Perú
| info:eu-repo/semantics/article
Information security risk management model for mitigating the impact on SMEs in Peru
dc.creator | Garay, Daniel Felipe Carnero | |
dc.creator | Marcos Antonio, Carbajal Ramos | |
dc.creator | Armas-Aguirre, Jimmy | |
dc.creator | Molina, Juan Manuel Madrid | |
dc.date.accessioned | 2021-06-23T13:53:56Z | |
dc.date.accessioned | 2024-05-07T02:13:28Z | |
dc.date.available | 2021-06-23T13:53:56Z | |
dc.date.available | 2024-05-07T02:13:28Z | |
dc.date.created | 2021-06-23T13:53:56Z | |
dc.date.issued | 2020-06-01 | |
dc.identifier | 21660727 | |
dc.identifier | 10.23919/CISTI49556.2020.9140980 | |
dc.identifier | http://hdl.handle.net/10757/656577 | |
dc.identifier | 21660735 | |
dc.identifier | Iberian Conference on Information Systems and Technologies, CISTI | |
dc.identifier | 2-s2.0-85089023750 | |
dc.identifier | SCOPUS_ID:85089023750 | |
dc.identifier | 0000 0001 2196 144X | |
dc.identifier.uri | https://repositorioslatinoamericanos.uchile.cl/handle/2250/9325595 | |
dc.description.abstract | This paper proposes an information security risk management model that allows mitigating the threats to which SMEs in Peru are exposed. According to studies by Ernst Young, 90% of companies in Peru are not prepared to detect security breaches, and 51% have already been attacked. In addition, according to Deloitte, only 10% of companies maintain risk management indicators. The model consists of 3 phases: 1. Inventory the information assets of the company, to conduct the risk analysis of each one; 2. Evaluate treatment that should be given to each risk, 3. Once the controls are implemented, design indicators to help monitor the implemented safeguards. The article focuses on the creation of a model that integrates a standard of risk management across the company with a standard of IS indicators to validate compliance, adding as a contribution the results of implementation in a specific environment. The proposed model was validated in a pharmaceutical SME in Lima, Peru. The results showed a 71% decrease in risk, after applying 15 monitoring and training controls, lowering the status from a critical level to an acceptable level between 1.5 and 2.3, according to the given assessment. | |
dc.language | eng | |
dc.publisher | IEEE Computer Society | |
dc.relation | https://ieeexplore.ieee.org/document/9140980 | |
dc.rights | info:eu-repo/semantics/embargoedAccess | |
dc.source | Repositorio Academico - UPC | |
dc.source | Universidad Peruana de Ciencias Aplicadas (UPC) | |
dc.source | Iberian Conference on Information Systems and Technologies, CISTI | |
dc.source | 2020-June | |
dc.subject | information security | |
dc.subject | ISO/IEC 27004 | |
dc.subject | ISO/IEC 31000 | |
dc.subject | IT Risk | |
dc.subject | Magerit | |
dc.title | Information security risk management model for mitigating the impact on SMEs in Peru | |
dc.type | info:eu-repo/semantics/article |