Implementing a risk management approach for optimizing information security systems

被引:0
|
作者
Petrescu, Marius [1 ]
Stegaroiu, Ion [1 ]
Braboveanu, Mioara [1 ]
Petrescu, Anca-Gabriela [1 ]
Sirbu, Nicoleta [1 ]
机构
[1] Valahia Univ Targoviste, Targoviste, Romania
关键词
Risk; risk assessment; risk management; information security; decision-making;
D O I
暂无
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
The globalization imposed a re-assessment of the security concepts, reconsideration and extension of the responsibilities in the field of information security. Organizations are continuously confronted with complex threats to information they handle and to the information systems they administer. The information security risk management emerged as an efficient and comprehensive procedure that complements the overall management of almost all aspects of our lives. Managers in very diverse types of organizations, with different missions, all incorporate risk assessment in their decision-making processes. At present, more and more managers in industry and government organizations are allocating a large part of their resources to the task of improving their understanding and approach to risk-based decision-making. The study revolves around the premises that information systems going through a systematic risk assessment and management process and associated decision-making steps would attain significantly better the information security objectives than systems that do not. The paper provides an overview of the theoretical approaches to information security risk management, as an essential step in developing effective information security systems. The article aims at advancing the current theories in order to develop adapted methods for different types of organizations.
引用
收藏
页码:304 / 309
页数:6
相关论文
共 50 条
  • [41] Information security management - A practical approach
    Dey, Manik
    2007 AFRICON, VOLS 1-3, 2007, : 587 - 592
  • [42] An Ontological Approach to Information Security Management
    Pereira, Teresa
    Santos, Henrique
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2012, : 368 - 375
  • [43] A PROCESS APPROACH TO INFORMATION SECURITY MANAGEMENT
    VONSOLMS, R
    VONSOLMS, SH
    CARROLL, JM
    COMPUTER SECURITY, 1993, 37 : 385 - 399
  • [44] PROBLEMS AND PITFALLS IN IMPLEMENTING MANAGEMENT INFORMATION SYSTEMS
    ARCHIBAL.RD
    VILLORIA, RL
    MECHANICAL ENGINEERING, 1965, 87 (03) : 82 - &
  • [45] Implementing information management systems in HTS laboratory
    Ausman, DJ
    GENETIC ENGINEERING NEWS, 1996, 16 (09): : 18 - 18
  • [46] Information systems security metrics management
    Kovacich, G
    COMPUTERS & SECURITY, 1997, 16 (07) : 610 - 618
  • [47] Information systems security metrics management
    Kovacich, Gerald
    Computers and Security, 1997, 16 (07): : 610 - 618
  • [48] Security management for radiological information systems
    Caramella, D
    Braccini, G
    Fabbrini, F
    Montanari, S
    Neri, E
    CAR '97 - COMPUTER ASSISTED RADIOLOGY AND SURGERY, 1997, 1134 : 1011 - 1011
  • [49] Security management: An information systems setting
    Warren, MJ
    Batten, LM
    INFORMATION SECURITY AND PRIVACY, 2002, 2384 : 257 - 270
  • [50] Security risk mitigation for information systems
    Page, V.
    Dixon, M.
    Choudhury, I.
    BT TECHNOLOGY JOURNAL, 2007, 25 (01) : 118 - 127