Cybersecurity Renewal in a Healthcare-Adjacent SME through ISO 27001-Aligned Practices

dc.contributor.authorRunola, Aleksi
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2025-06-24T21:06:07Z
dc.date.available2025-06-24T21:06:07Z
dc.date.issued2025-06-18
dc.description.abstractThis thesis investigates the cybersecurity renewal of a Finnish SME subcontractor providing digital room reservation systems for use in healthcare facilities. Despite not processing patient data directly, the company’s systems operated in regulated environments, prompting heightened expectations from clients and regulators alike. Motivated by both internal assessments and external requirements, particularly the demand to align eventually with ISO/IEC 27001, the company undertook a comprehensive renewal process of its infrastructure and security. Through qualitative case study methodology, the thesis investigates and demonstrates the integration of international standards, national tools, and regulatory requirements into development workflows, infrastructure management, and organizational policy. It evaluates the outcomes of the renewal with a focus on technical controls, risk reduction, and alignment with maturity frameworks, while also addressing challenges such as resource constraints and the absence of dedicated security personnel. The findings contribute a transferable model for other SMEs navigating compliance and cybersecurity demands in regulated environments.
dc.format.extent59
dc.identifier.olddbid199373
dc.identifier.oldhandle10024/182405
dc.identifier.urihttps://www.utupub.fi/handle/11111/20621
dc.identifier.urnURN:NBN:fi-fe2025062473323
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightssuljettu
dc.source.identifierhttps://www.utupub.fi/handle/10024/182405
dc.subjectcybersecurity, ISO/IEC 27001, GDPR, Kybermittari, SME, secure software development,health sector, information security maturity
dc.titleCybersecurity Renewal in a Healthcare-Adjacent SME through ISO 27001-Aligned Practices
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Runola_Aleksi_opinnayte.pdf
Size:
672.59 KB
Format:
Adobe Portable Document Format