Operational information security risk management in the Wellbeing Services County of Southwest Finland

dc.contributor.authorVälilä, Mikko
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tieto- ja viestintätekniikka|en=Information and Communication Technology|
dc.date.accessioned2023-12-22T22:06:52Z
dc.date.available2023-12-22T22:06:52Z
dc.date.issued2023-12-22
dc.description.abstractThe Wellbeing Services County of Southwest Finland (Varha) was created at the start of the year 2023 after a major health and social services reform was implemented in Finland. The new and developing organization saw demand for research in the field of cyber security where risks to information and applicable security solutions would be accounted for. To meet these requirements, this research was commissioned to investigate risk management and information security frameworks and applications that suit Varha's operations in due manner. As part of this study, an interview was conducted in the organization with a versatile target group in order to receive an extensive overview of the work environment and methods used therein. The study found out that the standards ISO 27799:2016 and ISO 27002:2022 contain recommendations that can be utilized in the social and healthcare sector. They provide aspects that could be used as a frame of reference for information risk management and security in Varha. These standards were reviewed and suitable recommendations from them were applied to the organization’s operational environment. Inapplicable portions from the standards were omitted from the work. Additional documentation in the field of healthcare was investigated to complement the recommendations included in the standards. As a result of this work, a standardized set of risk management and information security recommendations was compiled with an adjoining condensed checklist that can be used for quick validation of the requirements. These findings can be utilized to support and develop the management of information risks and security in Varha.
dc.format.extent67
dc.identifier.olddbid193271
dc.identifier.oldhandle10024/176330
dc.identifier.urihttps://www.utupub.fi/handle/11111/24778
dc.identifier.urnURN:NBN:fi-fe20231222157206
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightssuljettu
dc.source.identifierhttps://www.utupub.fi/handle/10024/176330
dc.subjectcyber security, healthcare, ISO 27002:2022, ISO 27799:2016, risk management, Varha
dc.titleOperational information security risk management in the Wellbeing Services County of Southwest Finland
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Valila_Mikko_thesis.pdf
Size:
871.18 KB
Format:
Adobe Portable Document Format