1 |
IT-säkerhet i små organisationerMagnusson, Roberth, Rydkvist, Rikard January 2013 (has links)
IT- och informationssäkerhet är ett ständigt aktuellt ämnesområde. ITsäkerhetsarbetei små organisationer framstår som ett underforskat område. Föratt göra en kartläggning av hur arbete med risk, hot och säkerhet kan se ut i småorganisationer har vi genomfört en explorativ intervjustudie med representanterför små organisationer om deras arbete med IT- och informationssäkerhet. Vihar dessutom genomfört intervjuer med experter på området för att få ettbredare perspektiv. Tolkningen och analysen av intervjusvaren har utförtsgenom att först tolka svaren utifrån Security Controls och därefter analyserasvaren utifrån fem temaområden som vi funnit i materialet. Vi går däreftervidare med en diskussion kring hur vi funnit att de studerade organisationernaser på hot, risk och säkerhet och hur de arbetar med Security Controls settgenom de tre säkerhetsdimensionerna. Avslutningsvis föreslår vi fortsattforskning inom området. / IT and information security is a recurring theme. IT security in smallorganizations appear to be an under-researched area. To make a survey of thework on risk, threat and security might look like in small organizations, weconducted an exploratory interview with representatives of small organizationsabout their work with IT and information security. We also conducted interviewswith experts in the field to get a broader perspective. The interpretation andanalysis of the interview responses have been carried out by first interpret theresponses based Security Controls, and then analyze the responses on fivethematic areas which we found in the material. We will then continue with adiscussion of how we have found that the studied organizations, look at threats,risk and safety and how they work with the Security Controls seen through thethree security dimensions. Finally, we suggest further research in this area.
|
2 |
Ett anpassat ledningssystem för informationssäkerhet : - Hur gör en liten organisation med hög personalomsättning?Magnus, Crafoord, Henrik, Sahlin January 2014 (has links)
This paper aims to find out how to implement an information security management (ISMS) system that is based on ISO/IEC 27001-standard into a small organization with high employee turnover. The standard employs the PDCA-method as a course of action for implementing the standard. The reason for implementing such a system is to introduce information security to the organization and to maintain it despite the changes in management. The paper based it’s survey on a case study of a student nation in Uppsala, Sweden. Data was gathered from documents, organization charts, direct observation and by studying physical artifacts. The result of this study showed that it is possible to base an ISMS on the ISO/IEC 27001-standard and that the PDCA-method of implementing the system works if careful adaptation of the two is applied during its establishment into the organization. This paper concludes that certain aspects has to be considered when using the standard and PDCA-method when working with these kinds of organizations. The leadership has to play an active role in maintaining the work related to information security in order to enable continuity in a high employee turnover-organization. Organization members working on a non-profit basis can enable a higher level of security policy compliance since the relationship between employee and the organization stems from a voluntary basis. Build the ISMS so that it focuses on the core operations of the organization. If the ISMS is made to comprehensive there is a risk of it becoming too big for the organization to manage. There should be no doubts regarding who is responsible for the ISMS. The continuity of the system depends on well-established means of knowledge transfer from the departing responsibility holder to his or her successor.
|
3 |
Exploring Reskilling Challenges in the Construction Industry : A case study of a Swedish flooring company / Undersöker utmaningarna med omskolning i byggbranschen : En fallstudie av ett svenskt golvföretagRehnberg, Filip, Lidmår, Emil January 2023 (has links)
The construction industry is facing problems with labour shortages. These problems have occurred because of a declining image, leading to fewer applicants to vocational schools. The purpose of this study was to explore the challenges that small organisations in the Swedish construction industry have to face when conducting reskilling programs. In addition to this the study also wanted to explore if there are any potential solutions to help mitigate the impact of these challenges. The goal of this study was to explore the gaps left by previous research and by that contribute with valuable research. The area that this study aims to help explore is how reskilling can be used in a labour-intensive industry, in this case, the construction industry. The study also wanted to explore reskilling from the perspective of smaller organisations in Sweden. A case study was performed at a small flooring company in Sweden to achieve this purpose. Two forms of data collection methods were completed to gather the primary data for the study. The first data collection method consisted of observations from the case company. Secondly, semi-structured interviews were conducted with several stakeholders in the construction industry, both at the case company and with experts outside the case company. This data was gathered to answer the following research question: RQ1: What are the challenges to reskilling programs in the Swedish construction industry? The challenges found by this study could be divided into three aggregate dimensions: Before, During and After. These aggregate dimensions were chosen to help properly show what challenges reskilling programs face during different phases of the program. / Byggbranschen står inför en brist på arbetskraft. Detta problem har uppstått dels till följd av en sämre bild av branschen, vilket har resulterat i färre sökande till yrkesutbildningar. Syftet med denna studie var att undersöka de utmaningar som små organisationer inom den svenska byggbranschen måste möta när de genomför omskolningsprogram. Utöver detta undersöker studien även om det finns några potentiella lösningar för att mildra effekten av dessa utmaningar. Målet med denna studie var att utforska de luckor som tidigare forskning lämnat och därigenom bidra med värdefull forskning. Området som denna studie avser att undersöka är hur omskolning kan användas inom en arbetsintensiv bransch, i detta fall byggbranschen. Studien ville även undersöka omskolning ur perspektivet av mindre organisationer i Sverige. En fallstudie genomfördes på ett litet golvföretag i Sverige. Två former av datainsamlingsmetoder genomfördes för att samla primärdata till studien. Den första datainsamlingsmetoden bestod av observationer från fallföretaget. För den andra metoden användes semistrukturerade intervjuer med flera intressenter inom byggbranschen, både på fallföretaget och med experter utanför fallföretaget. Denna data samlades in för att besvara följande forskningsfråga: RQ1: Vilka utmaningar finns det för omskolningsprogram inom den svenska byggbranschen? Utmaningarna som identifierades i denna studie kunde delas in i tre övergripande dimensioner: Före, Under och Efter. Dessa övergripande dimensioner valdes för att tydligt visa vilka utmaningar omskolningsprogram står inför under olika faser av programmet.
|
Page generated in 0.0845 seconds