Hassas bilgi varlıklarının ve kişisel verilerin hukuksal düzenlemeler ile korunması ve bu kapsamda üniversiteler için bilgi güvenliği politikasının geliştirilmesi
The protection of personal data and sensitive information assets by legal regulations, and in this context the development of an informatıon security policy for universities
- Tez No: 380076
- Danışmanlar: PROF. DR. NAZAN UÇAK
- Tez Türü: Doktora
- Konular: Bilgi ve Belge Yönetimi, Hukuk, Information and Records Management, Law
- Anahtar Kelimeler: Bilgi, Güvenlik, Güvenlik politikaları, Güvenlik sistemleri, Hukuk, Hukuki işlemler, Hukuksal korunma, Kişisel bilgi yönetimi, Mevzuat, Üniversiteler, Information, Security, Security policies, Security systems, Law, Legal processes, Legal protection, Personal information management, Legislation, Universities
- Yıl: 2015
- Dil: Türkçe
- Üniversite: Hacettepe Üniversitesi
- Enstitü: Sosyal Bilimler Enstitüsü
- Ana Bilim Dalı: Bilgi ve Belge Yönetimi Ana Bilim Dalı
- Bilim Dalı: Belirtilmemiş.
- Sayfa Sayısı: Belirtilmemiş.
Özet
Güvenilir bilgiye erişim ve büyük ölçüde elektronik ortamda saklanan mevcut bilginin korunmasına yönelik ihtiyaçların arttığı günümüzde, korunacak bilgi varlıkları içinde kişisel veriler önemli bir yer tutmaktadır. Bu bilgi varlıklarının korunması ve risk yönetiminin yapılabilmesi; hukuksal, teknik ve idari boyutların dikkate alındığı bilgi güvenliği politikalarının gücü ile mümkün olabilmektedir. Üniversitelerde kişisel verilerin korunmasında ne kadar ihtiyatlı olunduğu, uygulanan güvenlik politikaları ve veri sahibinin temel hak ve özgürlüklerin nasıl korunduğu konusunda belirsizlikler bulunmaktadır. Bu tez çalışmasıyla kişisel verilerin korunmasına ilişkin hususlar kapsamlı bir bilgi güvenliği modeli ve hukuksal koşullar çerçevesinde değerlendirilerek, üniversiteler için uygulanabilir bir bilgi güvenliği politikasının geliştirilmesi ve üniversitelerde bilgi güvenliği kültürünün oluşturulmasına katkı sağlanması amaçlanmıştır. Çalışmada Türk Hukuk Mevzuatında yer alan hassas bilgi varlıklarının korunması ile ilişkili düzenlemeler belirlenerek, Avrupa Birliği (AB) bilgi güvenliği politikaları kapsamında yapılan hukuksal düzenlemeler ve kuramsal bir bilgi güvenliği modeli çerçevesinde değerlendirilmiştir. Bununla beraber, Ankara'da bulunan 15 üniversitenin bilgi işlem daire başkanlığı (BİDB), personel daire başkanlığı (PDB) ve bilgi merkezlerini kapsayacak şekilde görüşme yoluyla anket uygulanmış ve alınan bilgi güvenliği önlemleri mevcut hukuksal düzenlemeler çerçevesinde değerlendirilmiştir. Çalışma sonucunda; yasal düzenlemelerin yeterli ve önleyici nitelikte olmadığı, üniversitelerde kişisel verilerin korunmasına ve verilerin güvenli olarak imha edilmesine ilişkin politikaların bulunmadığı, mevcut politika ve kurallar içinde kişisel verilerin korunmasına ilişkin maddelere yer verilmediği, veri koruma konusunun sadece teknik boyutuyla değerlendirildiği ve risk yönetiminin yapılmadığı, üniversite birimleri arasında sorumlulukların paylaşılmadığı, kişisel verileri işleyen personele veri korumaya ilişkin bilinçlendirme eğitimi verilmediği ve kişisel verileri işleyen birimlerin hangi verilerin kişisel veri olduğu konusunda dahi tereddütlerinin bulunduğu görülmektedir. Araştırma bulgularına bağlı olarak elde edilen bu sonuçlarla birlikte; kişisel verilerin korunmasına ilişkin hukuk literatürü, uluslararası bilgi güvenliği politikaları, bilgi güvenliği ve risk yönetimine yönelik uluslararası standartlar, kurumlara yönelik bilgi güvenliği denetleme raporları ve kişisel verilerin korunmasına ilişkin evrensel ilkelerden yararlanılarak üniversitelerin uygulayabileceği bir bilgi güvenliği politika önerisi geliştirilmiştir. Anahtar Sözcükler Bilgi güvenliği, kişisel veri, hassas veri, risk yönetimi, bilgi güvenliği politikası
Özet (Çeviri)
