Risks Management relating to Information Systems Security Treatment of IT Equipment Security Risks

被引:0
作者
Baicu, Floarea [1 ]
Baicu, Andrei Mihai [2 ]
机构
[1] Hyper Univ Bucharest, Bucharest, Romania
[2] VIO TOP, Bucharest, Romania
来源
QUALITY-ACCESS TO SUCCESS | 2012年 / 13卷 / 131期
关键词
risk management; risk treatment options; risk treatment plan; controls; information systems security;
D O I
暂无
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
This article is a natural sequel of the ideas presented in the first three articles from this series of articles referring to security risk management. All efforts of an organization to identify and assess the IT system assets, related vulnerabilities and threats and to assess the risk levels are done in order to reduce the risks and ensuring a proper security level in the organisation. This paper deals the adoption of risk treatment option, selection of optimum measures for reducing the risk to an acceptable level, criteria according to which the risk is treated and the limitations affecting the risk treatment options. Chapter 4 presents a fragment from a risk treatment plan prepared based upon the authors' own experience.
引用
收藏
页码:108 / 112
页数:5
相关论文
共 8 条
  • [1] [Anonymous], 270012005 ISOCEI
  • [2] [Anonymous], 310102010 ISOCEI
  • [3] [Anonymous], 270022008 ISOCEI
  • [4] [Anonymous], 1333531998 ISOIEC TR
  • [5] [Anonymous], 270052008 ISOCEI
  • [6] Baicu F, 2012, QUAL-ACCESS SUCCESS, V13, P108
  • [7] Floarea Baicu, 2012, QUALITY ACCESS SUCCE, V13, P112
  • [8] Floarea Baicu, 2006, AUDIT SECURITY INFOR