Definición del sistema de gestión de seguridad de la información de INSITEL S.A. alineado con la normativa de la familia ISO 27000.
Fecha
Autores
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
Practical methodology used for the implementation of the information security management system of INSITEL S.A. according to ISO/IEC 27000 standards. The planning of the system is carried out together with the information security committee; which involves understanding the context of the organization, defining the scope and its exclusions, drafting the general policy of information security according to the needs of the company. Then, the identification of the information assets is carried out; in this way, the criticality of each one of the assets with respect to the three fundamental pillars of the information; availability, integrity and confidentiality can be determined. Finally, the risks associated with these assets are recognized and evaluated with respect to parameters such as the probability of the risk occurring and the impact it may have on the development of the organization's activities, in order to mitigate, transfer, eliminate or accept these risks according to the criteria established by the organization.
