INFORMATION PROTECTION STANDARDS AND SECURITY RISKS IN INFORMATION AND COMMUNICATION SYSTEMS: EXPERIENCES FROM THE REPUBLIC OF SERBIA
Nemanja Deretić, Dejan Obućinski
Abstract
Nemanja Deretić, Dejan Obućinski
Abstract
In an area of development and implementation of computer systems, a growing problem is securityand protection of information. Networked computer systems increase the vulnerability of business informationsystems. The consequences of unauthorized access to protected information may be financial, immaterial andcombined. In the latest years, more and more business subjects apply information security management systemas a part of its risk management strategy. Information security management system is composed of policies,procedures, guidelines and related resources and activities. With this system, the organization wants to protectits information property. In addition, this approach helps in establishment, implementation, execution,monitoring, reviewing, maintaining and improving information security organizations to achieve its businessgoals. The whole system of information security management is based on the evaluation of risks and levels ofthe risk acceptance by the organization. The aim of the design is effective treatment and risk management. Thispaper is aimed at managers and employees in the field of information technologies in companies’ organizationalunits. In addition to that, this paper may be of interest to everyone involved in the process of programming andthe design of data protection systems, and the implementation of data protection standards. The paper offers anoverview of basic information about the legal regulations on data protection systems in the Republic of Serbia,the standards of electronic data interchange, and the basics of cyber crime. In addition, a section of the paper isconcerned with the identification of risks and the definition of the need for information protection. At the end, areview has been given of the information security management system in organizations and of securitytechniques.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In an area of development and implementation of computer systems, a growing problem is securityand protection of information. Networked computer systems increase the vulnerability of business informationsystems. The consequences of unauthorized access to protected information may be financial, immaterial andcombined. In the latest years, more and more business subjects apply information security management systemas a part of its risk management strategy. Information security management system is composed of policies,procedures, guidelines and related resources and activities. With this system, the organization wants to protectits information property. In addition, this approach helps in establishment, implementation, execution,monitoring, reviewing, maintaining and improving information security organizations to achieve its businessgoals. The whole system of information security management is based on the evaluation of risks and levels ofthe risk acceptance by the organization. The aim of the design is effective treatment and risk management. Thispaper is aimed at managers and employees in the field of information technologies in companies’ organizationalunits. In addition to that, this paper may be of interest to everyone involved in the process of programming andthe design of data protection systems, and the implementation of data protection standards. The paper offers anoverview of basic information about the legal regulations on data protection systems in the Republic of Serbia,the standards of electronic data interchange, and the basics of cyber crime. In addition, a section of the paper isconcerned with the identification of risks and the definition of the need for information protection. At the end, areview has been given of the information security management system in organizations and of securitytechniques.
Key concepts: Information security management, Information security, Information security standards, Computer security, Information security management system, Information system, Security information and event management, Vulnerability (computing)