{"id":2901,"date":"2015-10-21T19:01:11","date_gmt":"2015-10-21T17:01:11","guid":{"rendered":"http:\/\/preventista.sk\/info\/?p=2901"},"modified":"2015-10-19T21:38:29","modified_gmt":"2015-10-19T19:38:29","slug":"riadenie-rizik-v-informacnej-bezpecnosti","status":"publish","type":"post","link":"https:\/\/preventista.sk\/info\/riadenie-rizik-v-informacnej-bezpecnosti\/","title":{"rendered":"Riadenie riz\u00edk v informa\u010dnej bezpe\u010dnosti"},"content":{"rendered":"<h1><\/h1>\n<h1>IT riziko ako t\u00e9ma d\u0148a<\/h1>\n<p>Informa\u010dn\u00e9 technol\u00f3gie s\u00fa dnes integr\u00e1lnou s\u00fa\u010das\u0165ou v\u00e4\u010d\u0161iny podporn\u00fdch, ale aj obchodn\u00fdch podnikov\u00fdch procesov. Rast\u00faca z\u00e1vislos\u0165 na IT aplik\u00e1ci\u00e1ch v\u0161ak v s\u00fa\u010dasnosti znamen\u00e1 aj dramatick\u00fd n\u00e1rast riz\u00edk a potrebami ich nepretr\u017eitej a systematickej ochrany.<\/p>\n<p>Rie\u0161en\u00edm probl\u00e9mov ochrany informa\u010dn\u00fdch akt\u00edv organiz\u00e1cie pred rizikami vypl\u00fdvaj\u00facimi z prev\u00e1dzky IT je zavedenie <strong>Syst\u00e9mu mana\u017e\u00e9rstva informa\u010dnej bezpe\u010dnosti<\/strong> (\u010falej len ISMS), ktor\u00fd je prisp\u00f4soben\u00fd individu\u00e1lnym potreb\u00e1m podniku a\u00a0zah\u0155\u0148a v\u00a0sebe aj n\u00e1vrh procesov \u00fa\u010dinn\u00e9ho riadenia IT riz\u00edk.<\/p>\n<p>Existuj\u00fa r\u00f4zne defin\u00edcie informa\u010dnej bezpe\u010dnosti, no na z\u00e1klade sk\u00fasenosti z\u00a0hospod\u00e1rskej praxe m\u00e1 zrejme najbli\u017e\u0161ie k\u00a0realite defin\u00edcia, pod\u013ea ktorej <strong>bezpe\u010dnos\u0165 je udr\u017eiavanie akceptovate\u013enej miery identifikovan\u00e9ho rizika<\/strong>. Bezpe\u010dnos\u0165 je teda komplex procesov a \u010dinnost\u00ed zameran\u00fdch na odvr\u00e1tenie alebo zmen\u0161enie identifikovan\u00fdch riz\u00edk, resp. prejavov hrozieb ktor\u00e9 p\u00f4sobia na informa\u010dn\u00e9 akt\u00edva.<\/p>\n<p>Bezpe\u010dnos\u0165 nie je kone\u010dn\u00fd stav, ani produkt. Bezpe\u010dnos\u0165 a\u00a0riadenie IT rizika s\u00fa nepretr\u017eit\u00e9, komplexn\u00e9, cyklick\u00e9 procesy s kontinu\u00e1lnym prehodnocovan\u00edm a\u00a0zlep\u0161ovan\u00edm. V\u00a0oboch procesoch sa jedn\u00e1 o iterat\u00edvny pr\u00edstup,\u00a0 ktor\u00fd by mal by\u0165 riaden\u00fd, pl\u00e1novan\u00fd, implementovan\u00fd, overovan\u00fd a\u00a0udr\u017eiavan\u00fd.<\/p>\n<p>Nepretr\u017eitos\u0165 procesu riadenia IT rizika je mo\u017en\u00e9 zn\u00e1zorni\u0165 aj na upravenom Demingovom cykle (tzv. model PDCA) zn\u00e1mom z\u00a0ISO 27001 a\u00a0zalo\u017eenom na \u0161tyroch nadv\u00e4zn\u00fdch a\u00a0opakuj\u00facich\u00a0 sa f\u00e1zach Pl\u00e1nova\u0165 \u2013 Vykon\u00e1va\u0165 \u2013 Kontrolova\u0165 \u2013 P\u00f4sobi\u0165. V\u00a0dekompoz\u00edcii na proces riadenia IT rizika by Demingov cyklus PDCA mohol by\u0165 zn\u00e1zornen\u00fd aj nasledovne:<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/pcap.