Perú | info:eu-repo/semantics/article
dc.creatorGaray, Daniel Felipe Carnero
dc.creatorMarcos Antonio, Carbajal Ramos
dc.creatorArmas-Aguirre, Jimmy
dc.creatorMolina, Juan Manuel Madrid
dc.date.accessioned2021-06-23T13:53:56Z
dc.date.accessioned2024-05-07T02:13:28Z
dc.date.available2021-06-23T13:53:56Z
dc.date.available2024-05-07T02:13:28Z
dc.date.created2021-06-23T13:53:56Z
dc.date.issued2020-06-01
dc.identifier21660727
dc.identifier10.23919/CISTI49556.2020.9140980
dc.identifierhttp://hdl.handle.net/10757/656577
dc.identifier21660735
dc.identifierIberian Conference on Information Systems and Technologies, CISTI
dc.identifier2-s2.0-85089023750
dc.identifierSCOPUS_ID:85089023750
dc.identifier0000 0001 2196 144X
dc.identifier.urihttps://repositorioslatinoamericanos.uchile.cl/handle/2250/9325595
dc.description.abstractThis paper proposes an information security risk management model that allows mitigating the threats to which SMEs in Peru are exposed. According to studies by Ernst Young, 90% of companies in Peru are not prepared to detect security breaches, and 51% have already been attacked. In addition, according to Deloitte, only 10% of companies maintain risk management indicators. The model consists of 3 phases: 1. Inventory the information assets of the company, to conduct the risk analysis of each one; 2. Evaluate treatment that should be given to each risk, 3. Once the controls are implemented, design indicators to help monitor the implemented safeguards. The article focuses on the creation of a model that integrates a standard of risk management across the company with a standard of IS indicators to validate compliance, adding as a contribution the results of implementation in a specific environment. The proposed model was validated in a pharmaceutical SME in Lima, Peru. The results showed a 71% decrease in risk, after applying 15 monitoring and training controls, lowering the status from a critical level to an acceptable level between 1.5 and 2.3, according to the given assessment.
dc.languageeng
dc.publisherIEEE Computer Society
dc.relationhttps://ieeexplore.ieee.org/document/9140980
dc.rightsinfo:eu-repo/semantics/embargoedAccess
dc.sourceRepositorio Academico - UPC
dc.sourceUniversidad Peruana de Ciencias Aplicadas (UPC)
dc.sourceIberian Conference on Information Systems and Technologies, CISTI
dc.source2020-June
dc.subjectinformation security
dc.subjectISO/IEC 27004
dc.subjectISO/IEC 31000
dc.subjectIT Risk
dc.subjectMagerit
dc.titleInformation security risk management model for mitigating the impact on SMEs in Peru
dc.typeinfo:eu-repo/semantics/article


Este ítem pertenece a la siguiente institución