Today, with the significant increase in the need for the access to reliable information and for the protection of available information stored electronically; personal data has become the one of the most important information assets that must be protected. The protection of these information assets and the implementing a risk management are only possible with the power of information security policies considering legal, technical, and administrative dimensions. There are some uncertainties about how universities are cautious in the protection of personal data, whether they implement a security policy, and how they protect the fundamental rights and freedoms of the data subject. In this thesis study, it has been aimed to make an information security policy that can be applied in universities in order to protect personal data, and to contribute to the creation of information security culture by evaluating the matters relating to the protection of personal data within the framework of a comprehensive information security model and the legal conditions. In this study, upon determining the regulations related to the protection of sensitive information assets in the Turkish Law Legislation, these regulations have been evaluated within the scope of the legal regulations made under the European Union (EU) information security policies and in the framework of a theoretical information security model. In addition, by applying a questionnaire through interviews with the computer centers, the directorate of personnel affairs and the libraries of 15 universities in Ankara; the adequacy of the information security policies of universities has been examined and their compatibility with the existing legal regulations has been investigated. The results of the study show that the legal regulations are not adequate and preventive in nature, the universities do not have any security polies concerning the protection and the safe destruction of personal data, existing policies and rules do not include any articles concerning the protection of personal data, the issue of data protection is evaluated only within the scope of technical aspects and there is not any risk management, the responsibility is not shared within the units of universities, training for personal data protection awareness is not provided for the staff responsible for data processing, and the units responsible for the data processing have hesitation even in deciding whether data is personal or not. In addition to the results obtained based on the findings of the study, an information security policy that can be applied in universities in order to protect personal data has been developed within the framework of the legal literature related to the protection of personal information assets, international information security policies, international standards for information security and risk management, information security inspection reports for institution, and the universal principles relating to the protection of personal data. Keywords Information security, personal data, sensitive data, risk management, information security policy
Benzer Tezler
- Helisel yayların statik karakteristiklerini ölçme ve kontrol etme cihazının tasarımı ve imalatı
Design and manufacture of a device measuringand controlling the static characteristics of helical springs
MUAMMER MUSULLUOĞLU
Yüksek Lisans
Türkçe
1987
Makine MühendisliğiGazi ÜniversitesiMakine Mühendisliği Ana Bilim Dalı
DOÇ. DR. FEVZİ ERCAN
- İdrar kültürlerinden izole edilen coag (-) staphylococcus (s. epidrmidis ve s. saprophyticus)'ların idrar yolu enfeksiyonlarındaki yeri
The Place of coag (-) staphylococcus to the urinary tract infectron which are isolated from the urine cultures
SUMRU ÇITAK(KORMAN)
- Laktat dehidrogenaz tayini için klinik kullanıma uygun yöntem araştırması
The investigation of a suitable method for the determination of lactate dehidrogenase in routine analysis
SEVTAP BAKIR ÇETİNTARAKÇI
Yüksek Lisans
Türkçe
1984
BiyokimyaCumhuriyet ÜniversitesiBiyokimya Ana Bilim Dalı
YRD. DOÇ. DR. AHMET AKER
- Tekstil boyamacılığında atık flottede boyama imkanları üzerine araştırma
Başlık çevirisi yok
MEHMET YAKARTEPE
Yüksek Lisans
Türkçe
1985
Tekstil ve Tekstil MühendisliğiEge ÜniversitesiTekstil Mühendisliği Ana Bilim Dalı
YRD. DOÇ. DR. KERİM DURAN
- IgM, IgG ve lgA romatoid faktörlerin değişik artritli hasta gruplarında mikro-ELISA test yöntemiyle ölçülmesi
Başlık çevirisi yok
BAHRİYE KEŞ