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2902\" data-permalink=\"https:\/\/preventista.sk\/info\/riadenie-rizik-v-informacnej-bezpecnosti\/pcap\/\" data-orig-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/pcap.png?fit=422%2C345&amp;ssl=1\" data-orig-size=\"422,345\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"pcap\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/pcap.png?fit=422%2C345&amp;ssl=1\" class=\"aligncenter size-full wp-image-2902\" src=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/pcap.png?resize=422%2C345&#038;ssl=1\" alt=\"pcap\" width=\"422\" height=\"345\" srcset=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/pcap.png?w=422&amp;ssl=1 422w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/pcap.png?resize=320%2C262&amp;ssl=1 320w\" sizes=\"auto, (max-width: 422px) 100vw, 422px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Pre korektn\u00e9 uplatnenie metodiky riadenia IT rizika sa IT riziko definuje ako: <strong>\u201eriziko finan\u010dn\u00fdch a\u00a0reputa\u010dn\u00fdch str\u00e1t sp\u00f4soben\u00fdch naru\u0161en\u00edm d\u00f4vernosti, integrity, dostupnosti, alebo sledovate\u013enosti informa\u010dn\u00fdch akt\u00edv, vytvoren\u00fdch, ulo\u017een\u00fdch, sprac\u00favan\u00fdch, alebo\u00a0 pren\u00e1\u0161an\u00fdch informa\u010dn\u00fdmi technol\u00f3giami<\/strong>.<\/p>\n<p>Pou\u017e\u00edvanie a rozvoj pou\u017e\u00edvan\u00fdch informa\u010dn\u00fdch syst\u00e9mov ako aj\u00a0zmeny prev\u00e1dzkov\u00fdch procesov v\u00a0z\u00e1vislosti na \u00farovni ich automatiz\u00e1cie m\u00f4\u017eu organiz\u00e1cii sp\u00f4sobova\u0165 riziko.<\/p>\n<p>Pr\u00edstup k\u00a0mana\u017ementu riz\u00edk na z\u00e1klade medzin\u00e1rodnej normy ISO\/IEC 27001 podporuje osvojenie si procesn\u00e9ho pr\u00edstupu k\u00a0n\u00e1vrhu, implement\u00e1cii, prev\u00e1dzke, monitorovaniu, udr\u017eovaniu a\u00a0zlep\u0161ovaniu efektivity ISMS.<\/p>\n<hr \/>\n<h1>O\u0161etrovanie rizika<\/h1>\n<p>O\u0161etrovanie rizika je proces v\u00fdberu a\u00a0implement\u00e1cie opatren\u00ed na modifikovanie rizika.<\/p>\n<p>Najvhodnej\u0161ie met\u00f3da o\u0161etrenia rizika by mala by\u0165 vybrat\u00e1 na z\u00e1klade v\u00fdsledku hodnotenia rizika. Pou\u017eit\u00e1 by mala by\u0165 v\u017edy t\u00e1 met\u00f3da o\u0161etrenia rizika, ktorou je mo\u017en\u00e9 z\u00edska\u0165 v\u00fdraznej\u0161iu redukciu rizika s dosiahnut\u00edm relat\u00edvne ni\u017e\u0161\u00edch n\u00e1kladov.<\/p>\n<p>V\u00a0zmysle ISO 27005 je mo\u017en\u00e9 na o\u0161etrenie riz\u00edk pou\u017ei\u0165 protiopatrenia ktor\u00e9 je mo\u017en\u00e9 zaradi\u0165 do jednej z\u00a0mo\u017en\u00fdch kateg\u00f3ri\u00ed:<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2903\" data-permalink=\"https:\/\/preventista.sk\/info\/riadenie-rizik-v-informacnej-bezpecnosti\/riziko\/\" data-orig-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?fit=710%2C624&amp;ssl=1\" data-orig-size=\"710,624\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"riziko\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?fit=700%2C615&amp;ssl=1\" class=\"aligncenter wp-image-2903 size-full\" src=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?resize=710%2C624&#038;ssl=1\" alt=\"riziko\" width=\"710\" height=\"624\" srcset=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?w=710&amp;ssl=1 710w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?resize=320%2C281&amp;ssl=1 320w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?resize=450%2C395&amp;ssl=1 450w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/riziko.png?resize=700%2C615&amp;ssl=1 700w\" sizes=\"auto, (max-width: 710px) 100vw, 710px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3><a name=\"_Toc272622070\"><\/a><a name=\"_Toc265076142\"><\/a>Zn\u00ed\u017eenie rizika<\/h3>\n<p>Zn\u00ed\u017eenie rizika je met\u00f3da o\u0161etrenia rizika, pri ktorej je uplatnen\u00fd v\u00fdber vhodn\u00fdch opatren\u00ed tak, aby riziko bolo zn\u00ed\u017een\u00e9 a\u017e na \u00farove\u0148 zostatkov\u00e9ho rizika, ktor\u00e9 m\u00f4\u017ee by\u0165 n\u00e1sledne prehodnoten\u00e9 ako akceptovate\u013en\u00e9.<\/p>\n<p>Vhodn\u00e9 a opodstatnen\u00e9 opatrenia by mali by\u0165 vybran\u00e9 tak, aby sp\u013a\u0148ali po\u017eiadavky stanoven\u00e9 ohodnoten\u00edm rizika. V\u00fdber opatren\u00ed by mal bra\u0165 do \u00favahy krit\u00e9ria akcept\u00e1cie rizika ako napr. pr\u00e1vne, regula\u010dn\u00e9 a zmluvn\u00e9 po\u017eiadavky. Taktie\u017e by mal vzia\u0165 do \u00favahy primeranos\u0165 n\u00e1kladov a \u010dasov\u00fd r\u00e1mec na implement\u00e1ciu opatren\u00ed ale aj technick\u00e9 a kult\u00farne aspekty. Okrem toho, d\u00f4le\u017eit\u00e1 je ot\u00e1zka n\u00e1vratnosti invest\u00edcie s\u00favisiacej so zn\u00ed\u017een\u00edm rizika a potenci\u00e1l na vyu\u017e\u00edvanie nov\u00fdch obchodn\u00fdch pr\u00edle\u017eitost\u00ed z\u00edskan\u00fd implement\u00e1ciou opatren\u00ed.<\/p>\n<h3><a name=\"_Toc272622071\"><\/a><a name=\"_Toc265076143\"><\/a>Presun rizika<\/h3>\n<p>Presun rizika je met\u00f3da o\u0161etrenia rizika, pri ktorej bude ur\u010dit\u00e1 \u010das\u0165 rizika zdie\u013ean\u00e1 s extern\u00fdmi subjektmi.<\/p>\n<p>Presun rizika sa m\u00f4\u017ee uskuto\u010dni\u0165 napr. poisten\u00edm, ktor\u00e9 zni\u017euje n\u00e1sledky, alebo v\u00fdberom zmluvn\u00e9ho partnera, ktor\u00e9ho \u00falohou bude monitorova\u0165 proces, alebo informa\u010dn\u00fd syst\u00e9m a prija\u0165 okam\u017eit\u00e9 opatrenia na zastavenie hrozby sk\u00f4r, ako vznikne \u0161koda.<\/p>\n<h3><a name=\"_Toc272622072\"><\/a><a name=\"_Toc265076144\"><\/a>Vyhnutie sa riziku<\/h3>\n<p>Vyhnutie sa riziku je met\u00f3da o\u0161etrenia rizika, pri ktorej bude riziko ob\u00edden\u00e9 nevykonan\u00edm pr\u00edslu\u0161n\u00fdch rizikov\u00fdch aktiv\u00edt, alebo uplatnen\u00edm \u0161pecifick\u00fdch podmienok na vykonanie aktivity.<\/p>\n<p>Ke\u010f je identifikovan\u00e9 riziko pova\u017eovan\u00e9 za pr\u00edli\u0161 vysok\u00e9, alebo n\u00e1klady na implement\u00e1ciu o\u0161etrenia rizika presahuj\u00fa pr\u00ednosy, rozhodnut\u00edm m\u00f4\u017ee by\u0165 aj \u00fapln\u00e9 vyhnutie sa riziku a to odobrat\u00edm pl\u00e1novanej alebo existuj\u00facej aktivity alebo s\u00faboru aktiv\u00edt, alebo zmenou podmienok pod\u013ea ktor\u00fdch je \u010dinnos\u0165 prev\u00e1dzkovan\u00e1.<\/p>\n<h3><a name=\"_Toc272622073\"><\/a><a name=\"_Toc265076145\"><\/a><a name=\"_Toc256986752\"><\/a>Zachovanie rizika<\/h3>\n<p>Zachovanie rizika je met\u00f3da o\u0161etrenia rizika, pri ktorej nie s\u00fa uplatnen\u00e9 \u017eiadne opatrenia a\u00a0riziko zostane zachovan\u00e9 v\u00a0p\u00f4vodne ohodnotenej \u00farovni.<\/p>\n<p>Ak \u00farove\u0148 rizika sp\u013a\u0148a krit\u00e9ri\u00e1 na prijatie rizika, nie je potrebn\u00e9 implementova\u0165 opatrenia a riziko m\u00f4\u017ee zosta\u0165 zachovan\u00e9.<\/p>\n<h2><a name=\"_Toc272622074\"><\/a><a name=\"_Toc265076150\"><\/a><a name=\"_Toc256986757\"><\/a><a name=\"_Toc256966036\"><\/a>Zvy\u0161kov\u00e9 riziko<\/h2>\n<p>Zvy\u0161kov\u00e9 riziko je tak\u00e9 riziko, ktor\u00e9ho hodnota po komplexnom o\u0161etren\u00ed riz\u00edk implement\u00e1ciou p\u00f4vodn\u00fdch, dodato\u010dn\u00fdch a\u00a0vylep\u0161en\u00fdch opatren\u00ed na o\u0161etrenie rizika je tak\u00e1 n\u00edzka (t.j. nepresahuje referen\u010dn\u00fa \u00farove\u0148), \u017ee je pre podnik prijate\u013en\u00e9 a nie je nutn\u00e9 uplatni\u0165 \u010fal\u0161ie opatrenia na jeho zn\u00ed\u017eenie.<\/p>\n<p>Referen\u010dn\u00e1 \u00farove\u0148 je hranica miery rizika (stanoven\u00e1 hodnota rizika), ktor\u00e1 rozhoduje o tom, \u010di je riziko zvy\u0161kov\u00e9 (ve\u013ekos\u0165 rizika je men\u0161ia ne\u017e referen\u010dn\u00e1 \u00farove\u0148), alebo nie je zvy\u0161kov\u00e9 (ve\u013ekos\u0165 rizika je v\u00e4\u010d\u0161ia alebo rovn\u00e1 referen\u010dnej \u00farovni). T\u00fdm sa rozhodne, \u010di proti riziku je alebo nie je potrebn\u00e9 uplatni\u0165 \u010fal\u0161ie opatrenia pre jeho zn\u00ed\u017eenie. Referen\u010dn\u00e1 hodnota by mala by\u0165 na takej \u00farovni, aby dopad hrozby bol tak\u00fd n\u00edzky, \u017ee ju bude mo\u017en\u00e9 zanedba\u0165.<\/p>\n<p>Za predpokladu, \u017ee po\u010det implementovan\u00fdch protiopatren\u00ed postupne st\u00fapa, zvy\u0161kov\u00e9 rizik\u00e1 bud\u00fa z\u00a0v\u00fdchodiskov\u00fdch hodn\u00f4t postupne klesa\u0165, a\u017e sa zastavia na ur\u010ditej kone\u010dnej hodnote, ktor\u00e1 z\u00e1sadnej\u0161\u00edm sp\u00f4sobom neklesne ani po implement\u00e1cii \u010fal\u0161\u00edch protiopatren\u00ed. T\u00fato hodnotu rizika je mo\u017en\u00e9 ozna\u010di\u0165 za zvy\u0161kov\u00fa.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"2904\" data-permalink=\"https:\/\/preventista.sk\/info\/riadenie-rizik-v-informacnej-bezpecnosti\/protiopatrenia\/\" data-orig-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?fit=824%2C384&amp;ssl=1\" data-orig-size=\"824,384\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"protiopatrenia\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?fit=700%2C326&amp;ssl=1\" class=\"aligncenter size-large wp-image-2904\" src=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?resize=700%2C326&#038;ssl=1\" alt=\"protiopatrenia\" width=\"700\" height=\"326\" srcset=\"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?resize=700%2C326&amp;ssl=1 700w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?resize=320%2C149&amp;ssl=1 320w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?resize=450%2C210&amp;ssl=1 450w, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/protiopatrenia.png?w=824&amp;ssl=1 824w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>V\u00a0praxi pravdepodobne \u017eiaden informa\u010dn\u00fd syst\u00e9m nie je bez riz\u00edk a\u00a0teda plat\u00ed, \u017ee\u00a0ani v\u0161etky implementovan\u00e9 opatrenia nezn\u00ed\u017eia riziko nato\u013eko, aby dosiahlo nulov\u00fa hodnotu.<\/p>\n<h3><a name=\"_Toc272622075\"><\/a><a name=\"_Toc265076151\"><\/a>Akcept\u00e1cia zvy\u0161kov\u00e9ho rizika<\/h3>\n<p>Krit\u00e9ri\u00e1 prijatia rizika \u010dasto z\u00e1visia na politike organiz\u00e1cie, cie\u013eoch a z\u00e1ujmoch zainteresovan\u00fdch str\u00e1n. V\u00a0ka\u017edom pr\u00edpade v\u0161ak <strong>rozhodnutie o\u00a0prijat\u00ed riz\u00edk by malo by\u0165 u\u010dinen\u00e9 a\u00a0form\u00e1lne zaznamenan\u00e9<\/strong>.