Details

Vidiki kibernetske varnosti pri razvoju informacijskih sistemov v javni upravi
ID Horvat, Blaž (Author), ID Sedlar, Urban (Mentor) More about this mentor... This link opens in a new window

.pdfPDF - Presentation file, Download (4,62 MB)
MD5: C0FC3AE6884794E8B2B9C1B319D0DDAC

Abstract
Zaključno delo obravnava vidike kibernetske varnosti pri razvoju informacijskih sistemov v javni upravi Republike Slovenije. Informacijski sistemi predstavljajo ključni element za delovanje sodobne javne uprave, njihova varnost pa je zaradi vse večjih groženj bistvena za zagotavljanje stabilnosti in varnosti države. V zaključnem delu so opredeljeni pojmi informacijskih sistemov in kibernetske varnosti ter opisana pravna ureditev tega področja v Evropski uniji in Republiki Sloveniji. Predstavljeni so sodobni pristopi vključenosti varnosti v procese razvoja informacijskih sistemov, kot so izvajanje statične in dinamične analize kode, uporaba pristopa DevSecOps, avtomatizacija varnostnih testov ter napredne tehnike zaščite podatkov, med katere sodijo metode šifriranja, anonimizacija in psevdonimizacija podatkov. Obravnavani so tudi ukrepi za omrežno zaščito, zagotavljanje varnosti kontejnerskih okolij ter uporaba umetne inteligence in avtomatizacije pri odzivanju na varnostne incidente. Posebna pozornost je namenjena analizi varnostnih zahtev v razpisni dokumentaciji za izgradnjo informacijskih sistemov javne uprave, pri čemer so analizirani štirje konkretni primeri s področja pravosodja, zdravstva, socialnega varstva in inšpekcijskega nadzora. Na podlagi izvedene analize so oblikovani predlogi izboljšav, ki vključujejo zgodnje izvajanje varnostnih pregledov, centralizirano upravljanje identitet in dostopov ter redno izvajanje penetracijskih testov. V zaključnem delu je poudarjena tudi nujnost sistematične vključitve kibernetske varnosti v vse faze razvoja informacijskih sistemov, dosledno upoštevanje zakonodajnih zahtev ter uporabo sodobnih varnostnih tehnologij in praks za zagotavljanje visoke ravni informacijske varnosti v javni upravi.

Language:Slovenian
Keywords:Kibernetska varnost, Informacijski sistemi, Javna uprava, Informacijska zakonodaja, DevSecOps
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FE - Faculty of Electrical Engineering
Year:2026
PID:20.500.12556/RUL-179909 This link opens in a new window
COBISS.SI-ID:280503555 This link opens in a new window
Publication date in RUL:26.02.2026
Views:403
Downloads:214
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Secondary language

Language:English
Title:Cybersecurity Aspects in the Development of Information Systems in Public Administration
Abstract:
This thesis explores various aspects of cybersecurity during the development of information systems within the public administration of the Republic of Slovenia. It emphasizes that information systems are essential components of modern public administration, and their security is increasingly critical given the growing cyber threats that can compromise national stability and safety. It begins by clarifying the fundamental concepts of information systems and cybersecurity, followed by an examination of the relevant cybersecurity regulation in both the European Union and Slovenia. It presents modern approaches to integrating security into the development processes of information systems, such as the implementation of static and dynamic code analysis, the use of the DevSecOps approach, the automation of security testing, and advanced data protection techniques, including encryption, anonymization, and pseudonymization. It also covers network protection measures, securing containerized environments, and the use of artificial intelligence and automation in responding to security incidents. Special attention is given to the analysis of security requirements in public procurement documentation for the development of public sector information systems. Four concrete cases are examined from the areas of justice, healthcare, social welfare, and inspection oversight. Based on the analysis, improvement proposals are made, including the early execution of security reviews, centralized identity and access management, and regular penetration testing. The thesis also emphasizes the necessity of systematically incorporating cybersecurity into all phases of information system development, adhering strictly to legislative requirements, and using modern security technologies and practices to ensure a high level of information security in public administration.

Keywords:Cybersecurity, Information Systems, Public Administration, Information Legislation, DevSecOps

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back