diplomska naloga
Abstract
Upravljanje varnostnih informacij in dogodkov (angl. Security Information and Event Management, v nadaljevanju SIEM) je ključno orodje za kibernetsko varnost, ki ponuja konsolidiran pogled na podatke, vpogled v varnostne dejavnosti in operativne zmogljivosti za učinkovit boj proti kibernetskim grožnjam. Rešitve SIEM izboljšujejo stanje informacijske varnosti z zagotavljanjem preglednosti v realnem času in zgodovinske analize. Grožnje in anomalije zaznavajo s hitro analizo ogromnih količin podatkov, kar bi bilo ročno nemogoče. Diplomska naloga predstavi vpeljavo sistema SIEM v srednje velikem podjetju. Najprej smo pregledali lastnosti podjetja in zakaj potrebuje SIEM. Za uspešno vpeljavo smo raziskali, kaj je dejansko SIEM, katere so glavne komponente in lastnosti, ter opisali uveljavljene produkte. Nato sta sledili izbira primernega produkta za naše podjetje in njegova postavitev v okolje. Podjetje je tako izboljšalo informacijsko varnost, začelo shranjevati dnevniške zapise na enem mestu in dobilo vpogled v delovanje informacijskega sistema.
Keywords
SIEM;informacijska varnost;implementacija;SIM;SEM;
Data
Language: |
Slovenian |
Year of publishing: |
2024 |
Typology: |
2.11 - Undergraduate Thesis |
Organization: |
FIŠ - Faculty of Information Studies |
Publisher: |
[A. Grmšek] |
UDC: |
004.056:659.2(043.2) |
COBISS: |
205730819
|
Views: |
52 |
Downloads: |
0 |
Average score: |
0 (0 votes) |
Metadata: |
|
Other data
Secondary language: |
English |
Secondary abstract: |
Essentially, Security Information and Event Management (SIEM) is a key cybersecurity tool that provides a consolidated view of data, insight into security activities, and operational capabilities to effectively combat cyber threats. SIEM solutions improve the state of information security by providing real-time visibility and historical analysis. They detect threats and anomalies by quickly analyzing huge amounts of data, which would be impossible manually. The thesis presents the introduction of a SIEM system in a medium-sized company. First, we reviewed the features of our company and why it needs a SIEM. For a successful implementation, we researched what SIEM actually is, what are the main components and features, and described established products. Then followed the selection of a suitable product for our company and the installation itself in the environment. With this, the company gained information security, started storing event entries in one place and gained insight into the functioning of the information system. |
Secondary keywords: |
SIEM;information security;implementation;SIM;SEM;Univerzitetna in visokošolska dela; |
Type (COBISS): |
Bachelor thesis/paper |
Thesis comment: |
Fakulteta za informacijske študije v Novem mestu |
Source comment: |
Na ov.: Diplomska naloga : visokošolskega strokovnega študijskega programa prve stopnje;
|
Pages: |
XIII, 49 str. |
ID: |
24862700 |