The Systemic Approach to Information Protection in Relation to Risk in an Integrated Information Security System

Article Preview

Abstract:

This paper presents an approach to the risk of information security. By taking into consideration how critical it is for a system, each category of information should be associated with a correspondent level of security risk and each level of security risk must be defined by appropriate measures to control the risks for information security. Equally important is how many levels of security risk are defined for information, or how they are classified. It is critical, however, that the model adopted reflects all the objectives that the system requires.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

689-694

Citation:

Online since:

May 2015

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2015 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

* - Corresponding Author

[1] S. Popa, Concepts information security in: Security of the information systems, Alma Mater Publishing, Bacau, 2007, p.6.

Google Scholar

[2] ISO Guide 73, Risk Management – Vocabulary – Guidelines for use in standards, Geneva, (2002).

Google Scholar

[3] NIST – SP 800 – 30, Risk Management Guide for Information Technology Systems, July (2002).

Google Scholar

[4] B. Blakley, E. McDermott, D. Geer, Information Security is Information Risk Management, ACM Digital Library, New Mexico, USA, (2001).

Google Scholar

[5] D. Oprea, Protection and Security Information, Polirom Publishing, Iași, (2003).

Google Scholar

[6] M. Harkins, The misperception of risk in: Managing Risk and Information Security, Apress Media, 2013, pp.15-16.

Google Scholar