Risk Management & Business Continuity Plan as fundamental activites for an implementation and maintaining of Information Security Management Systems
Zoran Ćosić, Marija Boban, Jasmin Ćosić
Abstract
Zoran Ćosić, Marija Boban, Jasmin Ćosić
Abstract
This paper addresses to the importance of establishing the information security management systems (ISMS) as a foundation for managing an organization’s information security risks. Probability of company’s business success depends on the efficient design and implementation of the ISMS that is influenced by actual company needs and objectives, security requirements, employed business processes and organizational overall business risks. The authors in the paper give their own method of risk analysis design ed on the platform of CRAMM method and MAGERIT method which have been used by British and Spanish governments as the recommended methods for risk analysis coordinating with ISO 27000. Further the authors will give the presentation of the fundamental activities of Business Continuity Plan (BCP) methodology including the main process of operational continuity
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper addresses to the importance of establishing the information security management systems (ISMS) as a foundation for managing an organization’s information security risks. Probability of company’s business success depends on the efficient design and implementation of the ISMS that is influenced by actual company needs and objectives, security requirements, employed business processes and organizational overall business risks. The authors in the paper give their own method of risk analysis design ed on the platform of CRAMM method and MAGERIT method which have been used by British and Spanish governments as the recommended methods for risk analysis coordinating with ISO 27000. Further the authors will give the presentation of the fundamental activities of Business Continuity Plan (BCP) methodology including the main process of operational continuity
Key concepts: Business continuity, Risk management, Process management, Computer science, Information security, Information security management, Business process, Security information and event management