| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Zagotavljanje skladnosti z direktivo NIS2 v proizvodnem podjetju
Authors:ID Puščenik, Maj (Author)
ID Brezavšček, Alenka (Mentor) More about this mentor... New window
Files:.pdf UN_Puscenik_Maj_2025.pdf (898,51 KB)
MD5: 58FDDA10D6E76F1A156E7B69D41BD60A
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:Diplomsko delo obravnava skladnost proizvodnega podjetja z direktivo NIS2, ki določa strožje zahteve za kibernetsko varnost bistvenih subjektov. Namen naloge je bil ugotoviti do kake mere obravnavano proizvodno podjetje izpolnjuje zahteve NIS2 in katere ukrepe mora uvesti za dosego skladnosti. Za oceno skladnosti sta bili izvedeni sistematična analiza obstoječega stanja in analiza vrzeli. Metodologija je temeljila na 21. členu direktive NIS2, modelih zrelosti (ENISA, NIST CSF) ter priporočilih ISO 27001 in ISO 27005. Rezultati kažejo, da podjetje dosega srednjo stopnjo skladnosti. Največje pomanjkljivosti so na področjih poročanja o incidentih, varnosti dobavne verige, ozaveščanja zaposlenih in upravljanja ranljivosti v OT-okolju. Med dobro urejena področja sodijo nadzor dostopov, segmentacija IT/OT in kriptografska zaščita. Na podlagi ugotovitev so bili oblikovani organizacijski, tehnični in procesni ukrepi ter načrt njihove uvedbe po prioritetah. Priporočila vključujejo krepitev povezovanja IT in OT, specializirana usposabljanja za proizvodnjo ter redne presoje skladnosti. Zaključek potrjuje, da ima podjetje dobro osnovo, vendar mora ukrepe nadgraditi, da bo doseglo polno skladnost z direktivo.
Keywords:proizvodno podjetje, operativna tehnologija, kibernetska varnost, direktiva NIS2, skladnost
Place of publishing:Maribor
Year of publishing:2025
PID:20.500.12556/DKUM-95318 New window
COBISS.SI-ID:254407683 New window
Publication date in DKUM:23.10.2025
Views:165
Downloads:51
Metadata:XML DC-XML DC-RDF
Categories:FOV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:12.09.2025

Secondary language

Language:English
Title:Compliance assurance with the nis2 directive in a manufacturing company
Abstract:This thesis examines the compliance of a manufacturing company with the NIS2 Directive, which sets stricter requirements for the cybersecurity of essential entities. The purpose of the study was to determine the extent to which the observed manufacturing company meets the requirements of NIS2 Directive and which measures must be implemented to achieve full compliance. To assess compliance, a systematic analysis of the current state and a gap analysis were carried out. The methodology was based on Article 21 of the NIS2 Directive, maturity models (ENISA, NIST CSF), and the recommendations of ISO 27001 and ISO 27005. The results show that the company achieves a medium level of compliance. The greatest shortcomings were identified in incident reporting, supply chain security, employee awareness, and vulnerability management in the OT environment. Well-established areas include access control, IT/OT segmentation, and cryptographic protection. Based on these findings, organizational, technical, and process measures were developed, along with a prioritized implementation plan. The recommendations include strengthening IT and OT integration, specialized training for production staff, and regular compliance audits. The conclusion confirms that the company has a solid foundation but needs to further improve its measures to achieve full compliance with the Directive.
Keywords:manufacturing company, operational technology, cybersecurity, NIS2 Directive, compliance


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica