Changes in the audit of controls according to the new version of ISO/IEC 27002:2022
Název práce: | Changes in the audit of controls according to the new version of ISO/IEC 27002:2022 |
---|---|
Autor(ka) práce: | Milosavljevic, Nikola |
Typ práce: | Diploma thesis |
Vedoucí práce: | Svatá, Vlasta |
Oponenti práce: | Sigmund, Tomáš |
Jazyk práce: | English |
Abstrakt: | The standard ISO/IEC 27002 was revised, and a new version was published in 2022, changing the list of information security controls given in the standard. Due to this revision, the certification audit process for the standard ISO 27001 certification will be impacted. The primary goal of this paper is to analyse newly introduced controls and their impact on the certification audit process against the standard ISO/IEC 27001. The paper starts with an overview of the ISO 27000 family and main standards and an overview of changes introduced in new versions of both ISO/IEC 27001 and ISO/IEC 27002, followed by an overview of the theory behind audits and information security audits. All new controls from the standard ISO 27002 are described and discussed in terms of risks, control, and testing steps. For each of these controls, a risk control matrix (RCM) is developed and presented in the paper. A demonstration of developed RCMs is conducted through the Case Study written on the example company. It is described how the new controls will impact the example company and what evidence will have to be collected to provide assurance that the new controls are designed and operating effectively. |
Klíčová slova: | ISMS; ISO/IEC 27002; ISO/IEC 27001; IT Audits; Information security |
Název práce: | Changes in the audit of controls according to the new version of ISO/IEC 27002:2022 |
---|---|
Autor(ka) práce: | Milosavljevic, Nikola |
Typ práce: | Diplomová práce |
Vedoucí práce: | Svatá, Vlasta |
Oponenti práce: | Sigmund, Tomáš |
Jazyk práce: | English |
Abstrakt: | The standard ISO/IEC 27002 was revised, and a new version was published in 2022, changing the list of information security controls given in the standard. Due to this revision, the certification audit process for the standard ISO 27001 certification will be impacted. The primary goal of this paper is to analyse newly introduced controls and their impact on the certification audit process against the standard ISO/IEC 27001. The paper starts with an overview of the ISO 27000 family and main standards and an overview of changes introduced in new versions of both ISO/IEC 27001 and ISO/IEC 27002, followed by an overview of the theory behind audits and information security audits. All new controls from the standard ISO 27002 are described and discussed in terms of risks, control, and testing steps. For each of these controls, a risk control matrix (RCM) is developed and presented in the paper. A demonstration of developed RCMs is conducted through the Case Study written on the example company. It is described how the new controls will impact the example company and what evidence will have to be collected to provide assurance that the new controls are designed and operating effectively. |
Klíčová slova: | ISMS; ISO/IEC 27002; ISO/IEC 27001; IT Audits; Information security |
Informace o studiu
Studijní program / obor: | Information Systems Management |
---|---|
Typ studijního programu: | Magisterský studijní program |
Přidělovaná hodnost: | Ing. |
Instituce přidělující hodnost: | Vysoká škola ekonomická v Praze |
Fakulta: | Fakulta informatiky a statistiky |
Katedra: | Katedra systémové analýzy |
Informace o odevzdání a obhajobě
Datum zadání práce: | 20. 10. 2022 |
---|---|
Datum podání práce: | 28. 6. 2023 |
Datum obhajoby: | 29. 8. 2023 |
Identifikátor v systému InSIS: | https://insis.vse.cz/zp/82446/podrobnosti |