| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Vzpostavitev sistema upravljanja informacijske varnosti v javnem skladu
Authors:ID Trček, Darinka (Author)
ID Brezavšček, Alenka (Mentor) More about this mentor... New window
Files:.pdf MAG_Trcek_Darinka_2018.pdf (1,70 MB)
MD5: 4A81F334AA74758F0F827D032E0BEC5B
PID: 20.500.12556/dkum/b5840e2e-cfa9-4934-ac77-576cfbe4120d
 
Language:Slovenian
Work type:Master's thesis/paper
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:V magistrskem delu smo predstavili model vzpostavitve sistema upravljanja informacijske varnosti v štirih fazah, pri čemer smo zasledovali procesni pristop z uporabo temeljnih faz Demingovega kroga – načrtovanje, uvedba, preverjanje in ukrepanje, ki jih priporoča tudi ISO/IEC družina standardov 27000 za področje informacijske varnosti. Model je apliciran na konkretno organizacijo – Javni štipendijski, razvojni, invalidski in preživninski sklad Republike Slovenije. Podrobneje smo se v magistrskem delu usmerili v prvo fazo vzpostavitve – načrtovanje. Poleg pregleda trenutnega stanja smo izvedli popis ključnih procesov, ovrednotili dobrine in opredelili grožnje ter pripravili oceno tveganj. Ta je bila podlaga za pripravo načrta varovalnih ukrepov, ki skupaj s predlogom krovne politike informacijske varnosti in načrtom implementacije SUIV tvori predlog načrta uvedbe SUIV, ki ga potrdi poslovodstvo. Za nadaljnje tri faze – uvedbo SUIV, vzpostavitev sistema kontrol in nadzora SUIV ter analizo odstopanj SUIV z izvajanjem korektivnih ukrepov - so podana priporočila. Ker so zaposleni pogosto eden najšibkejših členov pri zagotavljanju informacijske varnosti, so podana tudi priporočila glede dviga ozaveščenosti, usposabljanja in izobraževanja zaposlenih na področju informacijske varnosti.
Keywords:varnost, informacijski sistem, upravljanje, SUIV, javna uprava
Place of publishing:Maribor
Year of publishing:2018
PID:20.500.12556/DKUM-72484 New window
COBISS.SI-ID:8066323 New window
NUK URN:URN:SI:UM:DK:IFI02IIJ
Publication date in DKUM:12.11.2018
Views:1844
Downloads:303
Metadata:XML DC-XML DC-RDF
Categories:FOV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:27.09.2018

Secondary language

Language:English
Title:Implementation of information security management system in a public fund
Abstract:The master’s thesis presents a model for implementation of information security management system (ISMS) in four phases, using the process approach based on Deming circle – plan, do, check, act. This process is also recommended by the ISO/IEC 27000 family of standards on information security. The model is applied on a specific organisation – Slovene Scholarship, Development, Disability and Maintenance Fund of the Republic of Slovenia. The thesis focuses primarily on the first phase of the process – planning. After the review of the current state of the information security in the organisation we identified key business processes, evaluated the information assets, defined threats and conducted a risk assessment. Based on that we prepared an action plan to address major information security threats. We also prepared a proposal of the general information security policy and ISMS implementation plan. Together they form a proposal to the management regarding ISMS implementation. Recommendations are given for next three phases of ISMS implementation – ISMS introduction, verification and corrective actions. Considering employees are one of the weakest links in ensuring information security, recommendations regarding programmes for raising awareness, training and education of employees on information security are given.
Keywords:Security, Information systems, Management, ISMS, Public sector


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica