Original title:
Bezpečnostní standardy v organizacích nespadajících pod zákon o kybernetické bezpečnosti
Translated title:
Security Standards in Organizations Not Covered by the Cybersecurity Act
Authors:
Panáček, Martin ; Burda, Karel (referee) ; Zeman, Václav (advisor) Document type: Bachelor's theses
Year:
2026
Language:
cze Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[cze][eng]
Cílem této práce je vytvoření návrhu bezpečnostních standardů a doporučení pro podniky, které nespadají pod zákon o kybernetické bezpečnosti č. 264/2025 Sb. Tyto subjekty se často potýkají s omezeným množstvím kybernetických specialistů, nízkým či žádným povědomím o kybernetické bezpečnosti nebo omezenými finančními prostředky a i přesto je na tyto organizace soustředěno největší procento kybernetických útoků a incidentů. Tato skutečnost velmi často vede k tomu, že malé firmy zaniknou nebo končí bankrotem. V praktické části práce je simulovaná fiktivní firma, která má velice nízké povědomí o kybernetické bezpečnosti a organizace je plná nedostatků, hrozeb a zranitelností. Práce obsahuje postup identifikace dané problémy a jak dané problémy převést na nová opatření a posílení kontinuity firmy. Výstupem této práce je tedy analýza materiálů od různých kybernetických institucí a firem pro manažery nebo ředitele firem, kteří chtějí posílit firemní kybernetickou situaci a vyhnout se tak nepříjemným dopadům a scénářům. Návrh bezpečnostních standardů a doporučení zahrnuje řízení aktiv a jejich kategorizaci, identifikaci hrozeb, dopadu, vyhodnocení rizika a následný návrh opatření.
The aim of this thesis is to create a proposal of security standards and recommendations for enterprises that are not subject to Act No. 264/2025 Coll. on Cybersecurity. These entities often struggle with a limited number of cybersecurity specialists, low or no cybersecurity awareness, or limited financial resources, and despite this, the highest percentage of cyberattacks and incidents is focused on these organizations. This fact very often leads to small companies ceasing to exist or ending in bankruptcy. In the practical part of the thesis, a fictitious company is simulated, which has very low cybersecurity awareness, and the organization is full of deficiencies, threats, and vulnerabilities. The thesis contains a procedure for identifying these problems and how to transform these problems into new measures and the strengthening of business continuity. The output of this thesis is therefore an analysis of materials from various cybersecurity institutions and companies intended for managers or company directors who wish to strengthen the cybersecurity posture of their company and thus avoid unpleasant impacts and scenarios. The proposal of security standards and recommendations includes asset management and their categorization, identification of threats, impacts, risk assessment, and the subsequent proposal of measures.
Keywords:
cybersecurity; data protection; risk analysis; security measures; security standards; small and micro enterprises; analýza rizik; bezpečnostní opatření; bezpečnostní standarty; kybernetická bezpečnost; malé a mikropodniky; ochrana dat
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258298