{"id":6507,"date":"2024-10-10T14:20:46","date_gmt":"2024-10-10T12:20:46","guid":{"rendered":"https:\/\/logmanager.com\/?post_type=case_studies&#038;p=2081"},"modified":"2026-05-27T11:48:25","modified_gmt":"2026-05-27T09:48:25","slug":"pripadova-studie-praha3","status":"publish","type":"resource_centre","link":"https:\/\/logmanager.com\/cs\/zdroje\/pripadova-studie-praha3\/","title":{"rendered":"Odbor informatiky Prahy 3"},"content":{"rendered":"\n<p><strong>Odbor informatiky m\u011bstsk\u00e9 \u010d\u00e1st\u00ed Praha 3 s Logmanagerem z\u00edskal centr\u00e1ln\u00ed \u00falo\u017ei\u0161t\u011b log\u016f s analytick\u00fdmi funkcemi a dostate\u010dn\u00fdm v\u00fdkonem, kter\u00e9 jim pom\u00e1h\u00e1 s provozn\u00edm monitoringem a zaji\u0161t\u011bn\u00edm souladu s bezpe\u010dnostn\u00edmi p\u0159edpisy.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">V\u00fdchoz\u00ed situace<\/h2>\n\n\n\n<p>Odbor informatiky \u00da\u0159adu m\u011bstsk\u00e9 \u010d\u00e1sti Praha 3 spravuje \u0159adu datab\u00e1zov\u00fdch syst\u00e9m\u016f, aplikac\u00ed pro provoz agend a po\u010d\u00edta\u010dovou s\u00ed\u0165. To je v\u00edce jak 300 po\u010d\u00edta\u010d\u016f, 40 virtu\u00e1ln\u00edch server\u016f, p\u0159ev\u00e1\u017en\u011b Windows, 30 p\u0159ep\u00edna\u010d\u016f a dal\u0161\u00edch za\u0159\u00edzen\u00ed.<\/p>\n\n\n\n<p>Aplikace slou\u017e\u00ed p\u0159edev\u0161\u00edm pro podporu v\u00fdkonu st\u00e1tn\u00ed spr\u00e1vy a m\u00edstn\u00ed samospr\u00e1vy. Cel\u00fd informa\u010dn\u00ed syst\u00e9m pak komunikuje s dal\u0161\u00edmi informa\u010dn\u00edmi syst\u00e9my ve\u0159ejn\u00e9 spr\u00e1vy, nap\u0159. je integrov\u00e1n s informa\u010dn\u00edmi syst\u00e9my Z\u00e1kladn\u00edch registr\u016f nebo Datov\u00fdch schr\u00e1nek.<\/p>\n\n\n\n<p>V\u0161echny aplikace, syst\u00e9my a za\u0159\u00edzen\u00ed generuj\u00ed logy, kter\u00e9 byly um\u00edst\u011bny lok\u00e1ln\u011b na za\u0159\u00edzen\u00edch. Nebylo tedy mo\u017en\u00e9 logy nijak korelovat a archivovat. Pouze logy ze s\u00ed\u0165ov\u00fdch za\u0159\u00edzen\u00ed byly uschov\u00e1v\u00e1ny v aplikaci pro management a monitoring HP Intelligent management center.<\/p>\n\n\n\n<p>\u00da\u0159ad m\u011bstsk\u00e9 \u010d\u00e1sti Praha 3 sice nespadal pod p\u016fsobnost Z\u00e1kona o kybernetick\u00e9 bezpe\u010dnosti 181\/2014 Sb., ale odbor informatiky \u00fa\u0159adu se sna\u017eil postupovat v souladu s t\u00edmto z\u00e1konem a odkazuje se na n\u011bj v Bezpe\u010dnostn\u00ed politice \u00fa\u0159adu.<\/p>\n\n\n\n<p>Bezpe\u010dnostn\u00ed politika je zpracov\u00e1na na z\u00e1klad\u011b z\u00e1kona 365\/2000 Sb. o informa\u010dn\u00edch syst\u00e9mech ve\u0159ejn\u00e9 spr\u00e1vy a podle ISO 27001:2005. Vyhl\u00e1\u0161ka k Z\u00e1konu o kybernetick\u00e9 bezpe\u010dnosti po\u017eaduje v \u00a721 \u2014 \u201eN\u00e1stroj pro zaznamen\u00e1v\u00e1n\u00ed \u010dinnost\u00ed kritick\u00e9 informa\u010dn\u00ed infrastruktury a v\u00fdznamn\u00fdch informa\u010dn\u00edch syst\u00e9m\u016f, jejich u\u017eivatel\u016f a administr\u00e1tor\u016f\u201c. V \u00a723 je to pak \u201eN\u00e1stroj pro sb\u011br a vyhodnocen\u00ed kybernetick\u00fdch bezpe\u010dnostn\u00edch ud\u00e1lost\u00ed\u201c.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Kl\u00ed\u010dov\u00e9 v\u00fdzvy projektu<\/h2>\n\n\n\n<p>Vzhledem k nemo\u017enosti sb\u00edrat, archivovat a korelovat logy na jednom m\u00edst\u011b bylo c\u00edlem projektu zajistit centr\u00e1ln\u00ed \u00falo\u017ei\u0161t\u011b log\u016f s dostate\u010dnou kapacitou, v\u010detn\u011b vhodn\u00e9ho n\u00e1stroje pro vyhodnocov\u00e1n\u00ed.<\/p>\n\n\n\n<p>Jedn\u00edm z hlavn\u00edch po\u017eadavk\u016f byl sb\u011br log\u016f ze stanic a server\u016f Windows. Nejl\u00e9pe s mo\u017enost\u00ed filtrov\u00e1n\u00ed odes\u00edlan\u00fdch ud\u00e1lost\u00ed.<\/p>\n\n\n\n<p>Z\u00e1kazn\u00edk tak\u00e9 pot\u0159eboval \u0159e\u0161en\u00ed, kter\u00e9 mu pom\u016f\u017ee splnit legislativn\u00ed po\u017eadavky a po\u017eadavky stanoven\u00e9 Bezpe\u010dnostn\u00ed politikou \u00fa\u0159adu<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">D\u016fvody pro nasazen\u00ed Logmanageru<\/h2>\n\n\n\n<p>Z\u00e1kazn\u00edk vyb\u00edral mezi n\u011bkolika SIEM n\u00e1stroji velk\u00fdch spole\u010dnost\u00ed (ARCSight a QRadar) na jedn\u00e9 stran\u011b, a mezi n\u00e1stroji postaven\u00fdmi na Open Source \u0159e\u0161en\u00edch (Splunk, Nagios).<\/p>\n\n\n\n<p>Syst\u00e9m Logmanager zaujal zlat\u00fd st\u0159ed mezi vybran\u00fdmi \u0159e\u0161en\u00edmi. Svou v\u00fdkonnost\u00ed v po\u010dtu p\u0159ijat\u00fdch EPS zdaleka p\u0159ev\u00fd\u0161il zaveden\u00e9 SIEM syst\u00e9my. Funkcemi pro anal\u00fdzu, reportov\u00e1n\u00ed a alertov\u00e1n\u00ed se jim vyrovnal.<\/p>\n\n\n\n<p>D\u016fle\u017eit\u00fdm parametrem p\u0159i v\u00fdb\u011bru bylo licencov\u00e1n\u00ed. Logmanager nen\u00ed nijak licencov\u00e1n na po\u010dty zdroj\u016f ani EPS.<\/p>\n\n\n\n<p>V konkurenci s open-source syst\u00e9my rozhodlo, \u017ee Logmanager je odlad\u011bn\u00e9 ucelen\u00e9 \u0159e\u0161en\u00ed s jedn\u00edm administra\u010dn\u00edm rozhran\u00edm a \u0159adou funkc\u00ed, kter\u00e1 open-source n\u00e1stroje nenab\u00edzej\u00ed. D\u016fle\u017eitou skute\u010dnost\u00ed je, \u017ee Logmanager nen\u00ed provozov\u00e1n ve virtu\u00e1ln\u00edm prost\u0159ed\u00ed, ale jako samostatn\u00fd server. P\u0159i hav\u00e1rii virtu\u00e1ln\u00edho serveru je log management st\u00e1le v provozu, logy se neztrat\u00ed a je mo\u017en\u00e9 analyzovat d\u016fvody p\u00e1du hypervizoru.<\/p>\n\n\n\n<p>Logmanager z\u00e1rove\u0148 nab\u00eddl vysokou \u00farove\u0148 zabezpe\u010den\u00ed ulo\u017een\u00fdch dat. Ve\u0161ker\u00e1 data jsou ulo\u017eena na diskov\u00e9m poli RAID6 s akcelerovan\u00fdm hardwarov\u00fdm \u0159adi\u010dem. Z bezpe\u010dnostn\u00edho hlediska bylo kl\u00ed\u010dov\u00e9, \u017ee administr\u00e1tor nem\u00e1 mo\u017enost mazat ulo\u017een\u00e1 data.<\/p>\n\n\n\n<p>Logmanager tak\u00e9 splnil pot\u0159ebu sb\u00edrat logy z prost\u0159ed\u00ed Windows, op\u011bt bez nutnosti zvl\u00e1\u0161tn\u00edho licencov\u00e1n\u00ed. Nav\u00edc nab\u00eddnul specialitu \u2013 p\u0159eklad chybov\u00fdch k\u00f3d\u016f Windows do srozumiteln\u00e9 formy, tedy dopln\u011bn\u00ed chybov\u00e9 hl\u00e1\u0161ky m\u00edsto k\u00f3du.<\/p>\n\n\n\n<p>P\u0159i v\u00fdb\u011bru Logmanageru tak\u00e9 rozhodlo, \u017ee syst\u00e9m je certifikovan\u00fd na pln\u011bn\u00ed po\u017eadavk\u016f ISO 27001:2005.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">P\u0159\u00ednosy pro z\u00e1kazn\u00edka<\/h2>\n\n\n\n<p>Logmanager zcela splnil po\u017eadavky na centr\u00e1ln\u00ed \u00falo\u017ei\u0161t\u011b dat a n\u00e1stroje na vyhodnocov\u00e1n\u00ed log\u016f.<\/p>\n\n\n\n<p>Obrovskou v\u00fdhodou vybran\u00e9ho \u0159e\u0161en\u00ed je jeho v\u00fdkon pro p\u0159\u00edjem ud\u00e1lost\u00ed a kapacita pro ukl\u00e1d\u00e1n\u00ed log\u016f. Syst\u00e9m je v provozu necel\u00e9 dva roky a p\u0159i sou\u010dasn\u00e9m mno\u017estv\u00ed p\u0159ij\u00edman\u00fdch log\u016f bude kapacita syst\u00e9mu sta\u010dit na cca 5 let. To je naprosto dostate\u010dn\u00e1 doba pro ulo\u017een\u00ed log\u016f bez nutnosti \u0159e\u0161it jejich retenci.<\/p>\n\n\n<div class=\"pt-20 lg:pt-24 pb-20 lg:pb-24\">\n    <div class=\"max-w-full w-full relative z-10 bg-white flex flex-col justify-center p-10 lg:p-14 rounded-2xl lg:rounded-24\">\n        <svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"67\" height=\"50\" viewBox=\"0 0 67 50\" fill=\"none\"><g clip-path=\"url(#clip0_1406_103)\"><path d=\"M0 40.2085C10.9025 39.1192 16.2645 33.6847 15.478 24.8419H5.68362V0H31.2778V20.9651C31.2778 41.4617 20.8519 49.6955 2.04944 50L0 40.2202L0 40.2085Z\" fill=\"#1111D1\"\/><path d=\"M35.7227 40.2085C46.6252 39.1192 51.9871 33.6847 51.2007 24.8419H41.4063V0H67.0004V20.9651C67.0004 41.4617 56.5745 49.6955 37.784 50L35.7346 40.2202L35.7227 40.2085Z\" fill=\"#1111D1\"\/><\/g><defs><clipPath id=\"clip0_1406_103\"><rect width=\"67\" height=\"50\" fill=\"white\"\/><\/clipPath><\/defs><\/svg>\n        <h5 class=\"text-lg md:text-xl lg:text-2xl text-black leading-[1.6] pt-7 lg:pt-10 pb-4 lg:pb-6\">Nepot\u0159ebujeme drah\u00fd SIEM syst\u00e9m s \u0159adou slo\u017eit\u00fdch funkc\u00ed. Cht\u011bli jsme centr\u00e1ln\u00ed \u00falo\u017ei\u0161t\u011b log\u016f s analytick\u00fdmi funkcemi a dostate\u010dn\u00fdm v\u00fdkonem. Logmanager m\u00e1 p\u0159im\u011b\u0159enou cenu a jednoduch\u00fd, tedy \u017e\u00e1dn\u00fd, syst\u00e9m licencov\u00e1n\u00ed. A to n\u00e1m naprosto vyhovuje.<\/h5> \n        <strong class=\"text-sm lg:text-base\">Tom\u00e1\u0161 Hilmar<\/strong>\n        <span class=\"text-sm lg:text-base\">Vedouc\u00ed odboru informatiky, Praha 3<\/span>\n    <\/div>   \n<\/div>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>D\u016fle\u017eit\u00e1 je i skute\u010dnost, \u017ee je syst\u00e9m spravov\u00e1n z jednotn\u00e9ho administra\u010dn\u00edho rozhran\u00ed a m\u00e1 propracovan\u00fd syst\u00e9m p\u0159\u00edstupov\u00fdch pr\u00e1v.<\/p>\n<\/blockquote>\n\n\n\n<p><strong>Analytick\u00e9 schopnosti Logmanageru jsou vyu\u017e\u00edv\u00e1ny nap\u0159\u00edklad pro:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Audit p\u0159\u00edstupu u\u017eivatel\u016f do informa\u010dn\u00edch syst\u00e9m\u016f.<\/li>\n\n\n\n<li>Audit spou\u0161t\u011bn\u00ed a ukon\u010dov\u00e1n\u00ed proces\u016f ve Windows, monitoring vyu\u017eit\u00ed aplikac\u00ed.<\/li>\n\n\n\n<li>Identifikace komunika\u010dn\u00edch tok\u016f a konfigurace pravidel na firewallu,<\/li>\n\n\n\n<li>Monitoring chov\u00e1n\u00ed u\u017eivatel\u016f v internetu a p\u0159ehledn\u00e9 v\u00fdstupy z Webfilteru firewallu.<\/li>\n\n\n\n<li>Monitoring komunikace s extern\u00edmi subjekty.<\/li>\n\n\n\n<li>Monitoring a \u0159e\u0161en\u00ed komunika\u010dn\u00edch probl\u00e9m\u016f integra\u010dn\u00edch m\u016fstk\u016f mezi informa\u010dn\u00edmi syst\u00e9my.<\/li>\n\n\n\n<li>\u0158e\u0161en\u00ed pracovn\u011b pr\u00e1vn\u00edch probl\u00e9m\u016f \u2013 \u010dinnost u\u017eivatele.<\/li>\n\n\n\n<li>Kontrola \u010dinnosti u\u017eivatel\u016f na n\u00e1v\u0161t\u011bvnick\u00e9 WiFi a vytv\u00e1\u0159en\u00ed statistik.<\/li>\n\n\n\n<li>Kontrola ne\u017e\u00e1douc\u00edch slu\u017eeb na po\u010d\u00edta\u010d\u00edch \u2013 nezda\u0159en\u00e9 \u010di nekompletn\u00ed odinstalace program\u016f.<\/li>\n<\/ul>\n\n\n\n<p>Pracovn\u00edci Odboru informatiky tak\u00e9 vyu\u017e\u00edvaj\u00ed zas\u00edl\u00e1n\u00ed informa\u010dn\u00edch alert\u016f p\u0159i p\u0159ihl\u00e1\u0161en\u00ed administr\u00e1tor\u016f nebo dodavatel\u016f ke spr\u00e1v\u011b bezpe\u010dnostn\u00edch za\u0159\u00edzen\u00ed \u2013 firewall a IPS. A tak\u00e9 p\u0159i p\u0159\u00edstupu p\u0159es Remote desktop protokol na servery s aplikacemi.