【24h】

Security Risk Management in complex organization

机译:复杂组织中的安全风险管理

获取原文

摘要

Security Risk Management is foundation and starting point for implementation of security measures in any organization and challenge by itself. But in complex organizations there are additional challenges, how to align IT Security Risk Management with overall Security Risk Management and later with the Company's overall Risk Management. When organization is part of some international corporation, corporative rules also need to be followed in addition to legal and regulation rules. In telecom industry in regular operations also is very important that security assessment could be performed in short timeslot as support for operational decisions. Croatian Telecom as a part of Deutsche Telecom Group is facing all of this issues in addition to ISO 27001 requirements against which the Company is certified. To solve the challenge, the Company developed three methodologies for Information Security Risk Management. All of these methodologies are merged in common Risk Register as well as aligned with the Company's Risk Management. In this paper each Information Security Risk Management methodology will be described including its application area, as well as how recognized security risks are shown in common Risk Register and how they relate to the Company's Risk Management.
机译:安全风险管理是在任何组织中实施安全措施的基础和起点,本身就是挑战。但是在复杂的组织中,还有其他挑战,如何使IT安全风险管理与总体安全风险管理保持一致,以及随后与公司的整体风险管理保持一致。当组织是某个国际公司的一部分时,除法律和法规规则外,还需要遵循公司规则。在电信行业中,正常运营也很重要,因为可以在短时间内执行安全评估以支持运营决策。除了已通过ISO认证的ISO 27001要求外,作为Deutsche Telecom Group一部分的Croatian Telecom还面临着所有这些问题。为解决这一挑战,公司开发了三种信息安全风险管理方法。所有这些方法均合并在通用风险登记册中,并与公司的风险管理保持一致。在本文中,将介绍每种信息安全风险管理方法,包括其应用领域,以及如何在公共风险登记簿中显示已识别的安全风险以及它们与公司风险管理的关系。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号