Pregled bibliografske jedinice broj: 810128
Exploring the Responsibilities and Practices Behind Information Security Governance
Exploring the Responsibilities and Practices Behind Information Security Governance // Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship / Tipurić, Darko ; Kovač, Ivana (ur.).
Zagreb: Centar za istraživanje i razvoj upravljanja (CIRU), 2016. str. 328-342 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)
CROSBI ID: 810128 Za ispravke kontaktirajte CROSBI podršku putem web obrasca
Naslov
Exploring the Responsibilities and Practices Behind Information Security Governance
Autori
Jadrić, Mario ; Ćukušić, Maja ; Garača, Željko
Vrsta, podvrsta i kategorija rada
Radovi u zbornicima skupova, cjeloviti rad (in extenso), znanstveni
Izvornik
Proceedings of the 4th International OFEL Conference on Governance, Management and Entrepreneurship
/ Tipurić, Darko ; Kovač, Ivana - Zagreb : Centar za istraživanje i razvoj upravljanja (CIRU), 2016, 328-342
ISBN
978-953-8079-01-6
Skup
4th International OFEL Conference on Governance, Management and Entrepreneurship: NEW GOVERNANCE FOR VALUE CREATION - Towards Stakeholding and Participation
Mjesto i datum
Dubrovnik, Hrvatska, 15.04.2016. - 16.04.2016
Vrsta sudjelovanja
Predavanje
Vrsta recenzije
Međunarodna recenzija
Ključne riječi
Information Security; Information Security Governance; Standards
Sažetak
Companies collect large amounts of various types of sensitive data e.g. user profiles, financial data, contracts, etc. Such a large amount of data and information is becoming increasingly difficult to manage, and even harder to protect against information security threats. Studies show that the gap between the existing security threats and associated response from companies is becoming larger and more over grows at an exponential rate. In other words, information security risks increase significantly as illustrated by the growing numbers and types of security incidents and data breaches. Managing different domains of information security has been in the focus of IT professionals for couple of decades now, resulting in the definition and adoption of international standards in this area. The first standards were created as a compilation of approaches and measures to minimize information security risks. They have been amended since, due to the development of modern technological and organizational solutions providing high level of information security in business settings. Nevertheless, information security initiatives do not require complex technological solutions, but need real leadership commitment and governance. Efficient and effective information security management is not possible without clear delegation of roles and responsibilities, good planning, systematic analyses and risk assessment, as well as determining adequate controls and measures for information security protection, followed by continuous review and performance evaluation of information security related efforts. Many companies have organizational and technological solutions (policies, standards, firewalls, etc.) for managing information security in place, but they are usually fragmented within various departments and on different levels. In such cases, the management is not truly involved, and information security goals are not aligned with corporate strategy. In line with that, this paper explores the importance of information security governance in modern business environment. Namely, the emphasis will be on positioning information security governance to corporate governance in general. Then, modes for implementing information security in corporations will be discussed along with detailing out information security roles and responsibilities across a company. Central part of the paper will analyze ISO/IEC 27001, the most commonly used standard i.e. a best practice approach for managing information security in corporations to ensure confidentiality, availability and integrity of sensitive information.
Izvorni jezik
Engleski
Znanstvena područja
Ekonomija, Informacijske i komunikacijske znanosti
POVEZANOST RADA
Ustanove:
Ekonomski fakultet, Split