Geri Dön

ISO/IEC 27001 bilgi güvenliği yönetim sistemleri gereksinimlerinin veri tabanı sistemlerinde uygulanması

Application of ISO/IEC 27001 information security management systems requirements in database management systems

  1. Tez No: 759643
  2. Yazar: RABİA YILDIZ
  3. Danışmanlar: DOÇ. DR. ÇELEBİ ULUYOL
  4. Tez Türü: Yüksek Lisans
  5. Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
  6. Anahtar Kelimeler: Bilgi güvenliği, Bilgi yönetim sistemi, ISO 27001, Kurumsal bilgi güvenliği, Veri tabanı güvenliği, Veri tabanı yönetim sistemi, Information security, Information management system, ISO 27001, Corporate information security, Database security, Database management system
  7. Yıl: 2022
  8. Dil: Türkçe
  9. Üniversite: Gazi Üniversitesi
  10. Enstitü: Bilişim Enstitüsü
  11. Ana Bilim Dalı: Bilişim Sistemleri Ana Bilim Dalı
  12. Bilim Dalı: Belirtilmemiş.
  13. Sayfa Sayısı: Belirtilmemiş.

Özet

Teknoloji, hızla artması ile birlikte kurumlarda iş süreçlerinin bir parçası haline gelmiştir. Artan teknoloji ile bilgi miktarı artmış ve bilginin güvenliği büyük önem kazanmıştır. Bu sebeple, kurumların mevcut sistemlerinin ve iş süreçlerinin kesintisiz bir şekilde zarara uğramadan çalışabilmesi için Bilgi Güvenliği Yönetim Sistemini kurması ve işletmesi gerekmektedir. Ülkemizde de, eylem planları hazırlanmış bilgi güvenliği yönetim sisteminin dinamik bir yapıya kavuşturulması istenmiştir. Ülkemiz genelinde kurum ve kuruluşlar, veri tabanında bulunan verilerin öneminden dolayı doğabilecek riskleri de makul düzeye indirgemek için Bilgi Güvenliği Yönetim Sistemlerini kurmalı ve gerek kurum personelinin gerekse bilgi işlem sistemi sorumlularının standardı anlaması ve sahiplenmesini sağlamalıdır. Bu çalışma, ISO/IEC 27001 Bilgi Güvenliği Yönetim Sistemleri sertifikasyon sürecinde yer alacak birçok sorumlunun, veri tabanı kavramı ve önemini kavrayıp veri tabanı yönetim sisteminde asgari gerçekleştirilmesi gereken gereklilikleri belirlemesine, standardı anlama ve özümseme aşamasında yaşayacağı problemleri ve belirsizlikleri en aza indirgemesine fayda sağlayacaktır. Böylece veri tabanı sorumluları da; standardın dayatması gibi gördükleri BGYS süreçlerinin ek iş yükü getirmediğini aksine standardın gereksinimlerinin veri tabanı yönetim sistemleri üzerinde uygulanabilir olduğunu anlayabileceklerdir. Ayrıca bu alanda yapılacak çalışmalara bir çerçeve oluşturması açısından önem arz etmesi de beklenmektedir.

Özet (Çeviri)

With the rapid increase on technology, it has become a part of business processes in institutions. With the increasing technology, the amount of information has increased and the security of information has gained great importance. For this reason, institutions need to establish and operate the Information Security Management System so that their existing systems and business processeses can operate uninterruptedly without any damage. Action plans were also prepared in our country, and it was requested that the information security management system be given a dynamic structure. Institutions and organizations throughout our country should establish Information Security Management Systems in order to reduce the risks that may arise due to the importance of the data in the database to a reasonable level and ensure that the database supervisors understand and own the standard. At this point, it is not enough for us to find what we need because the standard says what needs to be done without mentioning how to do it and the number of academic studies prepared is low. This study will help many responsible people who will take part in the ISO/IEC 27001 Information Security Management Systems certification process, to understand the database concept and its importance, to determine the minimum requirements to be fulfilled in the database management system, and to minimize the problems and uncertainties that they will encounter during the process of understanding and assimilation of the standard. Thus, the database administrators will be able to understand that the ISMS processes, which they see as the imposition of the standard, do not impose additional workload, on the contrary, that the requirements of the standard are applicable on database management systems and will be able to see how it is done. It is also expected to be important in terms of forming a framework for the studies to be carried out in this field.

Benzer Tezler

  1. ISO 27001 bı̇lgı̇ güvenlı̇ğı̇ yönetı̇m sı̇stemlerı̇ standartlarının uygulanması: Gıda sektöründe bir uygulama

    Implementation of ISO 27001 information security management systems standards: An application in the food sector

    RIDVAN ÖZKAN

    Yüksek Lisans

    Türkçe

    Türkçe

    2024

    Bilim ve TeknolojiKaramanoğlu Mehmetbey Üniversitesi

    Yönetim Bilişim Sistemleri Ana Bilim Dalı

    DOÇ. DR. İLHAMİ TUNCER

  2. Unification of it process models into a simple framework supplemented by Turkish web based application

    Türkçe web tabanlı uygulama desteği ile birlikte BT süreç modellerinin daha basit bir çerçeve halinde birleştirilmesi

    BETÜL AYGÜN

    Yüksek Lisans

    İngilizce

    İngilizce

    2010

    Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolOrta Doğu Teknik Üniversitesi

    Bilişim Sistemleri Bölümü

    DR. ALİ ARİFOĞLU

    DR. ELİF YİLAL

  3. ISO/IEC 27001 kapsamında bilgi güvenliği yönetim farkındalığının değerlendirilmesi: Ankara ili sağlık kurumları bilgi işlem birimi çalışanları örneği

    Evaluation of information security management awareness within the scope of ISO/IEC 27001: The case of Ankara province health institutions information processing unit employees

    HADİS SOYSAL

    Yüksek Lisans

    Türkçe

    Türkçe

    2023

    Sağlık YönetimiNecmettin Erbakan Üniversitesi

    Sağlık Yönetimi Ana Bilim Dalı

    DOÇ. DR. YUSUF YALÇIN İLERİ

  4. Bilgi güvenliği yönetim sisteminin yükseköğretim kurumlarında sürdürülebilirliğinin incelenmesi

    Investigation of sustainability of information security management system in higher education institutions

    ALİ EREN

    Yüksek Lisans

    Türkçe

    Türkçe

    2021

    Bilim ve TeknolojiAnkara Sosyal Bilimler Üniversitesi

    Denetim ve Risk Yönetimi Ana Bilim Dalı (disiplinlerarası)

    DOÇ. DR. HALİS KIRAL

  5. Assessment of information security maturity levels and ISO/IEC 27001:2005 compliance of organizations in turkey

    Türkiye?deki organizasyonların bilgi güvenliği olgunluk seviyelerinin belirlenmesi ve ISO/IEC 27001:2005 standardına uyumluluklarının değerlendirilmesi

    EMEL AYDOĞMUŞ

    Yüksek Lisans

    İngilizce

    İngilizce

    2010

    İşletmeİstanbul Teknik Üniversitesi

    İşletme Mühendisliği Ana Bilim Dalı

    DR. HALİL HALEFŞAN SÜMEN