Modelo de gestión de riesgos de seguridad de información para mitigar el impacto en las PYMEs en Perú

Daniel Felipe Carnero Garay, Carbajal Ramos Marcos Antonio, Jimmy Armas-Aguirre, Juan Manuel Madrid Molina

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

2 Citas (Scopus)

Resumen

This paper proposes an information security risk management model that allows mitigating the threats to which SMEs in Peru are exposed. According to studies by Ernst Young, 90% of companies in Peru are not prepared to detect security breaches, and 51% have already been attacked. In addition, according to Deloitte, only 10% of companies maintain risk management indicators. The model consists of 3 phases: 1. Inventory the information assets of the company, to conduct the risk analysis of each one; 2. Evaluate treatment that should be given to each risk, 3. Once the controls are implemented, design indicators to help monitor the implemented safeguards. The article focuses on the creation of a model that integrates a standard of risk management across the company with a standard of IS indicators to validate compliance, adding as a contribution the results of implementation in a specific environment. The proposed model was validated in a pharmaceutical SME in Lima, Peru. The results showed a 71% decrease in risk, after applying 15 monitoring and training controls, lowering the status from a critical level to an acceptable level between 1.5 and 2.3, according to the given assessment.

Título traducido de la contribuciónInformation security risk management model for mitigating the impact on SMEs in Peru
Idioma originalEspañol
Título de la publicación alojadaProceedings of CISTI 2020 - 15th Iberian Conference on Information Systems and Technologies
EditoresAlvaro Rocha, Bernabe Escobar Perez, Francisco Garcia Penalvo, Maria del Mar Miras, Ramiro Goncalves
EditorialIEEE Computer Society
ISBN (versión digital)9789895465903
DOI
EstadoPublicada - jun. 2020
Evento15th Iberian Conference on Information Systems and Technologies, CISTI 2020 - Seville, Espana
Duración: 24 jun. 202027 jun. 2020

Serie de la publicación

NombreIberian Conference on Information Systems and Technologies, CISTI
Volumen2020-June
ISSN (versión impresa)2166-0727
ISSN (versión digital)2166-0735

Conferencia

Conferencia15th Iberian Conference on Information Systems and Technologies, CISTI 2020
País/TerritorioEspana
CiudadSeville
Período24/06/2027/06/20

Palabras clave

  • information security
  • ISO/IEC 27004
  • ISO/IEC 31000
  • IT Risk
  • Magerit

Huella

Profundice en los temas de investigación de 'Modelo de gestión de riesgos de seguridad de información para mitigar el impacto en las PYMEs en Perú'. En conjunto forman una huella única.

Citar esto