<\/p>\n\n\n<div class=\"flex items-start gap-4 lg:gap-6 bg-white rounded-2xl lg:rounded-24 p-6 pr-8 lg:p-8 lg:pr-10 my-6 lg:my-10\">\n            <div class=\"flex-shrink-0 size-7\">\n            <svg width=\"28\" height=\"28\" viewBox=\"0 0 28 28\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                <g clip-path=\"url(#clip0_2972_5339)\">\n                <path d=\"M14.0025 28.0049C21.7358 28.0049 28.0049 21.7358 28.0049 14.0025C28.0049 6.26912 21.7358 0 14.0025 0C6.26912 0 0 6.26912 0 14.0025C0 21.7358 6.26912 28.0049 14.0025 28.0049Z\" fill=\"#00E24A\"\/>\n                <path d=\"M12.9659 20V11.2727H15.3864V20H12.9659ZM14.1818 10.1477C13.822 10.1477 13.5133 10.0284 13.2557 9.78977C13.0019 9.54735 12.875 9.25758 12.875 8.92045C12.875 8.58712 13.0019 8.30114 13.2557 8.0625C13.5133 7.82008 13.822 7.69886 14.1818 7.69886C14.5417 7.69886 14.8485 7.82008 15.1023 8.0625C15.3598 8.30114 15.4886 8.58712 15.4886 8.92045C15.4886 9.25758 15.3598 9.54735 15.1023 9.78977C14.8485 10.0284 14.5417 10.1477 14.1818 10.1477Z\" fill=\"white\"\/>\n                <\/g>\n                <defs>\n                <clipPath id=\"clip0_2972_5339\">\n                <rect width=\"28\" height=\"28.0049\" fill=\"white\"\/>\n                <\/clipPath>\n                <\/defs>\n            <\/svg>\n        <\/div>\n    \n    <div class=\"infobox-content leading-normal\"><p>Pokud se chcete o Logmanageru dozv\u011bd\u011bt v\u00edce, nev\u00e1hejte n\u00e1s <a href=\"https:\/\/logmanager.com\/cs\/kontaktujte-nas\/\">kontaktovat<\/a> nebo si zarezervujte <a href=\"https:\/\/logmanager.com\/cs\/demo\/\">nez\u00e1vaznou konzultaci<\/a> s na\u0161\u00edm specialistou.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Odbor informatiky Prahy 3 pou\u017e\u00edv\u00e1 Logmanager pro zaji\u0161t\u011bn\u00ed bezpe\u010dnost ICT a souladu s p\u0159edpisy.<\/p>\n","protected":false},"author":4,"featured_media":2084,"parent":0,"template":"","resource_category":[53],"resource_tag":[],"class_list":["post-6507","resource_centre","type-resource_centre","status-publish","has-post-thumbnail","hentry","resource_category-pripadove-studie"],"acf":[],"_links":{"self":[{"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/resource_centre\/6507","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/resource_centre"}],"about":[{"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/types\/resource_centre"}],"author":[{"embeddable":true,"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":3,"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/resource_centre\/6507\/revisions"}],"predecessor-version":[{"id":7254,"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/resource_centre\/6507\/revisions\/7254"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/media\/2084"}],"wp:attachment":[{"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/media?parent=6507"}],"wp:term":[{"taxonomy":"resource_category","embeddable":true,"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/resource_category?post=6507"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/logmanager.com\/cs\/wp-json\/wp\/v2\/resource_tag?post=6507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}