| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Oblikovanje dostopnih pravic po standardu ISO 27001
Authors:ID Martinjak, Klavdija (Author)
ID Rajkovič, Uroš (Mentor) More about this mentor... New window
Files:.pdf VS_Martinjak_Klavdija_2020.pdf (3,73 MB)
MD5: 1AF8BEA257214A9E6DE383903ACCFBD0
PID: 20.500.12556/dkum/91c1e621-7932-4e7e-aa2a-7bf826d62466
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:Podjetja in organizacije se vse bolj zavedajo pomembnosti informacij, ki so ključne za upravljanje procesov. Učinkovit nadzor z upoštevanjem mednarodno uveljavljenih varnostnih standardov je osnova informacijske varnosti. V informacijskih sistemih so shranjeni pomembni podatki za upravljanje in vodenje podjetij in organizacij, dostop do njih pa je treba skrbno nadzorovati, saj ta nadzor pomeni enega najpomembnejših temeljev informacijske varnosti. V diplomskem delu obravnavamo dodeljevanje dostopnih pravic v informacijskem sistemu Infor LN. Prav te dodeljene pravice so nepregledne in vnos novih zahteva veliko dodatnega ročnega dela za posamezni subjekt. Sledili smo dvema najpomembnejšima ciljema, tj. razvrstiti subjekte z enakimi nivoji pooblaščenosti v matriko dostopnih pravic in izboljšati kontrolo dodeljevanja teh. Obstoječe dostopne pravice smo razvrstili v nove skupine, imenovane vloge oz. role, ki so skupne za več subjektov. Te smo uporabili v matriki, s čimer smo dosegli boljšo preglednost ter enostavno delo z dodajanjem in odvzemanjem avtorizacij. Z upoštevanjem mednarodnega standarda ISO 27001, ki zahteva evidentirane procese, smo zasnovali postopek potrjevanja in odobravanja dostopnih pravic.
Keywords:poslovno informacijski sistem, standard ISO 27001, ključni uporabnik, dostopne pravice.
Place of publishing:Maribor
Year of publishing:2020
PID:20.500.12556/DKUM-78116 New window
COBISS.SI-ID:57991427 New window
NUK URN:URN:SI:UM:DK:EEIRLVHW
Publication date in DKUM:01.04.2021
Views:1537
Downloads:229
Metadata:XML DC-XML DC-RDF
Categories:FOV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:27.10.2020

Secondary language

Language:English
Title:Designing access rights according to ISO 27001 standard
Abstract:Companies and organizations are becoming more and more aware of the importance of information, which is essential for process management. Effective supervision in accordance to international security standards is the basis for informational security. There is many important information for managing companies and organizations saved in information systems. Access to them must be strictly supervised, because this supervision means one of the most important foundations informational security. In this bachelor's thesis we are discussing allocation of access rights in the information system Infor LN - these access rights are unclear and an impute of new ones demands a lot of manual work for each subject. We followed two of the most important goals; to sort our subjects with the same level of authorization into the matrix of access rights and to improve the allocation of them. We have divided the already existent access rights into new groups called »roles«, which are joint of numerous subjects. We used them in a matrix and in this way managed to have greater clarity and simpler work with addition and dispossession of authorization. In accordance to international standard ISO 27001, which demands recorded processes we designed a method of confirmation and improvement of access rights.
Keywords:Enterprise resource planning, standard ISO 27001, key user, access rights.


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica