| In the "big data" era of today,the information is in everywhere.For enterprises,information is an important internal asset,but also the core management objects.Retail enterprises have more information,and involve a lot of money and consumers’ privacy.So,information security management requirements will be higher for them.This paper discusses the theory of information security framework based on the basic theory of data management and risk management.Then,the characteristics of information security management in retail industry are discussed.The GIM Company as a typical retail enterprise is taken to study.The paper puts forward the design principle of the company’s information security management system,based on the current situation of GIM Company’s information security management.It discusses the specific implementation plan,through the critical point analysis system test;forecast the possible risks and the corresponding countermeasures,so as to complete the analysis of the feasibility of the implementation of information security management system in retail enterprises.This study is expected to provide a useful reference for the large retail industry and even more industries in the design and implementation of information security management system,and also provide a reference for subsequent theoretical research. |