Diseño del sistema de gestión de seguridad de la información (SGSI) para la empresa VAICO ONLINE SAS basado en la norma ISO 27001:2013
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
In the development of the project, risk analysis and treatment activities are contemplated using the PDVA methodology (Plan - Do - Verify - Act) together with ISO 31000, in accordance with the needs and business objectives. Thus, these activities are initially focused on the prior contextual knowledge of the company, in which a structural recognition of the organization and its current status with respect to the standards presented in ISO 27001: 2013 and its Annex A is carried out, in order to do so. get to identify their main shortcomings and stakeholders in information security, carry out their inventory of assets and their valuation, as well as the analysis of threats and vulnerabilities, so that in this way the risks can be assessed and subsequently managed to provide a treatment of the same through the application of controls and policies. As a result of this, a series of findings and results documents are presented, whose main objective is to publicize a guide for the design of the information security management system (ISMS), which are available to all Company employees on a web page, which will not only allow you to consult the updated and previous versions of the same, but also to identify new incidents that may arise in the future.
