MANAGEMENT OF INFORMATION RISKS OF THE ENTERPRISE IN THE CONDITIONS OF DIGITALIZATION
Анотація
The features of modern information risk management are considered and analyzed in the article. The influence of digitalization of enterprises on information security is analyzed. Approaches to the interpretation of the definition of "information risk" are analyzed. It is indicated that information risks arise primarily from the creation, transmission, storage, processing, use of information in practical activities using digital media and other information and communication means. The purpose of risk management of information risks of the enterprise is to minimize the costs of counteracting information risks and the overall losses from them. Information risks include risks of internal and external fraud, unauthorized use of company resources, breach of confidentiality, integrity and reliability of information, etc. The proposed information risk management system provides for the implementation of such procedures as identification of information risks, analysis of information risks, selection and implementation of the method of reducing information risks, control of information risks. It has been found that it is advisable to use models based on international standards when modeling information threats. Popular practices used in practice are based on standards such as ISO / IEC 27005: 2011, NIST SP800-30, EBIOS, OCTAVE. It is determined that quantitative calculation of risk situations is used first of all when it is necessary to choose the optimal variant of solving a risk situation. Enterprise information risk management techniques include organizational and technological measures. It is established that the methods of information risk management of the enterprise include organizational and technological measures. Organizational methods of risk reduction include: risk aversion, loss prevention, loss minimization, transfer of risk control, risk sharing method, information seeking, control or risk management. Technology measures include the accumulation of risk information, their assessment and analysis, ranking and informing management about the implementation of risks and the likelihood of their occurrence, the use of modern data protection systems (obstruction, access control, masking, regulation, etc.). It is established that the choice of information risk management methodology in each individual case depends on the specific activity of the enterprise.
Класифікація
Ідентифікатори
Рецензії (0)
Написати рецензіюРецензій ще немає. Будьте першим!
Схожі роботи
INNOVATIVE APPROACH IN THE ESTIMATOLOGY OF FINANCIAL INSTITUTIONS ECONOMIC SECURITY: POSSIBILITIES OF USE IN MANAGEMENT AND REGULATORY ACTIVITY WITHIN THE MEANS OF PROVISION OF THE STATE FINANCIAL SECURITY
Схоже за: Economic Issues in Ukraine · Business and Economic Development · Banking, Crisis Management, COVID-19 Impact
Essence and evolution of the concept «economic security of the enterprise»
Схоже за: Economic Issues in Ukraine · Business and Economic Development · Banking, Crisis Management, COVID-19 Impact
Assessment of financial and economic security of Ukraine in conditions of foreign banking development
Схоже за: Economic Issues in Ukraine · Business and Economic Development · Banking, Crisis Management, COVID-19 Impact
Problems and prospects of state financial control and analysis of local budget execution
Схоже за: Economic Issues in Ukraine · Business and Economic Development · Banking, Crisis Management, COVID-19 Impact
Restructuring of problem loans of banks in times of crisis
Схоже за: Economic Issues in Ukraine · Business and Economic Development · Banking, Crisis Management, COVID-19 Impact
Peculiarities of using tax compliance tools at enterprises engaged in foreign economic activities
Схоже за: Economic Issues in Ukraine · Business and Economic Development · Banking, Crisis Management, COVID-19 Impact