Javascript must be enabled to continue!
RİSK MANAGEMENT IN İNFORMATİON EXCHANGE
View through CrossRef
The field of risk management is one of today's most main fields. Risk-free business is not possible. It is necessary to calculate the risks that arise in every business so that it does not create any problems for us later. Although it is not possible to reduce the risk to zero, it is possible to reduce the risk. One of the most utilised areas of the risk term is the risk of informatisation. Ensuring the confidentiality, integrity and transparency of information is one of today's main problems. For this purpose, some standards and standards have been prepared. Some of these standards are ISO 27001 and ISO 31000.
With the widespread use of computer networks and the Internet, Information Security has become very important. Since organisations are mostly dependent on information, technology and systems, Information Security is of vital importance and the need to protect information assets from damage arises from this. On the other hand, many companies still do not take adequate and necessary measures in information security.
As a result, many companies, including many large and international organisations, are under serious threat. In order to be able to recognise these threats in advance and to reduce the severity of threats, it is necessary to comply with the Risk Management and the whole of the ISO 27001:2022 standard. Today, organisations face a risk in almost every transaction. It is necessary to identify and evaluate the risks that may arise during the functions of the institutions carefully and in detail in advance and to take measures to minimise or completely eliminate these risks. In this article, the steps to be taken to meet the requirements of ISO 27001:2022 Information Security Management System Risk Management are analysed step by step and a software has been developed to enter the data containing these requirements and receive the relevant reports. In this context, the ISO 27000:2018 family referenced by the ISO 27001:2022 Standard has been examined.
The ways in which risk analyses can be performed and how risk improvement can be achieved have been investigated. As a result of the study, all these have been brought together in a software and made reportable.
The security structure should be established by taking into account the differences of the organisation and the system. Afterwards information security risk management and methods that are not fully detailed in the standard.
A documentation by analysing assets under a corporate information processing structure
has been created. To create this structure and at the same time to create a dynamic
a basic level of information security control software has been produced to provide control.
Keywords: Information, information security, risk, risk management, risk analysis.
Education Support and Investment Fund NGO
Title: RİSK MANAGEMENT IN İNFORMATİON EXCHANGE
Description:
The field of risk management is one of today's most main fields.
Risk-free business is not possible.
It is necessary to calculate the risks that arise in every business so that it does not create any problems for us later.
Although it is not possible to reduce the risk to zero, it is possible to reduce the risk.
One of the most utilised areas of the risk term is the risk of informatisation.
Ensuring the confidentiality, integrity and transparency of information is one of today's main problems.
For this purpose, some standards and standards have been prepared.
Some of these standards are ISO 27001 and ISO 31000.
With the widespread use of computer networks and the Internet, Information Security has become very important.
Since organisations are mostly dependent on information, technology and systems, Information Security is of vital importance and the need to protect information assets from damage arises from this.
On the other hand, many companies still do not take adequate and necessary measures in information security.
As a result, many companies, including many large and international organisations, are under serious threat.
In order to be able to recognise these threats in advance and to reduce the severity of threats, it is necessary to comply with the Risk Management and the whole of the ISO 27001:2022 standard.
Today, organisations face a risk in almost every transaction.
It is necessary to identify and evaluate the risks that may arise during the functions of the institutions carefully and in detail in advance and to take measures to minimise or completely eliminate these risks.
In this article, the steps to be taken to meet the requirements of ISO 27001:2022 Information Security Management System Risk Management are analysed step by step and a software has been developed to enter the data containing these requirements and receive the relevant reports.
In this context, the ISO 27000:2018 family referenced by the ISO 27001:2022 Standard has been examined.
The ways in which risk analyses can be performed and how risk improvement can be achieved have been investigated.
As a result of the study, all these have been brought together in a software and made reportable.
The security structure should be established by taking into account the differences of the organisation and the system.
Afterwards information security risk management and methods that are not fully detailed in the standard.
A documentation by analysing assets under a corporate information processing structure
has been created.
To create this structure and at the same time to create a dynamic
a basic level of information security control software has been produced to provide control.
Keywords: Information, information security, risk, risk management, risk analysis.
Related Results
Tools for hiding currency risk: application of data analysis
Tools for hiding currency risk: application of data analysis
Purpose- The fluctuations in the exchange rate expose companies that perform foreign currency forward transactions to exchange rate risk. Exchange rate risk affects the internation...
Exchange rate and industrial output in Nigeria: sectoral analysis
Exchange rate and industrial output in Nigeria: sectoral analysis
Purpose- The Nigerian manufacturing sector is performing below expectations despite government’s proactive measures to address critical issues in the sector. A key driver of perfor...
Artificial Intelligence and Machine Learning Used as an Enabler for Dynamic Risk Management
Artificial Intelligence and Machine Learning Used as an Enabler for Dynamic Risk Management
Abstract
Applying big data, data science, business process automation (BPA) and domain expertise to operational and project risk in the upstream O&G space, will ...
Testing For Long Memory In The South Asian Foreign Exchange Rates
Testing For Long Memory In The South Asian Foreign Exchange Rates
Exchange rate movements have a great impact on the political and Economic stability of a country. Understanding the dynamic behavior of exchange is extremely important for decision...
Ion Exchangers
Ion Exchangers
AbstractThe article contains sections titled:1.Introduction2.Structures of Ion‐Exchange Resins2.1.Polymer Matrices2.2.Functional Groups2.2.1.Cation‐Exchange Resins2.2.2.Anion‐Excha...
DETERMINANTS OF REAL EXCHANGE RATE IN ETHIOPIA
DETERMINANTS OF REAL EXCHANGE RATE IN ETHIOPIA
Real exchange rate has direct effects on trade particularly on international trade and has indirect effects on productions and employments, so it is crucial to understand the facto...
Digital product data exchange in semantic service-oriented architecture
Digital product data exchange in semantic service-oriented architecture
Purpose
The purpose of this paper is to introduce a new method of ontology-based digital product data exchange. The digital product data are enriched with virtual...
Enterprise risk management and bow ties: going beyond patient safety
Enterprise risk management and bow ties: going beyond patient safety
Purpose
The growing importance of risk management programmes and practices in different industries has given rise to a new risk management approach, i.e. enterprise risk management...

