• DocumentCode
    723451
  • Title

    Security Risk Management in complex organization

  • Author

    Sedinic, Ivan ; Perusic, Tamara

  • Author_Institution
    Cyber & Data Security Sect., Croatian Telecom, Croatia
  • fYear
    2015
  • fDate
    25-29 May 2015
  • Firstpage
    1331
  • Lastpage
    1337
  • Abstract
    Security Risk Management is foundation and starting point for implementation of security measures in any organization and challenge by itself. But in complex organizations there are additional challenges, how to align IT Security Risk Management with overall Security Risk Management and later with the Company´s overall Risk Management. When organization is part of some international corporation, corporative rules also need to be followed in addition to legal and regulation rules. In telecom industry in regular operations also is very important that security assessment could be performed in short timeslot as support for operational decisions. Croatian Telecom as a part of Deutsche Telecom Group is facing all of this issues in addition to ISO 27001 requirements against which the Company is certified. To solve the challenge, the Company developed three methodologies for Information Security Risk Management. All of these methodologies are merged in common Risk Register as well as aligned with the Company´s Risk Management. In this paper each Information Security Risk Management methodology will be described including its application area, as well as how recognized security risks are shown in common Risk Register and how they relate to the Company´s Risk Management.
  • Keywords
    ISO standards; organisational aspects; risk management; security of data; Croatian Telecom; Deutsche Telecom Group; ISO 27001 requirements; IT security risk management; common risk register; complex organization; corporative rules; information security; international corporation; legal rules; operational decisions; regulation rules; Companies; ISO standards; Information security; Risk management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information and Communication Technology, Electronics and Microelectronics (MIPRO), 2015 38th International Convention on
  • Conference_Location
    Opatija
  • Type

    conf

  • DOI
    10.1109/MIPRO.2015.7160481
  • Filename
    7160481