This article raises the problem of formalization of processes in the information security management system. The question of the necessity and importance of the stage of formalization of processes, the study and analysis of national and international standards is considered. In the course of the work, approaches to the development of an information security management system were analyzed, as well as national standards ГОСТ Р ИСО/МЭК 27001-2006, ГОСТ Р ИСО/МЭК 27002-2012 and ГОСТ Р ИСО/МЭК 27005-2010, which are the main ones when creating an information security management system (ISMS) and approaches to assessing its risks. Taking into account the provisions of national standards, as well as having studied different approaches to the development of ISMS, practical recommendations for the formalization of ISMS processes have been formed in this article. All recommendations are aimed at ensuring the safety of employees and the organization, while implementing formalization processes for the appropriate information security management system. Also, using the example of one security measure from the ISO/IEC 27001 standard, one of the ways to implement the policy regarding the formalization of the processes affecting the presented measure is presented.
The article analyzes the main aspects of personal information security, the knowledge of which is important for a person in conditions of high rates of digitalization of social and economic spheres. They are aimed at the formation of a personal information digital space and its management in the conditions of changing technologies and the legal field in accordance with the private and business interests of the individual. The first task in this case is to make a person aware of their interests and needs in the use of the digital environment, to assess the significance of the issues of the security of their personal data. Further, attention is drawn to the development of skills for analyzing and evaluating Internet resources in the context of the reliability and purposes of information dissemination, the development of methods and means of managing your personal data available within the framework of current legislation. Examples of a number of other relevant tasks, existing opportunities for practical acquisition of knowledge and formation of skills for safe work in a digital environment for various categories of users at the current level of information technology development are considered, and those aspects that remain outside the scope of methods and technologies that are massively used to increase the level of digital literacy of the population are also identified.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.