Master'sOpen Access

Information security management system and information security risk management methodology development

2019
0 views
0 downloads
Advisor: Dr. Öğr. Üyesi Zeynep Özlem Ocak

Abstract (EN)

Information security is the protection of information from threats in order to ensure business continuity by reducing business risks, and maximizing return on investments and business opportunities. In strategic terms, the confidentiality, integrity and availability of crucial information must be provided via an effective information security management system to ensure business continuity. In today's world, information is exposed to a growing number of threats. Thus, ensuring the information security is vital for today's interconnected business environment. Information security policies are the basis for a reliable information security system and are critical to protect the organisation's Information System (IS) resources and data. ISO 27001:2005 provides a widely-accepted information security management guideline for establishing, implementing, operating, monitoring, maintaining and improving an information security management system (ISMS). Although it is suitable for all kinds of organizations there is a lack of a comprehensive framework, supporting process model, and methodology that can enable an enterprise to implement and effectively manage information security. Thus, the purpose of this study is to examine a pharmaceutical firm's information security management system, and to develop an appropriate framework and methodology to ensure integration of information security management with other enterprise business processes.

Author

Ayfer Ekiz

How to Cite

Ayfer Ekiz (Master Thesis). Information security management system and information security risk management methodology development, 2019, Yeditepe University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Yeditepe University