Modelo de un Sistema de Gestión de la Seguridad de la Información Aplicada a una Empresa de Software
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
This work is the implementation of the system of security management of information (ISMS), based on the standard ISO27001. By documenting, is intended to demonstrate how each of the tangible and intangible assets that owns the case study, is exposed to errors and threats, both internal and external, and how implementation of the ISMS will help to reduce significantly the risks to which they are exposed. For the implementation of the standard, the main activity of the company, which is the development of custom software has been identified. Therefore, found that the domain to follow is the 12: acquisition, maintenance, and development of custom software. After the detailed of the assets involved in the case study, has compiled the rating assigned to them, has tabbed them is, and with these results, has been established the respective analysis of risk. After this is set, according to best practices, controls to follow, whose objective is to minimize significant risks, so that the information remains confidential, integrated and accessible to persons designated by the company.