Changes in the audit of controls according to the new version of ISO/IEC 27002:2022

Název práce: Changes in the audit of controls according to the new version of ISO/IEC 27002:2022
Autor(ka) práce: Milosavljevic, Nikola
Typ práce: Diploma thesis
Vedoucí práce: Svatá, Vlasta
Oponenti práce: Sigmund, Tomáš
Jazyk práce: English
Abstrakt:
The standard ISO/IEC 27002 was revised, and a new version was published in 2022, changing the list of information security controls given in the standard. Due to this revision, the certification audit process for the standard ISO 27001 certification will be impacted. The primary goal of this paper is to analyse newly introduced controls and their impact on the certification audit process against the standard ISO/IEC 27001. The paper starts with an overview of the ISO 27000 family and main standards and an overview of changes introduced in new versions of both ISO/IEC 27001 and ISO/IEC 27002, followed by an overview of the theory behind audits and information security audits. All new controls from the standard ISO 27002 are described and discussed in terms of risks, control, and testing steps. For each of these controls, a risk control matrix (RCM) is developed and presented in the paper. A demonstration of developed RCMs is conducted through the Case Study written on the example company. It is described how the new controls will impact the example company and what evidence will have to be collected to provide assurance that the new controls are designed and operating effectively.
Klíčová slova: ISMS; ISO/IEC 27002; ISO/IEC 27001; IT Audits; Information security
Název práce: Changes in the audit of controls according to the new version of ISO/IEC 27002:2022
Autor(ka) práce: Milosavljevic, Nikola
Typ práce: Diplomová práce
Vedoucí práce: Svatá, Vlasta
Oponenti práce: Sigmund, Tomáš
Jazyk práce: English
Abstrakt:
The standard ISO/IEC 27002 was revised, and a new version was published in 2022, changing the list of information security controls given in the standard. Due to this revision, the certification audit process for the standard ISO 27001 certification will be impacted. The primary goal of this paper is to analyse newly introduced controls and their impact on the certification audit process against the standard ISO/IEC 27001. The paper starts with an overview of the ISO 27000 family and main standards and an overview of changes introduced in new versions of both ISO/IEC 27001 and ISO/IEC 27002, followed by an overview of the theory behind audits and information security audits. All new controls from the standard ISO 27002 are described and discussed in terms of risks, control, and testing steps. For each of these controls, a risk control matrix (RCM) is developed and presented in the paper. A demonstration of developed RCMs is conducted through the Case Study written on the example company. It is described how the new controls will impact the example company and what evidence will have to be collected to provide assurance that the new controls are designed and operating effectively.
Klíčová slova: ISMS; ISO/IEC 27002; ISO/IEC 27001; IT Audits; Information security

Informace o studiu

Studijní program / obor: Information Systems Management
Typ studijního programu: Magisterský studijní program
Přidělovaná hodnost: Ing.
Instituce přidělující hodnost: Vysoká škola ekonomická v Praze
Fakulta: Fakulta informatiky a statistiky
Katedra: Katedra systémové analýzy

Informace o odevzdání a obhajobě

Datum zadání práce: 20. 10. 2022
Datum podání práce: 28. 6. 2023
Datum obhajoby: 29. 8. 2023
Identifikátor v systému InSIS: https://insis.vse.cz/zp/82446/podrobnosti

Soubory ke stažení

    Poslední aktualizace: