چکیده مقاله
Risk management constitutes the foundation of both ISMS & BCMS, offering a unified structure for identifying, assessing, and mitigating threats that may undermine organizational resilience Conventional risk management practices typically depend on static asset inventories and isolated assessments of technical or operational risks, without adequately accounting for the dynamic flow of information and the interdependencies among business processes This paper introduces a risk management approach that positions information centric processes and business information assets as the primary units of analysis Risk scenarios are derived by tracing information flows within and across processes, with impact evaluated according to the criticality of the affected processes and information assets, and likelihood determined by the condition and vulnerabilities of the supporting assets through which these information flows are delivered or stored The model further incorporates traditional process performance dimensions—quantity, quality, cost, and time—into the fields of information security and business continuity by mapping them to the core attributes of CIA Triad This integrated method enables the development of a traceable risk register aligned with ISO/IEC 27001 and ISO 22301, thereby enhancing both regulatory compliance and organizational resilience through the convergence of security and business continuity risk perspectives
کلیدواژهها
نویسندگان
شیوه ارجاع
Moradi, Ali,1404,An Information-Centric & Process-Oriented Business Continuity & Information Security Risk Management Model,12th National Conference on Interdisciplinary Research in Engineering and Management,Tehran
ارائهشده در
مجموعه مقالات دوازدهمین همایش ملی تحقیقات میان رشته ای در علوم مهندسی و مدیریت30 آبان 1404 · تهران