Implementace systému managementu kybernetické bezpečnosti

Abstract

This bachelor thesis focuses on the analysis of an Information Security Management System (ISMS) in a specific organization and its practical application through an initial (GAP) audit based on the TISAX methodology. The aim of the thesis is to assess the level of ISMS implementation, identify non-conformities, and propose corrective measures to improve security processes within the organization. The theoretical part of the thesis defines key concepts in the field of cybersecurity, principles of ISMS, and relevant normative frameworks, particularly ISO/IEC 27001 and TISAX. The practical part is based on a conducted audit, which included a systematic evaluation of security measures, analysis of identified deficiencies, and formulation of recommendations for their mitigation. Based on the performed audit, the overall evaluation of the organization improved, leading to the successful achievement of TISAX certification. The thesis thus confirms the importance of an initial audit as an effective tool for identifying weaknesses and systematically enhancing the level of information security within organizations.

Description

Delayed publication

Available after

Subject(s)

ISMS, TISAX, cybersecurity, audit, GAP analysis, ISO/IEC 27001, risk management

Citation