National Repository of Grey Literature 2 records found  Search took 0.01 seconds. 
Evaluation of preparedness of a business for an implementation of ISO 27001 using Gap analysis
Zrcek, Tomáš ; Čermák, Igor (advisor) ; Šašek, Jaroslav (referee)
The aim of the thesis is to evaluate the preparedness of an information security management system (ISMS) in a logistic company JASA s.r.o. for a certification by standard ISO/IEC 27001:2013. This enterprise oscillates between small and medium enterprise. It has already implemented the certificate on quality management ISO 9001:2008. For this reason, in the thesis there are presented advantages for a company that already has implemented one of ISO standards and decides to implement another. First of all, the present state of information security management system in Jasa s.r.o was compared to other businesses functioning in the Czech and European market. Then the company control environment was evaluated accordingly to the requirements of standard ISO/IEC 27001:2013. Furthermore, a scheme was created in order to evaluate specific controls based on the impact risk that could arise in case of ignoring the suggested recommendations. In the last part, the controls were evaluated accordingly to difficulty, so that the company can find cheap and fast solutions with adequate impact. The main contribution of the thesis is the evaluation of the approach to solve information security in one of many enterprises that are afraid or are starting to notice the increasing amount of security threats. This approach may be chosen by other companies that decide to go the similar way.
Process and technological security audit based on open source methodology
Zrcek, Tomáš ; Gála, Libor (advisor) ; Šašek, Jaroslav (referee)
This thesis is focused on a process and technological security audit. First, the concept of this audit is described and then various approaches that deal with such issues are summarised. Furthermore, some criteria, that each process and technological security audit should meet, are set so that the result of an audit is of sufficient quality. Part of this thesis contains a procedure that states activities that are done before, during and after such audit. The main benefit of this thesis is an evaluation whether procedures and outcomes of the process and technological security audit based on an open source MetDK methodology achieve sufficient quality that is defined for this area. The work is based on a specific company (Jasa s.r.o.). The process and technological security audit based on MetDK methodology was executed in this company and the output of this activity contains a final audit report.

Interested in being notified about new results for this query?
Subscribe to the RSS feed.