<\/p>\n<p>Akcept\u00e1cia zvy\u0161kov\u00e9ho IT rizika je proces, v\u00a0ktorom vedenie podniku alebo veden\u00edm poveren\u00fd org\u00e1n (v bank\u00e1ch typicky Komisia pre riadenie opera\u010dn\u00e9ho rizika) form\u00e1lne vezme na vedomie eskalovan\u00e9 riziko.<\/p>\n<p>Krit\u00e9ri\u00e1 pre prijatie rizika by mali by\u0165 vopred vyvinut\u00e9 a \u0161pecifikovan\u00e9. Tieto nie je mo\u017en\u00e9 stanovi\u0165 v\u0161eobecne, preto ka\u017ed\u00e1 organiz\u00e1cia mus\u00ed definova\u0165 svoju vlastn\u00fa stupnicu pre \u00farovne prijatia rizika. Krit\u00e9ri\u00e1 pre prijatie rizika m\u00f4\u017eu samozrejme obsahova\u0165 aj nieko\u013eko r\u00f4znych prahov s\u00a0po\u017eadovanou cie\u013eovou \u00farov\u0148ou rizika.<\/p>\n<p>N\u00e1vrhy mo\u017en\u00fdch pr\u00edstupov (resp. hodnotiacich krit\u00e9ri\u00ed) pre prijatie zvy\u0161kov\u00e9ho rizika:<\/p>\n<ul>\n<li>vyjadrenie krit\u00e9ri\u00ed prijatia rizika ako pomeru odhadnut\u00e9ho zisku (alebo in\u00e9ho podnikate\u013esk\u00e9ho prospechu) k\u00a0odhadnut\u00e9mu riziku.<\/li>\n<li>stanovenie r\u00f4znych tried riz\u00edk (napr. riz\u00edk ktor\u00e9 by mohli vies\u0165 k\u00a0nes\u00faladu s\u00a0pr\u00e1vnymi a\u00a0regula\u010dn\u00fdmi po\u017eiadavkami, resp. riz\u00edk stanoven\u00fdch zmluvn\u00fdmi po\u017eiadavkami)<\/li>\n<li>po\u017eiadavky na bud\u00face dodato\u010dn\u00e9 o\u0161etrenie (napr. riziko m\u00f4\u017ee by\u0165 prijat\u00e9, ak existuje schv\u00e1lenie a\u00a0z\u00e1v\u00e4zok zn\u00ed\u017eenia rizika na prijate\u013en\u00fa \u00farove\u0148 v\u00a0stanovenom \u010dasovom obdob\u00ed).<\/li>\n<\/ul>\n<p>Krit\u00e9ria prijatia riz\u00edk sa m\u00f4\u017eu l\u00ed\u0161i\u0165 v z\u00e1vislosti na tom, ako dlho sa o\u010dak\u00e1va, \u017ee riziko bude existova\u0165, napr. riziko m\u00f4\u017ee by\u0165 spojen\u00e9 s do\u010dasnou, alebo kr\u00e1tkodobou aktivitou.<\/p>\n<p>V\u0161etky akceptovan\u00e9 rizik\u00e1 by mali by\u0165 prehodnocovan\u00e9 a\u017e do doby, pokia\u013e riziko neprestane by\u0165 relevantn\u00e9, alebo sa neprist\u00fapi k\u00a0in\u00e9mu sp\u00f4sobu o\u0161etrenia identifikovan\u00e9ho a\u00a0trvaj\u00faceho rizika. Jednozna\u010dne odpor\u00fa\u010dan\u00fdm term\u00ednom pre prehodnotenie akceptovan\u00fdch riz\u00edk je obdobie pred pl\u00e1novan\u00edm investi\u010dn\u00e9ho rozpo\u010dtu pre nasleduj\u00faci rok.<\/p>\n<h1><a name=\"_Toc265076167\"><\/a><\/h1>\n<hr \/>\n<h1><a name=\"_Toc265076167\"><\/a><a name=\"_Toc272622076\"><\/a>Z\u00e1ver<\/h1>\n<p>Ak m\u00e1 organiz\u00e1cia \u00faprimn\u00fd z\u00e1ujem na dosiahnut\u00ed \u00faspe\u0161nej implement\u00e1cie procesu riadenia IT riz\u00edk, najvy\u0161\u0161ie vedenie mus\u00ed by\u0165 odhodlan\u00e9 re\u00e1lne zahrn\u00fa\u0165 informa\u010dn\u00fa bezpe\u010dnos\u0165 do z\u00e1kladn\u00fdch obchodn\u00fdch procesov podniku. Iba zapojenie najvy\u0161\u0161ieho vedenia do procesu riadenia IT rizika zaru\u010d\u00ed, \u017ee organiz\u00e1cia bude ma\u0165 vyhraden\u00e9 dostato\u010dn\u00e9 zdroje na zabezpe\u010denie adekv\u00e1tnej \u00farovne informa\u010dnej bezpe\u010dnosti.<\/p>\n<p>Je potrebn\u00e9 si uvedomi\u0165, \u017ee i\u00a0ke\u010f je informa\u010dn\u00e1 bezpe\u010dnos\u0165 d\u00f4le\u017eitou s\u00fa\u010das\u0165ou\u00a0 procesu riadenia IT riz\u00edk, je len jednou z\u00a0mnoh\u00fdch \u00faloh, za ktor\u00e9 by malo zodpoveda\u0165 predstavenstvo spolo\u010dnosti v\u00a0r\u00e1mci procesu riadenia opera\u010dn\u00fdch riz\u00edk.