An Application on Supporting Information Security Management with RPA


BÜYÜKSAATÇI KİRİŞ S., ALTAY Y.

24th International Symposium for Production Research, ISPR 2024, Budva, Montenegro, 10 - 12 October 2024, pp.445-455, (Full Text) identifier

  • Publication Type: Conference Paper / Full Text
  • Doi Number: 10.1007/978-3-031-83583-4_31
  • City: Budva
  • Country: Montenegro
  • Page Numbers: pp.445-455
  • Keywords: Information security, ISO 27001, Management, Robotic process automation, RPA
  • Istanbul University-Cerrahpasa Affiliated: Yes

Abstract

While the rapid advancement of information technologies has improved data accessibility, it has also introduced significant challenges in privacy and security. The risks of data breaches and cyberattacks have increased due to the growing usage of personal computers and the internet. This has particularly affected organizations, leading them to adopt continuously updated security measures and standards to protect information privacy and ensure robust security. To advance information security management in organizations, the ISO/IEC 27,001 standard was established and has since gained worldwide adoption. This study investigates how Robotic Process Automation (RPA) can significantly improve the effectiveness of Information Security Management through a practical application implemented within a company operating in the textile sector. By integrating RPA, the company has automated the email encryption process, ensuring that daily reports related to emails are securely directed only to the intended recipients. With RPA integration, the encryption time for 30 reports has been reduced from 36 h to just 90 min (1.5 h). As a result, multiple staff previously dedicated to encryption have been reassigned to other tasks. Additionally, a security vulnerability in a person-managed encryption process has been eliminated.