TY - GEN
T1 - An Information Security Management System Model Based on ISO/IEC 27001:2022 for Mitigating Cyberattacks in Peruvian Fashion-Sector SMEs
AU - Aviles, Marcos Chenssen Carlos
AU - Aquino, Gianella Rosa Garcia
AU - Durango, Daniel Wilfredo Burga
AU - Sáenz, Carlos Alberto Tello
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.
PY - 2026
Y1 - 2026
N2 - The rise in cyberattacks targeting small and medium-sized enterprises (SMEs) highlights the urgent need for information security management models that are both effective and accessible. This study proposes an Information Security Management System (ISMS) model that harmonizes the ISO/IEC 27001:2022 standard with the NIST Cybersecurity Framework v1.1, specifically adapted to the context of SMEs in Peru’s fashion sector. A case study was conducted at Big Panda Clothing, applying key phases such as the assessment of the current security posture, asset identification and classification, risk analysis, development of security policies, and the implementation of continuous cybersecurity training. The validation of the proposed model projected an increase in the organization’s information security maturity level from 1.58 to 2.57, indicating meaningful improvements in cyber resilience and the protection of critical assets. The results suggest that the ISMS model provides a practical and replicable approach for SMEs, offering a sustainable strategy to address cybersecurity challenges in increasingly vulnerable digital environments.
AB - The rise in cyberattacks targeting small and medium-sized enterprises (SMEs) highlights the urgent need for information security management models that are both effective and accessible. This study proposes an Information Security Management System (ISMS) model that harmonizes the ISO/IEC 27001:2022 standard with the NIST Cybersecurity Framework v1.1, specifically adapted to the context of SMEs in Peru’s fashion sector. A case study was conducted at Big Panda Clothing, applying key phases such as the assessment of the current security posture, asset identification and classification, risk analysis, development of security policies, and the implementation of continuous cybersecurity training. The validation of the proposed model projected an increase in the organization’s information security maturity level from 1.58 to 2.57, indicating meaningful improvements in cyber resilience and the protection of critical assets. The results suggest that the ISMS model provides a practical and replicable approach for SMEs, offering a sustainable strategy to address cybersecurity challenges in increasingly vulnerable digital environments.
KW - Cyber Resilience
KW - ISO/IEC 27001:2022
KW - Information Security Management System
KW - NIST Cybersecurity Framework
KW - Risk Assessment
UR - https://www.scopus.com/pages/publications/105039604331
U2 - 10.1007/978-3-032-16764-4_14
DO - 10.1007/978-3-032-16764-4_14
M3 - Contribución a la conferencia
AN - SCOPUS:105039604331
SN - 9783032167637
T3 - Communications in Computer and Information Science
SP - 189
EP - 199
BT - Advanced Research in Technologies, Information, Innovation and Sustainability - 5th International Conference, ARTIIS 2025, Revised Selected Papers
A2 - Guarda, Teresa
A2 - Portela, Filipe
A2 - Augusto, Maria Fernanda
A2 - Coronado-Hernández, Jairo R.
PB - Springer Science and Business Media Deutschland GmbH
T2 - 5th International Conference on Advanced Research in Technologies, Information, Innovation and Sustainability 2025, ARTIIS 2025
Y2 - 21 October 2025 through 23 October 2025
ER -