Desarrollo de modelo de gestión de riesgos para la implementación de controles de seguridad permietral en medianas y pequeñas empresas del sector de T.I.
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
Small and medium-sized enterprises (SMEs) in the information technology (IT) sector face growing cybersecurity challenges due to the evolution of threats and the lack of structured strategies for risk management. This paper proposes a risk management model based on the ISO 27001 standard, aimed at strengthening perimeter security and mitigating vulnerabilities in these organizations. The model is developed using the Deming Cycle (PDCA: Plan, Do, Check, Act), allowing for efficient and continuous risk management. In the planning phase (Plan), critical assets, threats, and vulnerabilities are identified. The implementation phase (Do) defines security controls aligned with ISO 27001. Subsequently, in the verification phase (Check), performance metrics are established, and in the improvement phase (Act), controls are optimized based on new threats. The applied methodology includes the analysis of regulations, the theoretical design of the model, and its evaluation in technical, operational, and economic terms. The results indicate that the adoption of a structured model enhances the SMEs' ability to prevent and respond to security incidents, ensuring compliance with international standards. In conclusion, the study highlights the importance of implementing risk management models in SMEs within the IT sector, promoting a cybersecurity culture.
