Could an ISMS Model (ISO/IEC 27001:2013 Standard) Implementation Really Protect Public Data?

被引:0
|
作者
Tintin, Romel [1 ]
Hidalgo, Monica [1 ]
机构
[1] Adv Inst Natl Studies IAEN, Publ Adm Sch, Quito, Ecuador
关键词
Public data security; ISO/IEC 27001:2013 Standard; Information Security; Information Security Management System; ISMS;
D O I
10.1109/ICEDEG58167.2023.10122109
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper aims to present the experience on the design and implementation of an Information Security Management System (ISMS) model given under the international standard ISO/IEC 27001:2013 for the security of public data. To do this, the model taken as a reference is the one implemented by the Property Registry of the Pedro Moncayo Canton (PRPMC), Pichincha Province, Ecuador which due to its operability in the management of public data, brought about the achievement of said ISO international seal on Information Security and therefore became a benchmark for good practices in Ecuador at a national level. A quantitative methodology was used to analyze the design of the ISMS adopted by the PRPMC, under the international standard ISO/IEC 27001:2013 with the integration of some national regulations issued by the different competent control bodies. When a model is implemented, it can be considered that it indisputably ensures public data at a good level and allows us to be prepared through a contingency plan in the face of any adversity that implies damage or loss of physical or digital information and therefore be able to continue operating. In the same way, through the Gray Box-type ethical hacking reports, the evolution of the security and vulnerabilities of public data allocated at servers and in the cloud is shown. In the Property Registry case, the object of this study, it can be determined that said institution has reached a high standard of security of public data that guarantees reliability and trust of the procedures and contracts registered by the owners of any type of property in the canton. As a conclusion then it is recommended to take the protection of personal information of citizens as an obligation of the Ecuadorian State. This can be done through the updating of regulations so that the entities that handle public data are forced to implement information security based on these international standards.
引用
收藏
页码:83 / 87
页数:5
相关论文
共 13 条
  • [1] Assessment of ISMS Based On Standard ISO/IEC 27001:2013 at DISKOMINFO Depok City
    Nurbojatmiko
    Susanto, Aries
    Shobariah, Euis
    [J]. 2016 4TH INTERNATIONAL CONFERENCE ON CYBER AND IT SERVICE MANAGEMENT, 2016, : 43 - 48
  • [2] Der Standard ISO/IEC 27001:2013
    Kai Jendrian
    [J]. Datenschutz und Datensicherheit - DuD, 2014, 38 (8) : 552 - 557
  • [3] POSSIBILITIES OF ISO 9001: 2015 QMS AND ISO/IEC 27001:2013 ISMS INTEGRATION
    Britvic, Josip
    Merkas, Zvonko
    Tenjeri, Tihomir
    [J]. INTERDISCIPLINARY MANAGEMENT RESEARCH XVII (IMR 2021), 2021, : 585 - 600
  • [4] ISO/IEC 27001 Implementation in Public Organizations: A Case Study
    Sussy, Bayona
    Wilber, Chauca
    Milagros, Lopez
    Carlos, Maldonado
    [J]. 2015 10TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2015,
  • [5] On the Track of ISO/IEC 27001:2013 Implementation Difficulties in Portuguese Organizations
    Longras, Ana
    Pereira, Teresa
    Carneiro, Pedro
    Pinto, Pedro
    [J]. 2018 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS (IS), 2018, : 886 - 890
  • [6] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [7] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10
  • [8] ISMS Planning Based On ISO/IEC 27001:2013 Using Analytical Hierarchy Process at Gap Analysis Phase (Case Study : XYZ Institute)
    Briliyant, Obrina Candra
    Candra, Johanes Widhi
    Tamba, Sion Rebeca
    [J]. 2017 11TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATION SYSTEMS SERVICES AND APPLICATIONS (TSSA), 2017,
  • [9] General Data Protection Regulation and ISO/IEC 27001:2013: Synergies of Activities Towards Organisations' Compliance
    Diamantopoulou, Vasiliki
    Tsohou, Aggeliki
    Karyda, Maria
    [J]. TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, TRUSTBUS 2019, 2019, 11711 : 94 - 109
  • [10] The ISO/IEC 27001 Information Security Management Standard: How to Extract Value from Data in the IT Sector
    Kitsios, Fotis
    Chatzidimitriou, Elpiniki
    Kamariotou, Maria
    [J]. SUSTAINABILITY, 2023, 15 (07)