Design, Implementation, and Evaluation of ISO 27001 Process Controls in IT Infrastructure: An Analysis of Risk Probability and Process Efficiency

dc.contributor.authorSalminen, Joonas
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2026-04-29T22:47:35Z
dc.date.issued2026-03-30
dc.description.abstractISO/IEC 27001:2022 is a cybersecurity standard developed by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), against which organizations can certify their Information Security Management System (ISMS). This thesis has been carried out with an organization operating in the IT industry. ISO/IEC 27001 is a widely recognized standard, and the organization has therefore chosen to certify its ISMS against it. The increasing number of cyber threats, growing regulatory requirements, and customer expectations serve as the primary drivers for pursuing certification. A literature review is conducted to establish a foundational understanding of the subject and to examine the requirements of the standard. The empirical part of the research is carried out as a case study for the organization. Six controls from Annex A of ISO/IEC 27001 are selected for design and implementation in order to strengthen the cybersecurity of the organization's IT infrastructure and ensure compliance with the standard. A qualitative analysis is performed to assess how the implemented controls mitigate identified risks, how they influence process efficiency, and whether opportunities exist for automation to reduce any negative impacts on efficiency. The findings indicate that the implemented controls are effective in mitigating threats. However, the increased need for documentation reduces process efficiency. Consequently, several automation opportunities are proposed to minimize these negative effects.
dc.format.extent81
dc.identifier.urihttps://www.utupub.fi/handle/11111/60101
dc.identifier.urnURN:NBN:fi-fe2026042030232
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.subjectISO/IEC 27001
dc.subjectcybersecurity
dc.subjectIT infrastructure
dc.subjectInformation Security Management System
dc.subjectAnnex A controls
dc.titleDesign, Implementation, and Evaluation of ISO 27001 Process Controls in IT Infrastructure: An Analysis of Risk Probability and Process Efficiency
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Salminen_Joonas_opinnayte.pdf
Size:
583.44 KB
Format:
Adobe Portable Document Format