| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Centralizacija kontrole dostopa do IT infrastrukture z implementacijo prehodnega strežnika
Authors:ID Zupan, Luka (Author)
ID Lenart, Gregor (Mentor) More about this mentor... New window
ID Brezavšček, Alenka (Comentor)
Files:.pdf MAG_Zupan_Luka_2026.pdf (1,83 MB)
MD5: 16F8C89EABF09E428B7957564A26AFFE
 
Language:Slovenian
Work type:Master's thesis/paper
Typology:2.09 - Master's Thesis
Organization:FOV - Faculty of Organizational Sciences in Kranj
Abstract:V magistrski nalogi smo obravnavali problem centralizacije dostopa do IT-infrastrukture z implementacijo prehodnega strežnika (angl. jump host). V sodobnih podjetjih predstavlja administratorski dostop do strežnikov in kritičnih sistemov eno največjih varnostnih tveganj, saj so neposredne povezave težko nadzorovane in sledljive. Namen naloge je bil vzpostaviti rešitev, ki omogoča varno, pregledno in centralizirano upravljanje dostopov ter hkrati izboljšuje skladnost podjetja z mednarodnimi standardi informacijske varnosti. Analiza obstoječega stanja v podjetju je pokazala pomanjkljivosti na področjih večfaktorske avtentikacije, centralizacije administratorskih poti, beleženja sej in sistematičnega upravljanja privilegijev. Na podlagi teh ugotovitev smo zasnovali in implementirali prehodni strežnik v okolju VMware ESXi, temelječ na operacijskem sistemu Windows Server 2022. Strežnik je bil umeščen v ločen VLAN in dodatno zaščiten z varnostnimi postopki, kot so varnostno utrjevanje (angl. Hardening) preko objektov pravil skupinske politike (angl. Group Policy Object – GPO), omejitev oddaljenih dostopov (angl. Remote Desktop Protocol – RDP), vzpostavitev večnivojske požarne pregrade (Windows Defender Firewall in Cisco Firepower), uvedba večfaktorske avtentikacije z rešitvijo Cisco Duo ter integracija v sistem SIEM (angl. Security Information and Event Management). Vzpostavljeno je bilo tudi dnevno inkrementalno varnostno kopiranje s sistemom Commvault in rezervni dostop preko osrednjega (angl. Core) stikala, kar zmanjšuje tveganje enotne točke odpovedi (angl. Single Point of Failure – SPOF). Rezultati kažejo, da je uvedena rešitev bistveno izboljšala nivo informacijske in kibernetske varnosti podjetja ter tudi skladnost s standardom ISO/IEC 27001:2022, zlasti na področjih upravljanja dostopov, segmentacije omrežja, avtentikacije in beleženja varnostnih dogodkov. Kljub temu ostajajo možnosti za nadaljnjo nadgradnjo, kot so uvedba rešitev za upravljanje privilegiranih dostopov (angl. Privileged Access Management – PAM), aktivno-pasivna redundanca in sistematično skeniranje ranljivosti. Naloga tako prispeva praktičen primer dobre prakse za podjetje ter metodološki okvir, ki ga je mogoče uporabiti tudi v drugih organizacijah.
Keywords:prehodni strežnik, centralizacija dostopa, upravljanje dostopa, informacijska varnost, kibernetska varnost, večfaktorska avtentikacij (MFA), standard ISO/IEC 27001, varnostno utrjevanje
Place of publishing:Maribor
Year of publishing:2026
PID:20.500.12556/DKUM-96973 New window
COBISS.SI-ID:280015619 New window
Publication date in DKUM:01.06.2026
Views:167
Downloads:12
Metadata:XML DC-XML DC-RDF
Categories:FOV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-SA 4.0, Creative Commons Attribution-ShareAlike 4.0 International
Link:http://creativecommons.org/licenses/by-sa/4.0/
Description:This Creative Commons license is very similar to the regular Attribution license, but requires the release of all derivative works under this same license.
Licensing start date:09.02.2026

Secondary language

Language:English
Title:Centralization of access control to IT infrastructure with implementation of jump host
Abstract:This master’s thesis addresses the problem of access control centralizing to the IT-infrastructure through the implementation of a jump host. In modern enterprises, administrative access to servers and critical systems represents one of the highest security risks, as direct connections are difficult to monitor and audit. The main goal of this thesis was to design and implement a solution that ensures secure, transparent and centralized management of administrative access, while simultaneously improving the company’s compliance with the international information security standards. The analysis of the current state revealed shortcomings in the multi-factor authentication, centralization of administrative access, session logging, and privileged access management. Based on these findings, a jump host server was deployed on VMware ESXi, running on Windows Server 2022. The server was configured in a dedicated VLAN and secured using Group Policy Object hardening, restricted access via Remote Desktop Protocol (RDP), multi-layered firewalls (Windows Defender Firewall and Cisco Firepower), multi-factor authentication with Cisco Duo and integration with the company’s SIEM-system. Furthermore, daily incremental backups using Commvault and fallback access via the core switch were introduced to reduce the risk of a single point of failure (SPOF). The results demonstrate that the implemented solution has significantly improved the company’s security posture as well as the compliance with ISO/IEC 27001:2022, particularly in the areas of access control, network segmentation, authentication and logging. Nevertheless, further improvements remain possible, such as the implementation of Privileged Access Management (PAM) solutions, active-passive redundancy and systematic vulnerability scanning. The thesis therefore contributes both a practical example of best practice for the company under consideration and a methodological framework that can be applied to other organizations.
Keywords:jump host, access control centralization, access management, information security, cybersecurity, multi-factor authenticaiton (MFA), ISO/IEC 27001 standard, system hardening


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica