The thesis discusses network segmentation as technical support for improving information security in an organization that is implementing digitalization processes. Due to the increasing exposure of information systems to various threats and the increasing complexity of their management, segmentation is one possible solution for better control over network traffic and limiting the spread of cyber attacks.
The theoretical part presents essential concepts from the fields of digital transformation, information security, and computer network operation. Various approaches to segmentation are analysed in more detail, including the use of VLANs, access control lists, and the Cisco three-layer model as a basis for structured network infrastructure planning.
The empirical part analyses the network's existing state in the selected organization. Based on the findings, improvement proposals were prepared, with an emphasis on dividing the network into controlled segments. To ensure improved management, the possibility of lateral movement in the event of an incident and the ability to add the network to various security restrictions are enabled.
The thesis findings can be used to upgrade information systems in companies that strive for greater security and stability of their network environments.
|