Governance, risk management and compliance of information technologies (IT GRC) is the responsibility of the company’s executives. The IT GRC responds to the important concerns of information systems managers, to ensure the necessary changes in the Information System (IS) over time, and enable it to meet the needs of risk mitigation, regulatory compliance, value creation and strategic alignment. Like a large number of organizations' activities, the IT GRC has to find a solution that is equipped through IS applications. Although these tools do exist, they are never developed by considering the IT GRC processes as a whole. We respond to this lack of consideration by proposing an intelligent and distributed platform of risk, governance and compliance of information systems that deploys a variety of IT GRC best practices and frameworks and makes an intelligent choice under constraints and parameters of the best framework to evaluate the objectives and processes in question. EAS-COM (communication system dedicated to the IT GRC platform) is our second proposal in this work: it ensures end-to-end communication between the different layers of the proposed IT GRC platform. This approach is based on Multi-Agent System (MAS) intelligence to manage the interactions between the distributed systems of the IT GRC platform.
Read full abstract