Propuesta de un sistema de gestión de la seguridad de la información para entidades dedicadas al servicio de Outsourcing de TI
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
The present degree paper is a proposal of an Information Management Security System (ISMS) for entities dedicated to the IT outsourcing service, based on the ISO27001 standard and using the Magerit methodology as a guide. The document is structured as follows:
Definition, Planning and Organization: This chapter defines project planning. It is made an approach of the problem where it specifies the disadvantages that a company dedicated to providing services of Outsourcing of IT may have for lack of an information management system (ISMS), in addition they define a series of objectives that allow to show the fulfillment of the development of the solution to the above-mentioned problem.
Current Situation Analysis: This chapter conducts a case study of the current situation that an organization that is dedicated to providing IT Outsourcing services can have.
Risk Analysis and Management: This chapter identifies and assesses the integrity, availability and confidentiality of the most important assets, both tangible and intangible to the organization; In the same way an identification and valuation of the possible threats to which each of these assets are exposed, making possible to determine and carry out a risk analysis in a detailed way in order to be able to give an adequate treatment to those risks.
Security Plan: This chapter defines the ISMS and information security objectives where a series of information security policies are proposed, which are standards that allow communication with all employees and third parties related to the organization To give guidelines of good practices for the management of the information that is handled.
Controls and/or Safeguards: This chapter proposes a series of controls detailing its objective which can be implemented as procedures or mechanisms that allow the significant risk reduction to which the assets of these organizations are exposed.
