Napredna pretraga

Pregled bibliografske jedinice broj: 810128

Exploring the Responsibilities and Practices Behind Information Security Governance


Jadrić, Mario; Ćukušić, Maja; Garača, Željko
Exploring the Responsibilities and Practices Behind Information Security Governance // Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship / Tipurić, Darko ; Kovač, Ivana (ur.).
Zagreb, Hrvatska: CIRU - Governance research and development centre, 2016. str. 328-342 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)


Naslov
Exploring the Responsibilities and Practices Behind Information Security Governance

Autori
Jadrić, Mario ; Ćukušić, Maja ; Garača, Željko

Vrsta, podvrsta i kategorija rada
Radovi u zbornicima skupova, cjeloviti rad (in extenso), znanstveni

Izvornik
Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship / Tipurić, Darko ; Kovač, Ivana - Zagreb, Hrvatska : CIRU - Governance research and development centre, 2016, 328-342

ISBN
978-953-8079-01-6

Skup
4th International OFEL Conference on Governance, Management and Entrepreneurship: NEW GOVERNANCE FOR VALUE CREATION - Towards Stakeholding and Participation

Mjesto i datum
Dubrovnik, Hrvatska, 15-16.04.2016

Vrsta sudjelovanja
Predavanje

Vrsta recenzije
Međunarodna recenzija

Ključne riječi
Information Security; Information Security Governance; Standards

Sažetak
Companies collect large amounts of various types of sensitive data e.g. user profiles, financial data, contracts, etc. Such a large amount of data and information is becoming increasingly difficult to manage, and even harder to protect against information security threats. Studies show that the gap between the existing security threats and associated response from companies is becoming larger and more over grows at an exponential rate. In other words, information security risks increase significantly as illustrated by the growing numbers and types of security incidents and data breaches. Managing different domains of information security has been in the focus of IT professionals for couple of decades now, resulting in the definition and adoption of international standards in this area. The first standards were created as a compilation of approaches and measures to minimize information security risks. They have been amended since, due to the development of modern technological and organizational solutions providing high level of information security in business settings. Nevertheless, information security initiatives do not require complex technological solutions, but need real leadership commitment and governance. Efficient and effective information security management is not possible without clear delegation of roles and responsibilities, good planning, systematic analyses and risk assessment, as well as determining adequate controls and measures for information security protection, followed by continuous review and performance evaluation of information security related efforts. Many companies have organizational and technological solutions (policies, standards, firewalls, etc.) for managing information security in place, but they are usually fragmented within various departments and on different levels. In such cases, the management is not truly involved, and information security goals are not aligned with corporate strategy. In line with that, this paper explores the importance of information security governance in modern business environment. Namely, the emphasis will be on positioning information security governance to corporate governance in general. Then, modes for implementing information security in corporations will be discussed along with detailing out information security roles and responsibilities across a company. Central part of the paper will analyze ISO/IEC 27001, the most commonly used standard i.e. a best practice approach for managing information security in corporations to ensure confidentiality, availability and integrity of sensitive information.

Izvorni jezik
Engleski

Znanstvena područja
Ekonomija, Informacijske i komunikacijske znanosti



POVEZANOST RADA


Ustanove
Ekonomski fakultet, Split

Citiraj ovu publikaciju

Jadrić, Mario; Ćukušić, Maja; Garača, Željko
Exploring the Responsibilities and Practices Behind Information Security Governance // Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship / Tipurić, Darko ; Kovač, Ivana (ur.).
Zagreb, Hrvatska: CIRU - Governance research and development centre, 2016. str. 328-342 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)
Jadrić, M., Ćukušić, M. & Garača, Ž. (2016) Exploring the Responsibilities and Practices Behind Information Security Governance. U: Tipurić, D. & Kovač, I. (ur.)Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship.
@article{article, year = {2016}, pages = {328-342}, keywords = {Information Security, Information Security Governance, Standards}, isbn = {978-953-8079-01-6}, title = {Exploring the Responsibilities and Practices Behind Information Security Governance}, keyword = {Information Security, Information Security Governance, Standards}, publisher = {CIRU - Governance research and development centre}, publisherplace = {Dubrovnik, Hrvatska} }