| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Človeški vidik varnosti računalništva v oblaku
Authors:ID Maraž, Nataša (Author)
ID Leskovar, Robert (Mentor) More about this mentor... New window
Files:.pdf MAG_Maraz_Natasa_2016.pdf (572,96 KB)
MD5: 1C0D95E3A5F5F8D2DBF8B53C54761D56
 
Language:Slovenian
Work type:Master's thesis/paper
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:Magistrska naloga obravnava človeške aspekte varnosti računalništva v oblaku. Predstavljen je pregled literature na področju oblačnih storitev oziroma računalništva v oblaku. Podan je tudi pregled uporabe oblačnih storitev z vidika posameznika in organizacij, še posebej pri storitvah v bančništvu. Zaradi čedalje večje uporabe oblačnih storitev v bančništvu je opredeljen pristop ohranjanja informacijske varnosti, ki jih zagotavljajo tri glavne dimenzije. Navedene so tudi trenutno veljavne regulatorne zahteve in priporočila politike uporabe zunanjih izvajalcev, kot tudi veljavna zakonodaja na področju varovanja podatkov. Podrobneje je opisan psihološki vidik varnosti v virtualnem prostoru, saj je varovanje informacij pred osebjem in zunanjimi izvajalci zelo pomembno področje varovanja informacij. Notranje osebje, torej zaposleni, predstavljajo največje tveganje in lahko povzročijo največ škode, kljub temu pa se najpogosteje zanemarjajo kot varnostna grožnja. Poudarjeni so socialni inženiring, oblike samopomoči in opolnomočenje. Kot pomemben element varovanja podatkov je izpostavljen pomen zaupanja tako v operacijski sistem in strojno oz. tehnično opremo, kot tudi v osebje oziroma zaposlene v organizaciji. Analiziranih in opisanih je nekaj odmevnih primerov delovanja posameznikov in skupin, ki so povzročile varnostne incidente oz. zlorab oblačnih storitev in njihove posledice. Naveden je primer dobre prakse usposabljanja zaposlenih za varno uporabo oblačnih storitev v javni upravi z veljavno zakonodajo in možnimi rešitvami. V grafičnem prikazu je predstavljen model usposabljanja zaposlenih za varno uporabo oblačnih storitev, ki temelji na upoštevanju kombinacije usposobljenega osebja, postopkov in tehnologije ter navodil oziroma informacij s katerimi se lahko zagotovi varnost. Model vključuje tudi sistem SUVI, ki je natančneje opredeljen. Kot pomemben povezovalni element modela usposabljanja nastopa ozaveščenost o varnosti oziroma varni uporabi oblačnih storitev. V ekranskih slikah in z vsebinsko razlago je predstavljen poenostavljen primer usposabljanja zaposlenih za varno uporabo oblačnih storitev.
Keywords:računalništvo v oblaku, kibernetska varnost, zloraba informacij, ozaveščenost, oblačne storitve v bančništvu, model izobraževanja in usposabljanja zaposlenih za varno uporabo oblačnih storitev
Place of publishing:Maribor
Year of publishing:2016
PID:20.500.12556/DKUM-62892 New window
COBISS.SI-ID:7746067 New window
NUK URN:URN:SI:UM:DK:LGCUPDEW
Publication date in DKUM:07.10.2016
Views:1692
Downloads:194
Metadata:XML DC-XML DC-RDF
Categories:FOV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Secondary language

Language:English
Title:Human Aspects of Cloud Computing Security
Abstract:This Master's thesis deals with the human aspect of cloud computing security. It provides an overview of the literature available in the field of cloud services or cloud computing and an overview of the use of cloud services from the perspective of individuals and organisations, particularly for those services used in banking. The growing use of cloud computing in banking requires a new approach to information security management, which is presented within three main dimensions. It also lists the currently applicable regulatory requirements and outsourcing policy recommendations, as well as the applicable legislation in the field of data protection. It describes in detail the psychological aspects of cyber security, since the protection of information against staff and external service providers is an extremely important element in information security. Internal staff or employees represent the greatest risk and can cause most damage, however they often seem to be ignored as a security threat. The main highlights in this respect are social engineering, self-help and empowerment. An important data protection element is trust in the operating and hardware systems as well as the staff or employees working in the organisation. Several high-profile security breaches conducted by individuals or groups and their implications have been analysed and presented, as they led either to security incidents or abuse of information. There is also a good practice case of employee training on safe use of cloud services by the public administration with the applicable legislation and potential solutions. The graphic presentation shows a model of education and training of employees for safe use of cloud services based on the combination of employees’ skills, procedures and technology as well as security instructions or information. The model also consists of the Information Security Management System (ISMS), which is presented in detail. Raising the awareness of safety or safe use of cloud services is an important binding element in the training model. A simplified employee training model on safe use of cloud services is therefore provided along with the screen prints and text describing the activities.
Keywords:cloud computing, cyber security, abuse of information, awareness, cloud computing in banking, model of education and training of employees for safe use of cloud services


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica