Implementación del sistema de gestión de eventos y seguridad de la información (SIEM) haciendo uso de la herramienta Wazuh para la empresa Delta a Salud S.A.S BIC
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Altmetric
Resumen
Delta A Salud SAS BIC, a leading company in comprehensive medical auditing and oversight services in the social health security sector, faces significant challenges in managing its technological infrastructure. Despite its commitment to ethics, quality, and service, and having ISO 27001 certification, current security analysis and event correlation procedures are performed manually. This situation limits the company's ability to obtain a broad and real-time view of the state of its technological infrastructure, due to both budget constraints and the limited time available for the technology staff. As Delta A Salud SAS BIC grows and expands its operations, the amount of sensitive and critical data it handles also increases, making it more vulnerable to potential cyber threats and malicious attacks. Manual security protocols increase the risk of cyberattacks, vulnerability, and response times to security incidents, while also hindering the correlation of events for the detection and identification of attack patterns. To address these challenges, the implementation of the SCRUM methodology is proposed for the development of the internship, structured into five phases: project planning, integration of the SIEM Wazuh with authorized infrastructure, optimal configuration of the SIEM, effectiveness testing of the SIEM, and documentation and training of personnel. The goal is to implement and configure a hybrid infrastructure with a central Wazuh server and agents installed on the company's devices, protecting this infrastructure through specific security measures. The execution of this project allows Delta A Salud SAS BIC to improve threat and vulnerability detection, optimize the response to security incidents, and train its personnel in the proper use of the SIEM system. This seeks to reduce cyber risks and strengthen information security within the company.
