Informacijos saugos standarto mažoms ir vidutinėms įmonėms kūrimas
Jankauskas, Donatas |
Baigiamajame magistro darbe sprendžiama informacijos saugos standarto, skirto mažoms ir vidutinėms įmonėms (MVĮ) poreikio problema. Problemos sprendimo buvo ieškoma išsamiai nagrinėjant šiuo metu esančius informacijos saugos standartus, atliekant Lietuvos mažų ir vidutinių įmonių informacijos saugos tyrimą, remiantis užsienio šalyse atliktais MVĮ informacijos saugos tyrimų rezultatais bei gilinantis į jų poreikius. Atlikus esamų informacijos standartų apžvalgą ir tyrimų analizę, pateikiamos rekomendacijos ir pasiūlomas informacijos saugos standartas, orientuotas į esamą MVĮ informacijos saugos situaciją, atitinkantis šių įmonių mąstyseną ir saugos poreikius - tai buvo pagrindinis šio baigiamojo darbo tikslas. Taip pat nurodoma, kuriuos standarto punktus pagal įmonės dydį rekomenduojama taikyti. Pasiūlyto standarto struktūra pagrįsta atliktų informacijos saugos tyrimų ir esamų informacijos saugos standartų analizės rezultatais bei patirtimi dirbant MVĮ.Baigiamąjį darbą sudaro 7 dalys: įvadas, mažų ir vidutinių įmonių (MVĮ) apibrėžtis, MVĮ informacijos saugos tyrimų ir informacijos saugos standartų analizė, siūlomo saugos standarto struktūra, išvados, literatūros sąrašas, priedai. Darbo apimtis - 79 psl. teksto be priedų, 13 iliustracijos, 13 lentelių, 34 literatūros šaltiniai.Atskirai pridedami darbo priedai.
The master thesis deals with demand problem of information security standard for small and medium-sized enterprises (SME). Solution of this problem was sought by detailed examination of existing information security standards, by proceeding an information security research in Lithuanian medium-sized enterprises, by analyzing SME information security researches carried in foreign countries, and by delving deeper into the needs of SMEs. The recommendations were suggested, and information security standard focused on the current information security situation of SMEs, and corresponding the needs and mindset of these enterprises was proposed after reviewing the existing information security standards and when research analysis was done - this was the main goal of this thesis. It is also indicated which points of the standard according to the size of the company is recommended to apply. Proposed structure of the standard is based on the results of information security researches and analysis of the existing information security standards, as well as experience working in SMEs.The thesis consists of the following parts: the introduction, the definition of small and medium-sized enterprises (SME), the analysis of SME information security researches and information security standards, the structure of proposed security standard, the conclusions, the bibliography and the appendices.The volume of this thesis: 79 pages of text, excluding appendices, 13 illustrations, 13 tables and 34 literature entries.Appendices are attached separately.