<\/p>\n<p>Efekt\u00edvne riadenie riz\u00edk p\u00f4sobiacich na informa\u010dn\u00e9 akt\u00edva je teda podmienen\u00e9 ist\u00fdmi k\u013e\u00fa\u010dov\u00fdmi \u00falohami najvy\u0161\u0161ieho vedenia podniku:<\/p>\n<ul>\n<li>Poveri\u0165 zodpovednos\u0165ou za proces informa\u010dnej bezpe\u010dnosti a\u00a0riadenia IT rizika konkr\u00e9tneho \u010dlena najvy\u0161\u0161ieho vedenia<\/li>\n<li>Pravidelne sa oboznamova\u0165 zo stavom o\u0161etrovania IT riz\u00edk a\u00a0pravidelne vykon\u00e1va\u0165 form\u00e1lnu akcept\u00e1ciu zvy\u0161kov\u00e9ho rizika<\/li>\n<li>Form\u00e1lne na seba prevzia\u0165 zodpovednos\u0165 za akcept\u00e1ciu zvy\u0161kov\u00e9ho rizika vr\u00e1tane identifik\u00e1cie str\u00e1t<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Ivan Makat\u00fara<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT riziko ako t\u00e9ma d\u0148a Informa\u010dn\u00e9 technol\u00f3gie s\u00fa dnes integr\u00e1lnou s\u00fa\u010das\u0165ou v\u00e4\u010d\u0161iny podporn\u00fdch, ale aj obchodn\u00fdch podnikov\u00fdch procesov. Rast\u00faca z\u00e1vislos\u0165 na IT aplik\u00e1ci\u00e1ch v\u0161ak v s\u00fa\u010dasnosti znamen\u00e1 aj dramatick\u00fd n\u00e1rast riz\u00edk a potrebami ich nepretr\u017eitej a systematickej ochrany. Rie\u0161en\u00edm probl\u00e9mov ochrany informa\u010dn\u00fdch akt\u00edv organiz\u00e1cie pred rizikami vypl\u00fdvaj\u00facimi z prev\u00e1dzky IT je zavedenie Syst\u00e9mu mana\u017e\u00e9rstva informa\u010dnej [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":2907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-2901","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-itbezp"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/10\/rizika.png?fit=700%2C400&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6315,"url":"https:\/\/preventista.sk\/info\/debatky-o-bezpecnosti-iv\/","url_meta":{"origin":2901,"position":0},"title":"Debatky o bezpe\u010dnosti IV","author":"Redakcia","date":"15. janu\u00e1ra 2025","format":false,"excerpt":"V \u0161tvrtej \u010dasti sme vyspovedali odborn\u00edka z trochu inej oblasti bezpe\u010dnosti a to z pr\u00e1vnej sf\u00e9ry. Meno Miroslav Chl\u00edpala je \u0161irokej odbornej i laickej verejnosti zn\u00e1me z mnoh\u00fdch konferenci\u00ed, vzdel\u00e1vac\u00edch semin\u00e1rov, ale zn\u00e1me s\u00fa aj jeho publik\u00e1cie. Zdroj obr\u00e1zku: AI Microsoft Copilot Designer, 2024 Na \u00favod jednoduch\u0161ia ot\u00e1zka. \u010co motivuje\u2026","rel":"","context":"V &quot;Debatky o bezpe\u010dnosti&quot;","block_context":{"text":"Debatky o bezpe\u010dnosti","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/debatky-o-bezpecnosti\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/08\/image.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/08\/image.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/08\/image.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/08\/image.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":4512,"url":"https:\/\/preventista.sk\/info\/preco-je-tema-ochrany-pocitaca-pocitaca-sucastou-ucebnice-informacnej-bezpecnosti\/","url_meta":{"origin":2901,"position":1},"title":"Pre\u010do je t\u00e9ma ochrany po\u010d\u00edta\u010da s\u00fa\u010das\u0165ou u\u010debnice informa\u010dnej bezpe\u010dnosti?","author":"Daniel Chromek","date":"21. septembra 2021","format":false,"excerpt":"Do pr\u00e1c na u\u010debnici \u201eU\u010debnica informa\u010dnej bezpe\u010dnosti pre stredn\u00e9 \u0161koly a\u00a0gymn\u00e1zi\u00e1, prv\u00e1 \u010das\u0165\u201c som nast\u00fapil po debate s inici\u00e1torom projektu Marekom Zemanom, ako do rozbehnut\u00e9ho vlaku. Idea ma\u0165 u\u010debnicu, ktor\u00e1 kombinuje teoretick\u00e9 aj praktick\u00e9 oblasti informa\u010dnej bezpe\u010dnosti bola pr\u00ed\u0165a\u017eliv\u00e1 a som ve\u013emi r\u00e1d, \u017ee v u\u010debnici sa nach\u00e1dzaj\u00fa \u010dasti venovan\u00e9\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2021\/09\/Logo_Vzdelavanie.png?fit=450%2C381&ssl=1&resize=350%2C200","width":350,"height":200},"classes":[]},{"id":2768,"url":"https:\/\/preventista.sk\/info\/outsourcing-informacnych-technologii-a-bezpecnost\/","url_meta":{"origin":2901,"position":2},"title":"Outsourcing informa\u010dn\u00fdch technol\u00f3gi\u00ed a bezpe\u010dnos\u0165","author":"Redakcia","date":"5. augusta 2015","format":false,"excerpt":"In\u0161tit\u00facie verejnej spr\u00e1vy podobne ako firmy a organiz\u00e1cie zo s\u00fakromn\u00e9ho sektora vyu\u017e\u00edvaj\u00fa outsourcing ako jednu zo strat\u00e9gi\u00ed boja s ch\u00fdbaj\u00facimi profesion\u00e1lmi a\u00a0nedostatkom finan\u010dn\u00fdch prostriedkov pre\u00a0oblas\u0165 informa\u010dn\u00fdch a\u00a0komunika\u010dn\u00fdch technol\u00f3gi\u00ed. Je ale n\u00e1kup IT slu\u017eieb pre zabezpe\u010denie kritick\u00fdch procesov a\u00a0bezpe\u010dnosti organiz\u00e1cie u\u00a0dod\u00e1vate\u013ea v\u017edy spr\u00e1vnou vo\u013ebou? Outsourcing je v\u00a0s\u00fa\u010dasnosti ob\u013e\u00faben\u00fdm sp\u00f4sobom optimaliz\u00e1cie n\u00e1kladov\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2015\/08\/cover.jpg?fit=700%2C400&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":5816,"url":"https:\/\/preventista.sk\/info\/tretia-cast-ucebnice-pre-stredne-skoly\/","url_meta":{"origin":2901,"position":3},"title":"Tretia \u010das\u0165 u\u010debnice pre stredn\u00e9 \u0161koly","author":"Redakcia","date":"22. apr\u00edla 2024","format":false,"excerpt":"Tretia \u010das\u0165 U\u010debnice informa\u010dnej bezpe\u010dnosti pre stredn\u00e9 odborn\u00e9 \u0161koly a\u00a0gymn\u00e1zi\u00e1 uzrela svetlo sveta a tak sa uzavrela pl\u00e1novan\u00e1 trojica u\u010debn\u00edc, ktor\u00e9 sme mali v OZ Preventista - zdru\u017eenie pre bezpe\u010dnos\u0165 a prevenciu napl\u00e1novan\u00e9. Prv\u00e9 dve u\u010debnice na\u0161li svoje miesto v slovenskom \u0161kolstve - dnes ich vyu\u017e\u00edva viac ako 300 slovensk\u00fdch\u2026","rel":"","context":"V &quot;Aktu\u00e1lne&quot;","block_context":{"text":"Aktu\u00e1lne","link":"https:\/\/preventista.sk\/info\/category\/akcie\/aktualne\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/03\/image-4.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/03\/image-4.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/03\/image-4.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2024\/03\/image-4.