{"id":6616,"date":"2019-11-07T18:16:03","date_gmt":"2019-11-07T15:16:03","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=6616"},"modified":"2019-11-15T14:21:48","modified_gmt":"2019-11-15T11:21:48","slug":"ciso-2019","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/ciso-2019\/6616\/","title":{"rendered":"Kurumsal Bilgi G\u00fcvenli\u011fi Y\u00f6neticisi i\u00e7in temel beceri olarak risk y\u00f6netimi"},"content":{"rendered":"<p>Ge\u00e7en y\u0131l, meslekta\u015flar\u0131m\u0131n end\u00fcstrinin oda\u011f\u0131 ve sorunlar\u0131 hakk\u0131ndaki <a href=\"https:\/\/www.kaspersky.com\/blog\/ciso-report\/24288\/\" target=\"_blank\" rel=\"noopener nofollow\">geribildirimlerine<\/a> bakarken hislerim kar\u0131\u015f\u0131kt\u0131. Bir y\u0131l sonra, yeni anketimizin sonu\u00e7lar\u0131n\u0131n (a\u015fa\u011f\u0131da g\u00f6rebilirsiniz) daha da ilgin\u00e7 oldu\u011fu ortaya \u00e7\u0131kt\u0131.<\/p>\n<p>Bu iki \u00e7al\u0131\u015fman\u0131n sonu\u00e7lar\u0131na bakarken elde edinilen ilk izlenim \u015fudur: Genel olarak bilgi g\u00fcvenli\u011fi, \u00f6zellikle de kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisinin rol\u00fc, en az\u0131ndan a\u015fa\u011f\u0131 yukar\u0131 300 bilgi g\u00fcvenli\u011fi meslekta\u015f\u0131ma g\u00f6re, i\u015f i\u00e7in giderek daha \u00f6nemli hale gelmektedir. Bu, kesinlikle iyiye i\u015faret. Gittik\u00e7e daha fazla kat\u0131l\u0131mc\u0131n\u0131n, rolleri i\u00e7in gerekli beceriler aras\u0131nda \u201crisk y\u00f6netimi\u201d ve di\u011fer i\u015f becerileri listelemesi ger\u00e7e\u011fi de \u00f6yle.<\/p>\n<p>Bununla birlikte, i\u015f arkada\u015flar\u0131m\u0131n \u00e7o\u011fu ile ayn\u0131 fikirde olamad\u0131\u011f\u0131m bir nokta var. Baz\u0131lar\u0131 h\u00e2l\u00e2 teknik yeterlili\u011fin ve kurumsal BT sistemlerine dair detayl\u0131 bilginin hem \u00e7al\u0131\u015fmalar\u0131 hem de geli\u015fmeleri i\u00e7in kilit beceriler oldu\u011funu s\u00f6yl\u00fcyor. Bana g\u00f6re, teknik bilgi bir kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisinin temel gereksinimi olsa da \u2014ve bu y\u00f6neticilerin yeni teknolojilerle ha\u015f\u0131r ne\u015fir olmas\u0131 gerekse de\u2014 end\u00fcstri, modern BT sistemlerinin kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticilerinin potansiyel olarak t\u00fcm resmi g\u00f6rebilmesi a\u00e7\u0131s\u0131ndan \u00e7ok karma\u015f\u0131k oldu\u011funu fark etmeli.<\/p>\n<p>\u00dcstelik, bilgi sistemleri daha da sofistike hale gelecek (\u00e7o\u011fu kat\u0131l\u0131mc\u0131 da bunun ger\u00e7ekle\u015fmesini bekliyor). Bu nedenle, bir kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisinin teknik yeterlilikleri \u00f6nemli olsa da, risk y\u00f6netimi, etkili ekip y\u00f6netimi ve i\u015f ileti\u015fimi gibi becerilerin geli\u015ftirilmesinden sonra gelir. G\u00fcn\u00fcm\u00fczde \u00f6nemli olan personeldir.<\/p>\n<h2>\u0130nsanlar\u0131 anlay\u0131n, sistemleri de\u011fil.<\/h2>\n<p>Asl\u0131nda, hem BT sistemleri hem de g\u00fcvenlik teknolojileri, i\u015fe dair kritik kararlar alma konusunda son derece uzmanla\u015fm\u0131\u015f profesyonelleri serbest b\u0131rakacak kadar geli\u015fmi\u015f durumda art\u0131k. Elbette bu de\u011fi\u015fim, tak\u0131ma g\u00fcvenmeyi her zamankinden daha da \u00f6nemli hale getiriyor. Bir yandan, bilgi g\u00fcvenli\u011fi departman\u0131 \u015fefinin tak\u0131m\u0131n uzmanlar\u0131na g\u00fcvenebilmesi gerekiyor. \u00d6te yandan, onlar da, kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisinin yarg\u0131 ve kararlar\u0131na g\u00fcvenmek zorunda \u2014 k\u00f6r\u00fc k\u00f6r\u00fcne veya kendi g\u00f6r\u00fc\u015flerini dile getirmeden de\u011fil, ortak bir ama\u00e7 ve kar\u015f\u0131l\u0131kl\u0131 profesyonel sayg\u0131 \u00e7er\u00e7evesinde.<\/p>\n<p>Kat\u0131l\u0131mc\u0131lara g\u00f6re, sistem temini i\u00e7in b\u00fct\u00e7e art\u0131\u015f\u0131 kazanmak bazen daha fazla bilgi g\u00fcvenli\u011fi uzman\u0131n\u0131 i\u015fe almaktan daha kolay. M\u00fcmk\u00fcn oldu\u011funca \u00e7ok say\u0131da parlak yeni sistem sat\u0131n almak kula\u011fa harika gelebilir, ancak kurum i\u00e7inde \u00e7al\u0131\u015fan uzmanlar ve d\u0131\u015f kaynaklar i\u00e7in vazge\u00e7ilmez beceri ve yetkinlikleri belirlemek \u00e7ok daha \u00f6nemlidir. Asl\u0131nda, piyasadaki uzman yetersizli\u011fi g\u00f6z \u00f6n\u00fcne al\u0131nd\u0131\u011f\u0131nda, d\u0131\u015f kaynak kullan\u0131m\u0131n\u0131n departman\u0131n kabiliyetini geni\u015fletmek ve i\u015f gereksinimlerine daha h\u0131zl\u0131 yan\u0131t vermek i\u00e7in bir f\u0131rsat olarak g\u00f6r\u00fclmesi gerekti\u011fini d\u00fc\u015f\u00fcn\u00fcyorum.<\/p>\n<h2>Olay yan\u0131t\u0131ndan risk y\u00f6netimine<\/h2>\n<p>Kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisinin rol\u00fc kilit payda\u015flar \u2014\u00f6rne\u011fin y\u00f6netim kurulu veya CEO\u2014 i\u00e7in \u00f6nem kazanm\u0131\u015f olsa da, daha \u00f6nce oldu\u011fu gibi, \u00e7o\u011fu zaman bir \u015fey ger\u00e7ekle\u015ftikten sonra yard\u0131m \u00e7a\u011fr\u0131s\u0131 yaparlar. (Neyse ki, bu daha \u00e7ok rakiplere veya sekt\u00f6rdeki meslekta\u015flar\u0131n ba\u015f\u0131na gelir. Bununla birlikte, bir\u00e7ok \u015firketin bilgi g\u00fcvenli\u011fini bir i\u015f riski y\u00f6netimi arac\u0131 olarak g\u00f6rmedi\u011fini g\u00f6sterir.) Ve y\u00f6netimin bilgi g\u00fcvenli\u011fi performans\u0131n\u0131 nas\u0131l \u00f6l\u00e7t\u00fc\u011f\u00fc soruldu\u011funda, \u00e7o\u011fu kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisi olaylar\u0131n say\u0131s\u0131 veya olaya yan\u0131t verme s\u00fcresinin kilit g\u00f6stergeler oldu\u011funu s\u00f6yl\u00fcyor h\u00e2l\u00e2.<\/p>\n<p>Bunlar kesinlikle \u00f6nemli fakt\u00f6rlerdir, ancak Kaspersky\u2019nin benimsedi\u011fi modern siber ba\u011f\u0131\u015f\u0131kl\u0131k kavram\u0131na g\u00f6re, iyi korunan bir \u015firket, sadece zarar veren sald\u0131r\u0131lar\u0131n say\u0131s\u0131n\u0131 en aza indiren veya olaylar\u0131 h\u0131zl\u0131 bir \u015fekilde ara\u015ft\u0131ran de\u011fil, bu t\u00fcr olaylara ra\u011fmen i\u015fini ba\u015far\u0131yla geli\u015ftiren \u015firkettir.<\/p>\n<p>Sonu\u00e7ta, g\u00f6z yumulabilen riskler ve olaylar sonucunda ger\u00e7ekle\u015fen kabul edilebilir potansiyel kay\u0131plar her \u015firket i\u00e7in farkl\u0131d\u0131r. Bazen, i\u015f geli\u015fimini desteklemek i\u00e7in koruma \u00f6nlemleri konusunda gev\u015feme g\u00f6stermek i\u015fe yarar. Di\u011fer durumlarda bu bir se\u00e7enek de\u011fildir. Olay say\u0131s\u0131, bilgi g\u00fcvenli\u011fi performans\u0131n\u0131n mutlak \u00f6l\u00e7\u00fct\u00fc olamaz. Bilgi g\u00fcvenli\u011fine dair al\u0131nan \u00f6nlemlerin g\u00f6rev i\u015fleme h\u0131z\u0131n\u0131 ve maliyetini nas\u0131l etkiledi\u011fi de \u00f6nemlidir. Bence bu nedenle, kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticileri her \u015feyden \u00f6nce, olay korumaya a\u015f\u0131r\u0131 odaklanmak yerine, riskleri yeterince de\u011ferlendirebilecek ve \u015firketlerine ve i\u015f s\u00fcre\u00e7lerine m\u00fckemmelen uyarlanm\u0131\u015f bilgi g\u00fcvenli\u011fi sistemlerini olu\u015fturabilmelidir.<\/p>\n<p><span class=\"embed-youtube\" style=\"text-align:center; display: block;\"><iframe class=\"youtube-player\" type=\"text\/html\" width=\"640\" height=\"390\" src=\"https:\/\/www.youtube.com\/embed\/jalFI5hOvU0?