Enterprise information systems within the context of information security: a risk assessment for a health organization in Turkey

被引:4
|
作者
Eroglu, Sahika [1 ]
Cakmak, Tolga [1 ]
机构
[1] Hacettepe Univ, Dept Informat Management, TR-06800 Ankara, Turkey
关键词
Enterprise Information systems; information security; risk assessment;
D O I
10.1016/j.procs.2016.09.262
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Enterprise information systems implemented in the organizations are critical assets to provide competitive advantage in changing sectoral conditions and continuity of business processes and management of enterprise resources. In this regard, information security approaches and assessment techniques are used to examine the maturity level of enterprise and determine the risks and potential solutions for enterprise information systems. This study aims to measure information systems in terms of information security and risks. On the other hand, it is also aimed to describe the potential effects of assessment techniques and tools for state organizations to manage their critical assets. In order to achieve these aims, information systems of one of the large scale health sector organizations in Turkey were assessed via an international assessment tool that is adapted to Turkish conditions in some parts like legal regulations. The results obtained through assessment tool provide the current maturity level of the organization and remark the points that should be improved for the security of information systems and the critical components such as risks, processes, people, IT reliance and technology. (C) 2016 The Authors. Published by Elsevier B.V.
引用
收藏
页码:979 / 986
页数:8
相关论文
共 50 条
  • [1] RISK ASSESSMENT INFORMATION SECURITY SYSTEMS ORGANIZATION WITH MATLAB SYSTEM
    Glushenko, Sergey
    [J]. BIZNES INFORMATIKA-BUSINESS INFORMATICS, 2013, 26 (04): : 35 - +
  • [2] Overview of Enterprise Information Needs in Information Security Risk Assessment
    Korman, Matus
    Ekstedt, Mathias
    Sommestad, Teodor
    Hallberg, Jonas
    Bengtsson, Johan
    [J]. PROCEEDINGS OF THE 2014 IEEE 18TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE (EDOC 2014), 2014, : 42 - 51
  • [3] Enterprise Risk Management and Information Systems Security Risk
    Olson, David L.
    Wu, Desheng
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON RISK MANAGEMENT & GLOBAL E-BUSINESS, VOLS I AND II, 2009, : 1 - 5
  • [4] Collaborative risk method for information security management practices: A case context within Turkey
    Ozkan, Sevgi
    Karabacak, Bilge
    [J]. INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2010, 30 (06) : 567 - 572
  • [5] A Formal Methodology for Enterprise Information Security Risk Assessment
    Bhattacharjee, Jaya
    Sengupta, Anirban
    Mazumdar, Chandan
    [J]. 2013 INTERNATIONAL CONFERENCE ON RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS), 2013,
  • [6] The importance of integration of information security management systems (ISMS) to the organization's Enterprise Information Systems (EIS)
    Luma, A.
    Abazi, B.
    [J]. 2019 42ND INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2019, : 1205 - 1208
  • [7] Enterprise architecture to enhance security and risk management of information systems
    School of Software, Tsinghua University, Beijing 100084, China
    [J]. Qinghua Daxue Xuebao, 2009, SUPPL. 2 (2073-2086):
  • [8] Developing information security metrics and measures for risk assessment of an organization
    Manuja, Prashant
    Shekhawat, Rajveer Singh
    [J]. JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2022, 25 (04): : 1195 - 1202
  • [9] Information governance: information security and access within a UK context
    Lomas, Elizabeth
    [J]. RECORDS MANAGEMENT JOURNAL, 2010, 20 (02) : 182 - +
  • [10] Security Risk Assessment of Information Systems in an Indeterminate Environment
    Basumatary, Basundhara
    Kumar, Chandan
    Yadav, Dilip Kumar
    [J]. 2021 11TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING (CONFLUENCE 2021), 2021, : 82 - 87