ADOPTION OF STANDARD FOR INFORMATION SECURITY ISO/IEC 27001 IN BOSNIA AND HERZEGOVINA

被引:0
|
作者
Skopak, Anis [1 ]
Sakanovic, Semir [1 ]
机构
[1] Int Burch Univ, Ilidza, Bosnia & Herceg
关键词
ISO/IEC; 27001; International organization for standardization; Information security management system; ISO; ISMS;
D O I
暂无
中图分类号
TU98 [区域规划、城乡规划];
学科分类号
0814 ; 082803 ; 0833 ;
摘要
When it comes to security, no company in the world can be too cautious. Many companies own and use different systems for protection of data and information from intentional or non-intentional loss, unauthorized access, or abuse. However, the legal aspects of information security systems are well known in order for system to be internationally accepted and adopted. Because of this, the standard ISO/IEC 27001, which ensures positioning in relation to competition through marketing usage of this certificate, fulfills all requirements of the client for information security; reducing the risks associated with information relevant for the organization, reducing operating costs for the prevention of complaints and other incidents, and optimization of the process because the tasks in the organization are clearly defined and understood. ISO/IEC 27001 process of certification is carried out by a certification body that is accredited by schemes that are under the supervision of the IAF (International Accreditation Forum), as only these certificates are a guarantee of global standard acceptance. This study has examined the surveys of twenty (20) large companies, whose scope guarantees the suitability to this standard, and explored the way of implementation, and more importantly that the certification companies in Bosnia and Herzegovina offer this feature. In the end we compared the results of this study with the results from the region and the world.
引用
收藏
页码:35 / 42
页数:8
相关论文
共 50 条
  • [1] Information security fortification by ontological mapping of the ISO/IEC 27001 standard
    Fenz, Stefan
    Goluch, Gernot
    Ekelhart, Andreas
    Riedl, Bernhard
    Weippl, Edgar
    [J]. 13TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING, PROCEEDINGS, 2007, : 381 - +
  • [2] ADOPTION OF THE INFORMATION SECURITY MANAGEMENT SYSTEM STANDARD ISO/IEC 27001: A STUDY AMONG GERMAN ORGANIZATIONS
    Mirtsch, Mona
    [J]. INTERNATIONAL JOURNAL FOR QUALITY RESEARCH, 2023, 17 (03) : 747 - 768
  • [3] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [4] AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD
    de la Rosa Martin, Tonyse
    [J]. REVISTA UNIVERSIDAD Y SOCIEDAD, 2021, 13 (05): : 495 - 506
  • [5] Information Security Risk Management: Handbook for ISO/IEC 27001
    Lomas, Elizabeth
    [J]. RECORDS MANAGEMENT JOURNAL, 2011, 21 (03) : 239 - +
  • [6] Exploring the Adoption of the International Information Security Management System Standard ISO/IEC 27001: A Web Mining-Based Analysis
    Mirtsch, Mona
    Kinne, Jan
    Blind, Knut
    [J]. IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2021, 68 (01) : 87 - 100
  • [7] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10
  • [8] Information security and value creation: The performance implications of ISO/IEC 27001
    Podrecca, Matteo
    Culot, Giovanna
    Nassimbeni, Guido
    Sartor, Marco
    [J]. COMPUTERS IN INDUSTRY, 2022, 142
  • [9] Information security and value creation: The performance implications of ISO/IEC 27001
    Podrecca, Matteo
    Culot, Giovanna
    Nassimbeni, Guido
    Sartor, Marco
    [J]. Computers in Industry, 2022, 142
  • [10] Der Standard ISO/IEC 27001:2013
    Kai Jendrian
    [J]. Datenschutz und Datensicherheit - DuD, 2014, 38 (8) : 552 - 557