Security in Practice #01: Prague 2 – Cybersecurity as a Functioning System, Not Just a Set of Technologies
How can a government agency with more than 450 users and 300 workstations and servers ensure cybersecurity? The Prague 2 City District has adopted a comprehensive approach that integrates technology, risk management, security processes, documentation, and expert capabilities. The result is not just technical security, but a functioning cybersecurity management system.

Starting Point: Security Must Function as a Whole
Cybersecurity cannot be built solely on individual technologies. An organization may have tools for endpoint protection, monitoring, log management, or SIEM, but it still needs to know how the individual components relate to one another, what risks they address, who is responsible for them, and how to document the entire system during an audit. It was precisely this comprehensive approach that formed the basis of the cybersecurity project for the Prague 2 City District – City District Office. The project encompasses an environment with more than 300 workstations and servers and 450 users. The scope of delivery included technology, software, and operational support, including five years of manufacturer support. The goal was not merely to deploy security technologies; rather, it was to create a system that would enable long-term security management.
The Four Components of a Single Security System
The solution for Prague 2 is based on four interconnected areas.
1. User and Data Protection
The first area consists of technologies that help protect an agency’s information, control access to it, and prevent unauthorized access, leaks, or misuse of sensitive data. Technical protection is the foundation. However, effective cybersecurity management also requires an understanding of what is happening within the infrastructure and the significance of individual events for the organization.
2. Security Status Overview
The second area involves creating a unified view of important security events across the IT infrastructure. To this end, the project uses the ODP (Open Data Platform), which collects security events from various technologies—such as SIEM, log management, EDR, and Zabbix—and correlates them into a single overview. This provides responsible staff with up-to-date information on the security status, enabling them to respond more quickly to emerging situations.
3. Asset, Risk, and Security Management with OMIS
Technical information must be translated into management practices. This is where OMIS—Open Management for Information Security—comes in; within the project, it handles the management of assets, risks, and security measures. OMIS makes it possible to link information about what the organization protects, what risks its assets are exposed to, and what measures are being taken to manage them. Another important feature is the automatic generation of documents required for security management and auditing—such as Statements of Applicability, Risk Treatment Plans, or Risk Assessment Reports. Risk management is thus not a separate administrative task; it becomes an integral part of ongoing cybersecurity management.
4. Secure Storage of Records
The fourth area consists of logs and other security records. These must be protected against unauthorized deletion or alteration, as they serve as an important source of information during security incident investigations and, at the same time, provide the basis for demonstrating compliance with legal requirements. This enables an organization not only to respond to a security incident but also to retrospectively document relevant information about its course.
Technology is only part of the solution
One of the key principles of the project was that cybersecurity does not end with the installation of technology. Therefore, the implementation also included establishing processes, defining roles and responsibilities, and transferring knowledge so that Prague 2 could independently operate and further develop the system. Throughout the project, the role of cybersecurity manager—including representation before regulatory authorities—was also provided by a contractor. This provides the technology with a clear procedural and organizational framework.
OMIS Integrates Risk Management with Everyday Practice
It is precisely the ability to link individual pieces of information that is essential for long-term security management. It is not enough to simply create a risk analysis and then save it as a document. Risks change along with the organization, its assets, technologies, and operations. OMIS therefore allows you to manage assets, risks, and security measures in a single environment and generate the necessary documentation based on up-to-date information. This gives the organization an overview not only of the risks it has identified but also of how it is managing them.
The result: security that can be managed and verified
Thanks to the project, Prague 2 gained more than just individual security technologies.
A system was created that connects:
- user and data protection,
- an overview of security incidents,
- asset and risk management,
- management of safety measures,
- security processes,
- roles and responsibilities,
- the necessary documentation,
- secure storage of records,
- Professional cybersecurity services.
It is precisely this connection that is important. Security technologies help protect the environment. Data shows what is happening within it. Risk management helps set priorities. Processes define what should happen and who is responsible for it. Documentation and records make it possible to trace the entire process.
From Compliance to True Security
The purpose of a cybersecurity management system is not merely to create documentation for the sake of an audit. Effective security must, above all, support an organization in its day-to-day operations and when a security incident actually occurs. The project for the Prague 2 City District demonstrates how technological protection, monitoring, risk management, processes, responsibilities, and documentation can be integrated into a single, functional system. One provider. Comprehensive cybersecurity—from protection to documentation. The result is a security system with processes, documentation, and expert support that is prepared for both regulatory audits and the resolution of actual security incidents.
OMIS – From Assets and Risks to a Managed Solution
OMIS helps organizations manage assets, assess risks, implement security measures, and generate the necessary outputs for ISMS and audits. Instead of using separate spreadsheets, documents, and records, it integrates key information into a single environment and helps translate cybersecurity management into everyday practice.
Do you want to keep your assets, risks, and security measures under control? Learn more about OMIS.


