Implementing a risk management approach for optimizing information security systems

被引:0
|
作者
Petrescu, Marius [1 ]
Stegaroiu, Ion [1 ]
Braboveanu, Mioara [1 ]
Petrescu, Anca-Gabriela [1 ]
Sirbu, Nicoleta [1 ]
机构
[1] Valahia Univ Targoviste, Targoviste, Romania
关键词
Risk; risk assessment; risk management; information security; decision-making;
D O I
暂无
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
The globalization imposed a re-assessment of the security concepts, reconsideration and extension of the responsibilities in the field of information security. Organizations are continuously confronted with complex threats to information they handle and to the information systems they administer. The information security risk management emerged as an efficient and comprehensive procedure that complements the overall management of almost all aspects of our lives. Managers in very diverse types of organizations, with different missions, all incorporate risk assessment in their decision-making processes. At present, more and more managers in industry and government organizations are allocating a large part of their resources to the task of improving their understanding and approach to risk-based decision-making. The study revolves around the premises that information systems going through a systematic risk assessment and management process and associated decision-making steps would attain significantly better the information security objectives than systems that do not. The paper provides an overview of the theoretical approaches to information security risk management, as an essential step in developing effective information security systems. The article aims at advancing the current theories in order to develop adapted methods for different types of organizations.
引用
收藏
页码:304 / 309
页数:6
相关论文
共 50 条
  • [1] A Comprehensive Risk Management Approach to Information Security in Intelligent Transport Systems
    Vogt T.
    Spahovic E.
    Doms T.
    Seyer R.
    Weiskirchner H.
    Pollhammer K.
    Raab T.
    Rührup S.
    Latzenhofer M.
    Schmittner C.
    Hofer M.
    Bonitz A.
    Kloibhofer C.
    Chlup S.
    SAE International Journal of Transportation Cybersecurity and Privacy, 2021, 4 (01):
  • [2] System dynamics based approach to risk management for security in information systems
    Trcek, Denis
    PROCEEDINGS OF THE 11TH WSEAS INTERNATIONAL CONFERENCE ON SYSTEMS, VOL 2: SYSTEMS THEORY AND APPLICATIONS, 2007, : 347 - +
  • [3] Enterprise Risk Management and Information Systems Security Risk
    Olson, David L.
    Wu, Desheng
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON RISK MANAGEMENT & GLOBAL E-BUSINESS, VOLS I AND II, 2009, : 1 - 5
  • [4] A Novel Approach for Optimizing Governance, Risk management and Compliance for Enterprise Information security using DEMATEL and FoM
    Ramalingam, Dharmalingam
    Arun, Shivasankarappa
    Anbazhagan, Neelamegam
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 365 - 370
  • [5] HIPAA and information security risk: Implementing an enterprise-wide risk management strategy
    Alberts, C
    Dorofee, A
    MEDICAL IMAGING 2001: PACS AND INTEGRATED MEDICAL INFORMATION SYSTEMS: DESIGN AND EVALUATION, 2001, 4323 : 97 - 108
  • [6] An economic modelling approach to information security risk management
    Bojanc, Rok
    Jerman-Blazic, Borka
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2008, 28 (05) : 413 - 422
  • [7] Agile Approach with Kanban in Information Security Risk Management
    Dorca, Vasile
    Popescu, Sorin
    Munteanu, Radu, Jr.
    Chioreanu, Adrian
    Peleskei, Claudius
    PROCEEDING OF 2016 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS (AQTR), 2016, : 19 - 24
  • [8] Towards a Systemic Approach for Information Security Risk Management
    Naudet, Yannick
    Mayer, Nicolas
    Feltus, Christophe
    PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 177 - 186
  • [9] A management perspective on risk of security threats to information systems
    Farahmand F.
    Navathe S.B.
    Sharp G.P.
    Enslow P.H.
    Information Technology and Management, 2005, 6 (2-3) : 203 - 225
  • [10] 1 Information Security Risk Management for Systems Engineers
    Gauvain, Tony
    INCOSE International Symposium, 1999, 9 (01): : 780 - 785