamwerk gebruik om die wesenlike risiko’s verbonde aan elke komponent en
subkategorie van die tegnologie, te identifiseer. Die wesenlike risiko’s sluit beide
risiko’s vir die gebruiker (insluitend kontinuïteit, gebruikerservaring, konnektiwiteit en
IT ondersteuning) sowel as risiko’s vir die onderneming se strategieë (insluitend
kontinuïteit, sekuriteit, koste en data eienaarskap) in. Die navorsing sluit af met die
formulering van die beheermaatreëls wat geïmplementeer kan word om die
wesenlike risiko’s aan te spreek. Dit het gelei tot twee tabelle wat as vinnige
verwysingsraamwerke deur ondernemings gebruik kan word in die identifisering van
wesenlike risiko’s op ʼn onderneming-spesifieke tegnologie komponentvlak asook die
oorweging van relevante interne beheermaatreëls. Die tabelle help ondernemings
ook om die beste mobiele tegnologie vir hul besigheid te implementeer, gebaseer op
hul strategie, risiko evaluering en beheeromgewing.Master
Mobile technology risk management
CITATION: Sahd, L.M. & Rudman, R. 2016. Mobile technology risk management. Journal of Applied Business Research, 32(4):1079-1096, doi:http://dx.doi.org/10.19030/jabr.v32i4.9723.The original publication is available at http://www.cluteinstitute.com/journals/journal-of-applied-business-research-jabr/Publication of this article was funded by the Stellenbosch University Open Access Fund.Mobile technology is fast becoming an indispensable part of consumers’ lives and an essential business tool in improving productivity, streamlining business processes and remaining competitive. The mobile revolution is transforming business operations, but the pervasive nature of mobile technology also introduces new and significant risks into all areas of the businesses. In most businesses, however, the governance of mobile technology and its related risks is often disjointed and implemented in an ad hoc manner, resulting in all risks not being addressed. This lack of appropriate governance policies and procedures is a direct consequence of a lack of understanding of the technology and the speed at which new technologies are developed and adopted. If the risks are not addressed in a comprehensive manner, it could have severe consequences for a business. The objective of this research is to address this problem by using an appropriate control framework, Control Objectives for Information Technology (COBIT), to identify a comprehensive set of internal controls to address mobile technology risks at a governance, management and operational level. The research proposes a comprehensive set of internal controls which can be used by those charged with governance to manage each significant risk arising from the implementation of mobile technology.http://www.cluteinstitute.com/ojs/index.php/JABR/article/view/9723Publisher's versio
A structured approach to mitigate significant risks associated with the use of machine learning models
Thesis (MCom)--Stellenbosch University, 2020.ENGLISH SUMMARY: Many organisations find it challenging to analyse large and varied big data sets to extract relevant insights providing competitive advantage. Traditional modelling and statistical techniques are not able to effectively analyse large and varied big data sets. The use of machine learning models presents a potential solution. The problem is that governing bodies and senior management do not always understand machine learning, the significant risks associated with the use, development and deployment of machine learning models and the controls required to mitigate the risks. The aim of this research is to investigate machine learning, machine learning models, big data and data analytics, identify significant risks and recommend mitigating controls. A literature review provided a theoretical foundation for the research performed. The literature review focused on understanding machine learning, big data, data analytics, corporate governance, information and technology governance and the use of frameworks to facilitate effective governance. COBIT 2019 was selected as the most appropriate framework to identify and mitigate significant risks associated with machine learning models. To further facilitate the identification of significant risks, the core components of machine learning, as well as a machine learning development life cycle, were identified and described. The research found that machine learning consisted of four core components, namely tasks, data, algorithms and models, that are combined into a functional machine learning model through an iterative machine learning development life cycle. Using the understanding of the core components of machine learning and the machine learning development life cycle, COBIT 2019 was used to identify significant risks related to the use of machine learning models on a strategic and operational or technological level. Strategic level risks included inadequate governance and management practices, a lack of benefits realisation and a lack of skills to develop and deploy machine learning models. Operational or technological level significant risks included: (i) risks affecting the ability of machine learning models to achieve their objectives, such as cost and data and model-related risks, (ii) risks affecting the operational effectiveness of machine learning, such as information security risks, scalability and integration, and (iii)risks relating to the machine learning development life cycle. After the identification of significantrisks, mitigating controls were formulated to address the significant risks identified. These controls included appropriate governance and management practices, strategies and policies, controls over human skills and resources and organisational change management, data management controls, controls over the IT infrastructure, model validation controls, controls over vendors and third parties and controls over the machine learning development life cycle. To summarise the research a risk-and-control matrix was prepared to link the significant risks identified to the relevant mitigating controls.AFRIKAANSE OPSOMMING: Baie organisasies vind dit uitdagend om groot en veelsoortige datastelle te analiseer, ten einde relevante insigte vir mededingende voordeel te ontgin. Tradisionele modellering en statistiese tegnieke is nie effektief om groot en veelsoortige datastelle te analiseer nie. Die gebruik van masjienleermodelle (machine learning models) bied 'n moontlike oplossing. Die probleem is dat bestuursliggame en senior bestuur nie altyd masjienleer, die beduidende risiko's wat met die gebruik, ontwikkeling en ontplooiing daarvan verband hou en die kontroles wat nodig is om die risiko's te verminder, verstaan nie. Die doel van hierdie navorsing is om masjienleer, groot data (big data) en data-analise te ondersoek, beduidende risiko's te identifiseer en mitigerende kontroles aan te beveel. 