Skip to main navigation Skip to search Skip to main content

Modelo de gestión de riesgos de seguridad de información para mitigar el impacto en las PYMEs en Perú

Translated title of the contribution: Information security risk management model for mitigating the impact on SMEs in Peru
  • Daniel Felipe Carnero Garay
  • , Carbajal Ramos Marcos Antonio
  • , Jimmy Armas-Aguirre
  • , Juan Manuel Madrid Molina
  • Universidad Peruana de Ciencias Aplicadas
  • Universidad ICESI

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

This paper proposes an information security risk management model that allows mitigating the threats to which SMEs in Peru are exposed. According to studies by Ernst Young, 90% of companies in Peru are not prepared to detect security breaches, and 51% have already been attacked. In addition, according to Deloitte, only 10% of companies maintain risk management indicators. The model consists of 3 phases: 1. Inventory the information assets of the company, to conduct the risk analysis of each one; 2. Evaluate treatment that should be given to each risk, 3. Once the controls are implemented, design indicators to help monitor the implemented safeguards. The article focuses on the creation of a model that integrates a standard of risk management across the company with a standard of IS indicators to validate compliance, adding as a contribution the results of implementation in a specific environment. The proposed model was validated in a pharmaceutical SME in Lima, Peru. The results showed a 71% decrease in risk, after applying 15 monitoring and training controls, lowering the status from a critical level to an acceptable level between 1.5 and 2.3, according to the given assessment.

Translated title of the contributionInformation security risk management model for mitigating the impact on SMEs in Peru
Original languageSpanish
Title of host publicationProceedings of CISTI 2020 - 15th Iberian Conference on Information Systems and Technologies
EditorsAlvaro Rocha, Bernabe Escobar Perez, Francisco Garcia Penalvo, Maria del Mar Miras, Ramiro Goncalves
PublisherIEEE Computer Society
ISBN (Electronic)9789895465903
DOIs
StatePublished - Jun 2020
Event15th Iberian Conference on Information Systems and Technologies, CISTI 2020 - Seville, Spain
Duration: 24 Jun 202027 Jun 2020

Publication series

NameIberian Conference on Information Systems and Technologies, CISTI
Volume2020-June
ISSN (Print)2166-0727
ISSN (Electronic)2166-0735

Conference

Conference15th Iberian Conference on Information Systems and Technologies, CISTI 2020
Country/TerritorySpain
CitySeville
Period24/06/2027/06/20

Fingerprint

Dive into the research topics of 'Information security risk management model for mitigating the impact on SMEs in Peru'. Together they form a unique fingerprint.

Cite this