Collaborative risk method for information security management practices: A case context within Turkey

作者:

Highlights:

摘要

In this case study, a collaborative risk method for information security management has been analyzed considering the common problems encountered during the implementation of ISO standards in eight Turkish public organizations. This proposed risk method has been applied within different public organizations and it has been demonstrated to be effective and problem-free. The fundamental issue is that there is no legislation that regulates the information security liabilities of the public organizations in Turkey. The findings and lessons learned presented in this case provide useful insights for practitioners when implementing information security management projects in other international public sector organizations.

论文关键词:ISO/IEC 27001:2005,ISO/IEC 27002:2005,Information security,Risk analysis,Flow chart,Case process approach,Information security governance

论文评审过程:Available online 9 October 2010.

论文官网地址:https://doi.org/10.1016/j.ijinfomgt.2010.08.007