Propuesta para implementar un sistema de gestión de la seguridad de la información, con trazabilidad de incidentes en jira y análisis de riesgos mediante la herramienta pilar basic para la empresa Pcvsoft Colombia S.A.S
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
The problem that the company PCVSoft Colombia SAS currently has is defined as it does not have an ISMS that provides support for all the appropriate control measures for the confidentiality, integrity and availability of the information to protect it from the parties involved inside and outside of the organization. In addition, it is clear that this ISMS aims to establish and maintain a reasonable and secure environment in accordance with its mission to protect its information assets, use resources correctly and carry out risk management of the information managed and ensure the continuity of the technical services provided in the organization.
The information that is handled in a company or entity is very valuable and this requires that it be protected from eventual threats that may occur in the entity. This degree project is established in the development of an operation framework, which is carried out using the MAGERIT methodology, being a risk analysis methodology developed by the Higher Council of Electronic Administration of Spain, which offers a systematic method to analyze the risks derived from the use of information and communication technologies in order to implement the most appropriate control measures that allow mitigating the risks, additionally keeping a control simultaneously in Jira, an online tool for managing tasks of a project, the monitoring of errors and incidents and for the operational management of projects. Jira can be used for managing and improving processes, thanks to its functions for organizing workflows. In addition to recording the risks on the PILAR BASIC software as a tool to perform a risk analysis on the various security dimensions (confidentiality, integrity, availability,) or an analysis of continuity of operations, focused on the availability of the system, seeking reduce outage times when disasters strike.
Regarding the domain controls in the ISO 27001 standard, within the implementation of the MAGERIT methodology for the development of the work, the analysis and relationship of the current state of the company PCVSoft Colombia SAS was carried out, where the shortcomings in terms of the level of information security that is currently evident in the company. There is a contrast of three groups of applications according to their criticality in the business objective, taking precisely the Missionary or Critical schemes, the least critical and lastly the non-critical ones, similarly generating a quantitative valuation of the assets on their collision as measured by Availability, Data integrity, Information confidentiality, Authenticity, Traceability. Together, an information survey was generated on the priority physical assets for business continuity and their applications.
However, we proceed to the conception of the different security policies that it is recommended to implement contemplated in the GAP study for the advancement of the ISMS plan proposed at the detailed level of the authors of the thesis towards the highest organizational hierarchical level of the company PCVSoft Colombia SAS
