首页> 外文会议>Iberian Conference on Information Systems and Technologies >Information security risk management model for mitigating the impact on SMEs in Peru
【24h】

Information security risk management model for mitigating the impact on SMEs in Peru

机译:减轻秘鲁对中小企业影响的信息安全风险管理模型

获取原文

摘要

This paper proposes an information security risk management model that allows mitigating the threats to which SMEs in Peru are exposed. According to studies by Ernst & Young, 90% of companies in Peru are not prepared to detect security breaches, and 51% have already been attacked. In addition, according to Deloitte, only 10% of companies maintain risk management indicators. The model consists of 3 phases: 1. Inventory the information assets of the company, to conduct the risk analysis of each one; 2. Evaluate treatment that should be given to each risk, 3. Once the controls are implemented, design indicators to help monitor the implemented safeguards. The article focuses on the creation of a model that integrates a standard of risk management across the company with a standard of IS indicators to validate compliance, adding as a contribution the results of implementation in a specific environment. The proposed model was validated in a pharmaceutical SME in Lima, Peru. The results showed a 71% decrease in risk, after applying 15 monitoring and training controls, lowering the status from a critical level to an acceptable level between 1.5 and 2.3, according to the given assessment.
机译:本文提出了一种信息安全风险管理模型,该模型可以减轻秘鲁中小型企业所面临的威胁。根据安永会计师事务所的研究,秘鲁90%的公司不准备发现安全漏洞,而51%的公司已经受到攻击。此外,根据德勤,只有10%的公司维护风险管理指标。该模型包括三个阶段:1.盘点公司的信息资产,以对每个资产进行风险分析; 2.评估应对每种风险应采取的措施,3.实施控制措施后,设计指标以帮助监控已实施的保障措施。本文着重于创建一个模型,该模型将整个公司的风险管理标准与IS指标标准集成在一起,以验证合规性,并在特定环境中添加实施结果作为贡献。该模型在秘鲁利马的一家制药中小企业中得到了验证。根据给定的评估,结果表明,在应用15个监控和培训控制措施后,风险状态降低了71%,状态从临界水平降低到1.5至2.3之间的可接受水平。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号