| Naslov: | Information security in risk management systems : Slovenian perspective |
|---|
| Avtorji: | ID Bernik, Igor (Avtor) ID Prislan Mihelič, Kaja (Avtor) |
| Datoteke: | https://www.fvv.um.si/rv/arhiv/2011-2/07_Bernik-Prislan-E.html
https://www.fvv.um.si/rv/arhiv/2011-2/07_Bernik-Prislan.pdf
|
|---|
| Jezik: | Angleški jezik |
|---|
| Vrsta gradiva: | Znanstveno delo |
|---|
| Tipologija: | 1.01 - Izvirni znanstveni članek |
|---|
| Organizacija: | FVV - Fakulteta za varnostne vede
|
|---|
| Opis: | Purpose:
Modern organizations are no longer able to operate and achieve their goals without information technology. The only stability in the modern world is change, and users adjust to them, as do the threats to information technology. Therefore, the only way to control threats to information security is to execute a process of risk management, which enables organizations to manage threats. This paper introduces various ways of managing information security threats and researches the existence of risk management systems in Slovenia.
Design/Methods/Approach:
The study focused on the research of the perception of information security risk management among Slovenian organizations. For this purpose, research has been conducted in different organizations. The results of this research revealed that threats to information security are largely not fully comprehended. Moreover, the structure of risk management systems depends completely on each individual organization. The problem is therefore the fact that there are as many systems as there are organizations. In theory, any information system must be examined thoroughly before risk management systems are established. It is important to know the weaknesses of the system, possible threats to it and ways of attack, and what consequences follow.
Findings:
Risks can be managed in different ways. Organizations choose mostly among the following approaches: (1) informal or unsystematic approach; (2) general approach, which provides the same protection mechanism for every organizational level; (3) exact approach, which refers to an analysis of the entire information system; (4) a combination of a general and an exact approach. When organizations choose their approach, they establish the control mechanisms. With these mechanisms it is possible to simply avoid risks, mitigate their consequences, accept a particular risk, or introduce adequate security mechanisms. Due to continual changes such systems must be constantly evaluated and improved. This means that systems must be constantly adjusted to new types of threats. By establishing a safe information system, organizations can consider different trends, recommendations and effective practices; for instance the ISO 27000 series of standards. In the process of managing information security, it is of great significance to establish a risk management system, to be able to recognize the most exposed areas, and to protect them accordingly.
Research limitations:
Research results cannot be generalized due to the relatively small number of companies interviewed.
Practical implications:
This paper represents a useful source of information for companies establishing information security risk management systems, and it represents the basis for further research.
Originality/Value:
Guidelines for establishing a secure information system and forms conclusions on how these guidelines are considered in practice are represented. The study has original value because it is based on a research of the current state of risk management procedures in different organizations. Organizations can consider different guidelines, recommendations and good practices for establishing their own effective information security. Findings show that defining management responsibility, identifying key vulnerabilities and securing them, are the three most significant elements in effective risk management and maintenance of information security. |
|---|
| Ključne besede: | informacijski sistemi, informacijska varnost, grožnje, tveganje, management, Slovenija |
|---|
| Status publikacije: | Objavljeno |
|---|
| Verzija publikacije: | Objavljena publikacija |
|---|
| Leto izida: | 2011 |
|---|
| Št. strani: | str. 208-221 |
|---|
| Številčenje: | Letn. 13, št. 2 |
|---|
| PID: | 20.500.12556/DKUM-76264  |
|---|
| UDK: | 004.056(497.4) |
|---|
| COBISS.SI-ID: | 2170858  |
|---|
| ISSN pri članku: | 1580-0253 |
|---|
| NUK URN: | URN:SI:UM:DK:DDXE9XBK |
|---|
| Datum objave v DKUM: | 05.05.2020 |
|---|
| Število ogledov: | 1219 |
|---|
| Število prenosov: | 68 |
|---|
| Metapodatki: |  |
|---|
| Področja: | Ostalo
|
|---|
|
:
|
Kopiraj citat |
|---|
| | | | Skupna ocena: | (0 glasov) |
|---|
| Vaša ocena: | Ocenjevanje je dovoljeno samo prijavljenim uporabnikom. |
|---|
| Objavi na: |  |
|---|
Postavite miškin kazalec na naslov za izpis povzetka. Klik na naslov izpiše
podrobnosti ali sproži prenos. |