'n Literatuuroorsig, gefokus op die verstaan van masjienleer, groot data, data-analise, korporatiewe bestuur, inligting-en tegnologiebestuur en die gebruik van raamwerke om doeltreffende bestuur te bewerkstellig is uitgevoer om 'n teoretiese grondslag vir die navorsing te verskaf. COBIT 2019 is gekies as die mees geskikte raamwerk om beduidende masjienleer risiko's te identifiseer en te mitigeer. Om risiko identifisering verder te vergemaklik is die kernkomponente van masjienleer, sowel as a masjienleer ontwikkelingslewensiklus, geidentifiseer en gedefinieer. Hierdie navorsing het bevind dat masjienleer uit vier kernkomponente bestaan, naamlik take, data, algoritmes en modelle, geondersteun deur ‘n iteratiewe ontwikkelingslewensiklus om die komponente in ‘n werkende masjienleermodel te omskep. COBIT 2019, die kernkomponente van masjienleer en die masjienleerontwikkelingslewensiklus is daarna gebruik om beduidende strategiese en operasionele of tegnologiese risiko's te identifiseer wat verband hou met die gebruik van masjienleermodelle. Beduidende strategiese risiko’s sluit onvoldoende korporatiewe beheer en bestuurspraktyke, 'n gebrek aan voordele verwesenliking en 'n gebrek aan masjienleer vaardighede in. Beduidende operasionele en tegnologiese risiko’s sluit in: (i) risiko's wat die verwesenliking van masjienleerdoelwitte kan belemmer, soos koste en data- en model-verwante risiko's, (ii) risiko's wat die operasionele doeltreffendheid van die masjienleer belemmer, soos inligtingsekuriteitsrisiko's, skaalbaarheid en integrasie, en (iii) risiko's met betrekking tot die masjienleerontwikkelingslewensiklus. Na die identifisering van beduidende risiko's, is kontroles geformuleer om die beduidende risiko's te mitigeer. Hierdie kontroles sluit toepaslike korporatiewe beheer en bestuurspraktyke, strategiee en beleide, kontroles oor menslike vaardighede en hulpbronne en organisatoriese veranderingsbestuur, databestuursbeheer, kontroles oor die IT-infrastruktuur, modelvalidering, beheer oor derde partye en beheer oor die masjienleerontwikkelingslewensiklus in. 'n Risiko-en-beheer-matriks is voorberei om die beduidende risiko's te koppel aan die betrokke mitigerende kontroles.Master
Significant risks relating relating to mobile technology
CITATION: Sahd, L.-M. 2016. Significant risks relating relating to mobile technology. Journal of Economic and Financial Sciences, 9(1):291-309.The original publication is available at https://jefjournal.org.zaThe consumerisation of mobile technology is driving the large-scale adoption of mobile solutions in business models. Each component of mobile technology, however, introduces specific risks into the enterprise and those charged with governance are often unaware of all the risks they are exposed to. The research addresses this problem by using the processes of Control Objectives for Information and Related Technology (COBIT) to identify the significant risks introduced by mobile technology and linking these risks to the components of the technology. The resulting risk matrix determines an enterprise’s risk exposure given its mobile technology component landscape and identifies the most effective technology to deploy given the enterprise risk tolerance levels. The matrix also promotes improved alignment through the development of IT governance systems that correlate with business strategies and by using the understanding of IT capabilities to drive business strategies.https://jefjournal.org.za/index.php/jef/article/view/43Publisher's versio
Going Beyond Counting First Authors in Author Co-citation Analysis
The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation
counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings
are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that
only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into
account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed
Variations on the Author
“Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
Appropriate Similarity Measures for Author Cocitation Analysis
We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis
Dispelling the Myths Behind First-author Citation Counts
We conducted a full-scale evaluative citation analysis study of scholars in the XML research field to explore just how different from each other author rankings resulting from different citation counting methods actually are, and to demonstrate the capability of emerging data and tools on the Web in supporting more realistic citation counting methods. Our results contest some common arguments for the continued
use of first-author citation counts in the evaluation of scholars, such as high correlations between author rankings by first-author citation counts and other citation
counting methods, and high costs of using more realistic citation counting methods that are not well-supported by the ISI databases. It is argued that increasingly available digital full text research papers make it possible for citation analysis studies to go beyond what the ISI databases have directly supported and to employ more
sophisticated methods
- …
