Personal Data Protection as a Part of Information Security Management. Research Results. A Case Study

Authors

  • Jacek Łuczak Uniwersytet Ekonomiczny w Poznaniu

DOI:

https://doi.org/10.18559/SOEP.2016.12.4

Keywords:

Personal data protection, Personal files, Information security, Sensitive data, Management, Safety management, Case study, Research results

Abstract

The article stresses the importance of information and the necessity for information security management. The essential role of these issues calls for a system approach; thus, key definitions and principles of information security management have been presented in detail. The paper also takes account of numerous legal requirements, as well as the most significant requirements, as they refer to each organization, relating to personal information security. The legal basis within this scope has also been presented. The article depicts research results linked with information security management within the area of personal data protection. The research was conducted on a sample of 130 micro-,medium-sized and small enterprises. The questionnaire was extended with in-depth interviews. Moreover, the present paper embraces a case study: an IT enterprise, a provider of elearning platforms for teaching English. The case study is concerned with selected elements of the quality management system and the information security system, particularly in the aspects of personal data protection.

Downloads

Download data is not yet available.

References

Axelrod, C.W., Bayuk, J.L., Schutzer D. (eds.), 2009, Enterprise Information, Security and Privacy, Artech House, Norwood.
View in Google Scholar

Białas, A., 2007, Bezpieczeństwo informacji i usług w nowoczesnej instytucji i firmie, WNT, Warszawa.
View in Google Scholar

Calder, A., 2005, A Business Guide to Information Security, Kogan Page, London.
View in Google Scholar

Humphreys, E., 2007, Implementing the ISO/IEC 27001Information Security Management System Standard, Artech House, Norwood.
View in Google Scholar

Hunter, J.M.D, 2001, An Information Security Handbook, Springer, London.
View in Google Scholar

ISO/IEC 27001, 2013, Information technology - Security techniques - Information security management systems - Requirements.
View in Google Scholar

ISO Survey 2015, Executed summary, International Standards Organization.
View in Google Scholar

Kępa, L., 2015, Ochrona danych osobowych w praktyce, Difin, Warszawa.
View in Google Scholar

Konstytucja Rzeczypospolitej Polskiej z dnia 2 kwietnia 1997 r., Dz.U., nr 78, poz. 483.
View in Google Scholar

Łuczak, J., Tyburski, M., 2010, Systemowe zarządzanie bezpieczeństwem informacji ISO/IEC 27001, Wydawnictwo Uniwersytetu Ekonomicznego w Poznaniu, Poznań.
View in Google Scholar

Mottord, H.J., Whitman, M.E., 2008, Management of Information Security, 2nd ed., Thomson, Boston.
View in Google Scholar

Osborn, M., 2006, How to Cheat at Managing Information Security, Syngress, Rockland.
View in Google Scholar

Peltier, T.R., 2002, Information Security Policies, Procedures and Standards, Auerbach Publications.
View in Google Scholar

Rozporządzenie Ministra Spraw Wewnętrznych i Administracji z dnia 29 kwietnia 2004 r. w sprawie dokumentacji przetwarzania danych osobowych oraz warunków technicznych i organizacyjnych, jakim powinny odpowiadać urządzenia i systemy informatyczne służące do przetwarzania danych osobowych, Dz.U., nr 100, poz. 1024.
View in Google Scholar

Shostack, A., Stewart, A., 2008, A New School of Information Security, Pearson Education.
View in Google Scholar

Ustawa z dnia 29 sierpnia 1997 r. o ochronie danych osobowych, Dz.U., nr 133, poz. 883, z późn. zm.
View in Google Scholar

Downloads

Published

2016-12-31

Issue

Section

Articles

How to Cite

Łuczak , J. (2016). Personal Data Protection as a Part of Information Security Management. Research Results. A Case Study. Studia Oeconomica Posnaniensia, 4(12), 57-73. https://doi.org/10.18559/SOEP.2016.12.4