| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Pomembnost vzdrževanja varnosti informacijskih sistemov v podjetju h : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Authors:ID Sagadin, Tilen (Author)
ID Bernik, Igor (Mentor) More about this mentor... New window
Files:.pdf VS_Sagadin_Tilen_2026.pdf (441,51 KB)
MD5: FD2C542CE058CF4FDE8AED771EA54AED
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:Informacijska varnost je ključnega pomena za nemoteno delovanje organizacij, saj so informacijski sistemi izpostavljeni številnim grožnjam, kot so kibernetski napadi, zlonamerna programska oprema, nepooblaščeni dostopi in človeške napake. Učinkovito varovanje informacij zahteva usklajeno uporabo tehničnih, organizacijskih in kadrovskih ukrepov. Diplomsko delo obravnava vzdrževanje varnosti informacijskih sistemov s poudarkom na upravljanju tveganj, varnostnih politikah, standardu ISO/IEC 27001 in vlogi zaposlenih pri zagotavljanju informacijske varnosti. V teoretičnem delu so predstavljene ključne varnostne grožnje, pravni in standardni okvir ter temeljni pristopi k obvladovanju informacijskih tveganj. V praktičnem delu je izvedena študija primera podjetja XY. Analiza temelji na pregledu interne dokumentacije, varnostne politike, postopkov upravljanja tveganj in tehničnih ter organizacijskih ukrepov. Ugotovitve kažejo, da ima podjetje vzpostavljen učinkovit sistem upravljanja informacijske varnosti, vendar so bile ugotovljene tudi pomanjkljivosti na področju formalizacije metodologije upravljanja tveganj, dokumentiranja incidentov in spremljanja učinkovitosti varnostnih ukrepov. Na podlagi ugotovitev so podana priporočila za nadaljnje izboljšanje sistema informacijske varnosti. Raziskava potrjuje, da učinkovita zaščita informacijskih sistemov temelji na celovitem pristopu, ki povezuje tehnološke rešitve, organizacijske procese in ozaveščene zaposlene.
Keywords:podjetja, informacijski sistemi, informacijska varnost, upravljanje tveganj, varnostna politika, kibernetska varnost, ISO/IEC 27001, diplomske naloge
Publication status:Published
Publication version:Version of Record
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:T. Sagadin
Year of publishing:2026
Year of performance:2026
Number of pages:VII f., 47 str.
PID:20.500.12556/DKUM-98569 New window
UDC:005.934:004.056(043.2)
COBISS.SI-ID:289154819 New window
Publication date in DKUM:27.08.2026
Views:131
Downloads:3
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:21.06.2026

Secondary language

Language:English
Title:The Importance of Maintaining the Security of Information System in Company H
Abstract:Information security is of crucial importance for the uninterrupted operation of organizations, as information systems are exposed to numerous threats, such as cyberattacks, malware, unauthorized access, and human error. Effective information protection requires the coordinated implementation of technical, organizational, and personnel measures. This bachelor's thesis examines the maintenance of information systems security, with a focus on risk management, security policies, the ISO/IEC 27001 standard, and the role of employees in ensuring information security. The theoretical part presents the main security threats, the legal and standardization framework, and the fundamental approaches to information risk management. The practical part consists of a case study of company XY. The analysis is based on a review of internal documentation, the security policy, risk management procedures, and technical and organizational security measures. The findings indicate that the company has established an effective information security management system; however, certain deficiencies were identified in the areas of formalizing the risk assessment methodology, incident documentation, and monitoring the effectiveness of security measures. Based on the findings, recommendations for further improvement of the information security management system are provided. The research confirms that effective information systems protection is based on a comprehensive approach that integrates technological solutions, organizational processes, and security-aware employees.
Keywords:information security, risk management, security policy, ISO/IEC 27001, cybersecurity


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica