INTEGRATION OF THE GDPR REQUIREMENTS INTO THE REQUIREMENTS OF THE SR EN ISO/IEC 27001:2018 STANDARD, INTEGRATION SECURITY MANAGEMENT SYSTEM IN A SOFTWARE DEVELOPMENT COMPANY

Mirabela Luciana Gaşpar, Sorin Popescu · ACTA TECHNICA NAPOCENSIS - Series: APPLIED MATHEMATICS, MECHANICS, and ENGINEERING · 2018

Information security in general and personal data security in particular is one of the major challenges in today’s business arena. It implies specific reactions both from the technological point of view and from the management point of view and specific international regulations and standards set the boundaries between which it operates. This paper presents a managerial approach on information security, which combines the GDPR (General Regulation regarding Personal Data Protection) requirements and those of the ISO 27001 standard, validated by a study case on a software development company. It suggests stages, the identification of the critical ones, it defines directions and actions related to information security and it describes the methodology for applying certain support techniques and instruments.

Read the paper · More papers on PaperTik