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent\" frameborder=\"0\" allowfullscreen=\"true\"><\/iframe><\/span><\/p>\n<h2>Avukatlarla daha fazla zaman ge\u00e7irin<\/h2>\n<p>Benim a\u00e7\u0131mdan \u00f6ne \u00e7\u0131kan bir di\u011fer \u015fey, \u015firket i\u00e7indeki di\u011fer b\u00f6l\u00fcmlerle ileti\u015fim kurman\u0131n \u00f6nemi hakk\u0131ndaki cevaplard\u0131. Avukatlar onlardan daha y\u00fcksek \u00f6nceli\u011fe sahip olmal\u0131d\u0131r. Bug\u00fcn, bili\u015fim sistemlerinin artan karma\u015f\u0131kl\u0131\u011f\u0131, bir yandan bunlar\u0131n d\u0131\u015f hizmetlerle ili\u015fkileri, di\u011fer yandan da uluslararas\u0131 yasalar, bilgi g\u00fcvenli\u011fi uzmanlar\u0131n\u0131n kararlar\u0131n\u0131n olas\u0131 yasal sonu\u00e7lar\u0131n\u0131n g\u00f6rmezden gelinemeyece\u011fi anlam\u0131na geliyor.<\/p>\n<p>Ankete kat\u0131lanlar avukatlarla temas\u0131 d\u00f6rd\u00fcnc\u00fc s\u0131raya yerle\u015ftirdi \u2014 finansal y\u00f6neticiler, y\u00f6netim kurulu ve BT departman\u0131 meslekta\u015flar\u0131ndan sonraya. Avukatlarla temas\u0131n en az\u0131ndan finansal y\u00f6neticilerle kurulan temaslardan daha \u00f6ncelikli olmas\u0131 gerekti\u011fine inan\u0131yorum. Bilgi g\u00fcvenli\u011fini bir i\u015f riski y\u00f6netimi arac\u0131 olarak g\u00f6r\u00fcrseniz, bu mant\u0131kl\u0131 gelecektir.<\/p>\n<p>Anket \u00e7ok daha ilgin\u00e7 veriler sunuyor, bu y\u00fczden tam metni okuman\u0131z\u0131 tavsiye ederim. Raporu indirmek i\u00e7in l\u00fctfen a\u015fa\u011f\u0131daki formu doldurun.<\/p>\n<div class=\"interactive\"><form id=\"mktoForm_24061\"><\/form><script>MktoForms2.loadForm(\"\/\/app-sj06.marketo.com\", \"802-IJN-240\", 24061);<\/script><script>\n            MktoForms2.whenReady(function(form) {\n                form.onSuccess(function(vals, tyURL) {\n                    document.location.href = tyURL;\n                    dataLayer.push({\n                        'event': 'addEvents_makeConversions',\n                        'event_id': 'd-n01-e11',\n                        'conversion_name': 'Marketo Form',\n                        'conversion_step': 'Form Fill Out',\n                        'conversion_param': jQuery(location).attr(\"href\"),\n                        'eventCallback' : function() {\n                            jQuery(location).attr('href',tyURL);\n                        }\n                    });\n                    return false;\n                });\n            });\n            <\/script><\/div><!-- RECAPTCHA -->\n        <style>.googleRecaptcha { padding: 20px !important; }<\/style>\n        <script>\n            var GOOGLE_RECAPTCHA_SITE_KEY = '6Lf2eUQUAAAAAC-GQSZ6R2pjePmmD6oA6F_3AV7j';\n\n            var insertGoogleRecaptcha = function (form) {\n            var formElem = form.getFormElem().get(0);\n\n            if (formElem && window.grecaptcha) {\n                var div = window.document.createElement('div');\n                var divId = 'g-recaptcha-' + form.getId();\n                var buttonRow = formElem.querySelector('.mktoButtonRow');\n                var button = buttonRow ? buttonRow.querySelector('.mktoButton[type=\"submit\"]') : null;\n\n                var submitHandler = function (e) {\n                var recaptchaResponse = window.grecaptcha && window.grecaptcha.getResponse(widgetId);\n                e.preventDefault();\n\n                if (form.validate()) {\n                    if (!recaptchaResponse) {\n                    div.setAttribute('data-error', 'true');\n                    } else {\n                    div.setAttribute('data-error', 'false');\n\n                    form.addHiddenFields({\n                        reCAPTCHAFormResponse: recaptchaResponse,\n                    });\n\n                    form.submit();\n                    }\n                }\n                };\n\n                div.id = divId;\n                