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":4472,"url":"https:\/\/preventista.sk\/info\/vzdelavanie-informacnej-bezpecnosti-na-strednych-skolach-ma-sancu\/","url_meta":{"origin":2901,"position":4},"title":"Vzdel\u00e1vanie informa\u010dnej bezpe\u010dnosti na stredn\u00fdch \u0161kol\u00e1ch m\u00e1 \u0161ancu!","author":"Marek Zeman","date":"14. septembra 2021","format":false,"excerpt":"S\u00a0ve\u013ekou rados\u0165ou v\u00e1m oznamujeme, \u017ee svetlo sveta uzrela \u201eU\u010debnica informa\u010dnej bezpe\u010dnosti pre stredn\u00e9 \u0161koly a\u00a0gymn\u00e1zi\u00e1, prv\u00e1 \u010das\u0165\u201c. Je to u\u010debnica, ktor\u00e1 je v\u00a0na\u0161ich kon\u010din\u00e1ch prelomov\u00e1. Pomocou u\u010debnice je mo\u017en\u00e9 vytvori\u0165 pevn\u00e9 z\u00e1klady osobnej bezpe\u010dnosti a\u00a0z\u00e1rove\u0148 si osvoji\u0165 vedomosti, ktor\u00e9 tvoria jadro te\u00f3rie informa\u010dnej bezpe\u010dnosti. Za\u010diatkom roka 2020 vznikla po\u017eiadavka 1.\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2021\/09\/kniha-2021.png?fit=762%2C1200&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2021\/09\/kniha-2021.png?fit=762%2C1200&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2021\/09\/kniha-2021.png?fit=762%2C1200&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2021\/09\/kniha-2021.png?fit=762%2C1200&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":3406,"url":"https:\/\/preventista.sk\/info\/co-je-to-kyberneticka-bezpecnost\/","url_meta":{"origin":2901,"position":5},"title":"\u010co je to kybernetick\u00e1 bezpe\u010dnos\u0165?","author":"I. Makatura","date":"3. marca 2017","format":false,"excerpt":"\u00a0 Dnes u\u017e zrejme nikto nepochybuje o\u00a0tom, \u017ee \u013eudia s\u00fa na inform\u00e1ci\u00e1ch z\u00e1visl\u00ed. A\u00a0nie je to len z\u00e1vislos\u0165 v\u00a0zmysle poh\u013eadov, neust\u00e1le sklonen\u00fdch ku mobiln\u00fdm telef\u00f3nom. Ve\u010f z\u00e1vislos\u0165 na inform\u00e1ci\u00e1ch sa t\u00fdka u\u017e aj mnoh\u00fdch hospod\u00e1rskych odvetv\u00ed a\u00a0spr\u00e1vy vec\u00ed verejn\u00fdch. Inform\u00e1ci\u00ed je viac, ne\u017e kedyko\u013evek predt\u00fdm, inform\u00e1cie s\u00fa sprac\u00favan\u00e9 r\u00fdchlej\u0161ie a\u2026","rel":"","context":"V &quot;Bezpe\u010dnos\u0165&quot;","block_context":{"text":"Bezpe\u010dnos\u0165","link":"https:\/\/preventista.sk\/info\/category\/itbezp\/"},"img":{"alt_text":"\u010co je to kybernetick\u00e1 bezpe\u010dnos\u0165?","src":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2017\/03\/clanok.png?fit=800%2C400&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2017\/03\/clanok.png?fit=800%2C400&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2017\/03\/clanok.png?fit=800%2C400&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/preventista.sk\/info\/wp-content\/uploads\/2017\/03\/clanok.png?fit=800%2C400&ssl=1&resize=700%2C400 2x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts\/2901","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/comments?post=2901"}],"version-history":[{"count":2,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts\/2901\/revisions"}],"predecessor-version":[{"id":2906,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/posts\/2901\/revisions\/2906"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/media\/2907"}],"wp:attachment":[{"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/media?parent=2901"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/categories?post=2901"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/preventista.sk\/info\/wp-json\/wp\/v2\/tags?post=2901"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}