Back to Search
Start Over
Enterprise Information Systems within the Context of Information Security: A Risk Assessment for a Health Organization in Turkey
- Source :
- Procedia Computer Science. 100:979-986
- Publication Year :
- 2016
- Publisher :
- Elsevier BV, 2016.
-
Abstract
- Enterprise information systems implemented in the organizations are critical assets to provide competitive advantage in changing sectoral conditions and continuity of business processes and management of enterprise resources. In this regard, information security approaches and assessment techniques are used to examine the maturity level of enterprise and determine the risks and potential solutions for enterprise information systems. This study aims to measure information systems in terms of information security and risks. On the other hand, it is also aimed to describe the potential effects of assessment techniques and tools for state organizations to manage their critical assets. In order to achieve these aims, information systems of one of the large scale health sector organizations in Turkey were assessed via an international assessment tool that is adapted to Turkish conditions in some parts like legal regulations. The results obtained through assessment tool provide the current maturity level of the organization and remark the points that should be improved for the security of information systems and the critical components such as risks, processes, people, IT reliance and technology. (C) 2016 The Authors. Published by Elsevier B.V.
- Subjects :
- Knowledge management
Process management
information security
Computer science
Business process
Standard of Good Practice
Enterprise architecture
02 engineering and technology
Security information and event management
Competitive advantage
Enterprise system
Information security management
Enterprise life cycle
Enterprise Information systems
0502 economics and business
0202 electrical engineering, electronic engineering, information engineering
Information system
Information governance
Security management
Enterprise information system
Health sector
Enterprise Information
Enterprise planning system
Public, Environmental & Occupational Health
General Environmental Science
Enterprise systems engineering
Certified Information Security Manager
business.industry
05 social sciences
risk assessment
Enterprise information security architecture
Information security
Management information systems
Information security standards
Computer Science
General Earth and Planetary Sciences
020201 artificial intelligence & image processing
business
Risk assessment
050203 business & management
Enterprise software
Subjects
Details
- ISSN :
- 18770509
- Volume :
- 100
- Database :
- OpenAIRE
- Journal :
- Procedia Computer Science
- Accession number :
- edsair.doi.dedup.....9c2726284b778ccc401dad1e3bdb4de2
- Full Text :
- https://doi.org/10.1016/j.procs.2016.09.262