div.classList.add('googleRecaptcha');\n\n                if (button) {\n                button.addEventListener('click', submitHandler);\n                }\n\n                if (buttonRow) {\n                formElem.insertBefore(div, buttonRow);\n                }\n\n                if (window.grecaptcha.render) {\n                    var widgetId = window.grecaptcha.render(divId, {\n                    sitekey: GOOGLE_RECAPTCHA_SITE_KEY,\n                });\n                formElem.style.display = '';\n                }\n            }\n            };\n\n            function onloadApiCallback() {\n            var forms = MktoForms2.allForms();\n            for (var i = 0; i < forms.length; i++) {\n                insertGoogleRecaptcha(forms[i]);\n            }\n            }\n\n            (function () {\n            MktoForms2.whenReady(function (form) {\n                form.getFormElem().get(0).style.display = 'none';\n                jQuery.getScript('\/\/www.google.com\/recaptcha\/api.js?onload=onloadApiCallback');\n            });\n            })();\n        <\/script>\n        <!-- END RECAPTCHA -->\n","protected":false},"excerpt":{"rendered":"<p>Bir kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisi i\u015fle etkile\u015fime girmek i\u00e7in \u00e7ok zaman harcamak zorundad\u0131r, ayn\u0131 zamanda olduk\u00e7a \u00f6zel teknik g\u00f6revleri yerine getirebilecek profesyonellerden olu\u015fan bir ekibe ihtiya\u00e7 duyar.<\/p>\n","protected":false},"author":2498,"featured_media":6617,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[667,2055],"class_list":{"0":"post-6616","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-arastirma","10":"tag-kurumsal-bilgi-guvenligi-yoneticisi"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/ciso-2019\/6616\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ciso-2019\/16804\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ciso-2019\/14193\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/ciso-2019\/18788\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ciso-2019\/16835\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/ciso-2019\/15587\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/ciso-2019\/19501\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/ciso-2019\/18155\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ciso-2019\/24017\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ciso-2019\/29014\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/ciso-2019\/12454\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/ciso-2019\/14474\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/ciso-2019\/11356\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/ciso-2019\/21606\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/ciso-2019\/24385\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ciso-2019\/19364\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ciso-2019\/23572\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ciso-2019\/23419\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/kurumsal-bilgi-guvenligi-yoneticisi\/","name":"Kurumsal bilgi g\u00fcvenli\u011fi y\u00f6neticisi"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2498"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=6616"}],"version-history":[{"count":6,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6616\/revisions"}],"predecessor-version":[{"id":6700,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6616\/revisions\/6700"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/6617"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=6616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=6616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=6616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}