Policies based on ISO 27001: 2013 and its influence on information security management in municipalities of Peru

被引:0
|
作者
Bustamante Garcia, Shonerly [1 ]
Valles Coral, Miguel Angel [2 ]
Cuellar Rodriguez, Immer Elias [2 ]
Levano Rodriguez, Danny [2 ]
机构
[1] UPeU Univ Peruana Union, Tarapoto, Peru
[2] UPeU, Tarapoto, Peru
来源
ENFOQUE UTE | 2021年 / 12卷 / 02期
关键词
Information; management; organization; policies; security;
D O I
10.29019/enfoqueute.743
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information security management within an organization must be a well-defined process, as it involves a huge effort from users, area managers and other servers to know how to respond to suspicious events and how to manage identified vulnerabilities. The objective of this research was to improve information security management in a Peruvian district municipality, through the implementation of a policy model under ISO 27001: 2013. For this, a preexperimental investigation was carried out with a sample of 30 workers, to whom a questionnaire was applied to measure the degree of satisfaction with the implanted model. On average, more than 90 % of those surveyed recognized improvements in the municipality, marking a great difference between the pre and postest, from 49 % to 96 %. It is concluded that the security policy model, based on three fundamental pillars: confidentiality, integrity, and availability, improved information security management, guaranteeing adequate data protection.
引用
收藏
页码:69 / 79
页数:11
相关论文
共 50 条
  • [1] NEW STANDARD ISO/IEC 27001:2013 OF INFORMATION SECURITY MANAGEMENT SYSTEM
    Drastich, Martin
    [J]. KNOWLEDGE FOR MARKET USE 2014: MEDIA AND COMMUNICATION IN THE 21ST CENTURY, 2014, : 387 - 393
  • [2] Application of ISO 27001 and its influence on the information security of a Peruvian private company
    Rodriguez Baca, Liset Sulay
    Cruzado Puente de la Vega, Carlos Francisco
    Corredor, Carolina Mejia
    Alarcon Diaz, Mitchell Alberto
    [J]. PROPOSITOS Y REPRESENTACIONES, 2020, 8 (03):
  • [3] Information Security Risk Management: Handbook for ISO/IEC 27001
    Lomas, Elizabeth
    [J]. RECORDS MANAGEMENT JOURNAL, 2011, 21 (03) : 239 - +
  • [4] Information Security Management Systems - A Maturity Model Based on ISO/IEC 27001
    Proenca, Diogo
    Borbinha, Jose
    [J]. BUSINESS INFORMATION SYSTEMS (BIS 2018), 2018, 320 : 102 - 114
  • [5] AUTOMATION OF AN INFORMATION SECURITY MANAGEMENT SYSTEM BASED ON THE ISO/IEC 27001 STANDARD
    de la Rosa Martin, Tonyse
    [J]. REVISTA UNIVERSIDAD Y SOCIEDAD, 2021, 13 (05): : 495 - 506
  • [6] COMPARATIVE STUDY REGARDING INTERNATIONAL STANDARDS ON INFORMATION SECURITY MANAGEMENT SYSTEMS IN ORGANIZATIONS: ISO/IEC 27001:2013 vs ISO/IEC 27001:2005
    Tiganoaia, Bogdan
    [J]. GLOBALIZATION AND INTERCULTURAL DIALOGUE: MULTIDISCIPLINARY PERSPECTIVES - ECONOMY AND MANAGEMENT, 2014, : 102 - 109
  • [7] Goal- Based Establishment of an Information Security Management System Compliant to ISO 27001
    Beckers, Kristian
    [J]. SOFSEM 2014: THEORY AND PRACTICE OF COMPUTER SCIENCE, 2014, 8327 : 102 - 113
  • [8] Using ISO 27001 in Teaching Information Security
    Abu Talib, Manar
    Khelifi, Adel
    Ugurlu, Tahsin
    [J]. 38TH ANNUAL CONFERENCE ON IEEE INDUSTRIAL ELECTRONICS SOCIETY (IECON 2012), 2012, : 3149 - 3153
  • [9] Analysis of factors that inhibiting implementation of Information Security Management System (ISMS) based on ISO 27001
    Tatiara, R.
    Fajar, A. N.
    Siregar, B.
    Gunawan, W.
    [J]. 2ND INTERNATIONAL CONFERENCE ON COMPUTING AND APPLIED INFORMATICS 2017, 2018, 978
  • [10] A Model of an Information Security Management System Based on NTC-ISO/IEC 27001 Standard
    Fonseca-Herrera, Omar A.
    Rojas, Alix E.
    Florez, Hector
    [J]. IAENG International Journal of Computer Science, 2021, 48 (02) : 1 - 10