Dissertação
Política de segurança da informação: uma estratégia para garantir a proteção e a integridade das informações arquivísticas no Departamento de Arquivo Geral da UFSM
Fecha
2012-12-06Registro en:
SFREDDO, Josiane Ayres. INFORMATION SECURITY POLICY: A STRATEGY TO ENSURE
THE SECURITY AND INTEGRITY OF THE DEPARTMENT OF
ARCHIVAL INFORMATION IN THE GENERAL ARCHIVING
DEPARTMENT OF THE UFSM. 2012. 206 f. Dissertação (Mestrado em História) - Universidade Federal de Santa Maria, Santa Maria, 2012.
Autor
Sfreddo, Josiane Ayres
Institución
Resumen
Presents a study on information security in order to propose an Information Security
Policy for the Department of General Archives (DAG), Federal University of Santa Maria
(UFSM) as a way of enabling the protection, availability and secure access to archival
information (not digital), in the university context. It is characterized as an exploratory
qualitative approach, assuming a case study form, because it involves the study of a certain
subject allowing its wide and detailed knowledge. It was first conducted a more detailed study
of the Standard ISO/IEC 27002 which is a code of practice for information security, providing
guidelines for the implementation of an Information Security Policy, based on regulations
according to the institutional purposes. The study aimed, at first, to adapt the requirements
and controls present in this standard archival context, focusing on the protection of not digital
information, a research in the Heritage Documentary line. Thus, the adaptation of the standard
for archival followed the structure of the original standard, seeking to provide for the archival
institutions a tool to subsidize the development of an Information Security Policy, providing a
more secure and reliable protection. In order to compose this policy a data collection was
carried out through interviews, structured within questions about security information, based
on the standard ISO/IEC 27002, on the previous study and the Adaptation of the Standard for
the archival context. With the data collected and analyzed, along with the DAG, it can be
verified that the problems causer of threats to the security of not digital archives in the
department are directly related to the lack of security to the perimeter and to the absence of a
physical control, including entries and exits. These security actions made it possible, together
with the adaption of the standard, to propose control in order to prevent further incidents. This
way it was possible to structure the Document of the Security Policy representing the
materialization of the Security Policy according to the needs presented by DAG. This
document will serve as an instrument to support and guide employees, users and third parties
in the conduct of institutional activities. However, it is up to the department to approve it and
implement it for the purpose of preventing incidents, thereby providing safe reliable and
continuous access to not digital information by him guarded.