Maturity Model for Information Access Management of Peruvian IT Service Providers based on ISO/IEC 27001 and CMMI Security Controls

Descripción del Articulo

In the current context of increasing cyber threats to Latin American IT service providers, the cost of data breaches is expected to increase 31% by 2023, which highlights the urgency of strengthening security practices. Therefore, it is proposed to improve maturity in access management, with the dev...

Descripción completa

Detalles Bibliográficos
Autores: Huaman, Sergio, Ponce, Luis, Wong, Lenis
Formato: artículo
Fecha de Publicación:2024
Institución:Universidad Peruana de Ciencias Aplicadas
Repositorio:UPC-Institucional
Lenguaje:inglés
OAI Identifier:oai:repositorioacademico.upc.edu.pe:10757/676108
Enlace del recurso:http://hdl.handle.net/10757/676108
Nivel de acceso:acceso embargado
Materia:Information Access Managemen
ISO/IEC 27001
Descripción
Sumario:In the current context of increasing cyber threats to Latin American IT service providers, the cost of data breaches is expected to increase 31% by 2023, which highlights the urgency of strengthening security practices. Therefore, it is proposed to improve maturity in access management, with the development of a model based on ISO/IEC 27001:2022 designed for Peruvian IT service providers. The study consists of three stages: analysis, design, and validation. In the first stage, a comparative analysis is made between success factors, cybersecurity aspects, maturity models and access management mechanisms. The second and third stages cover the model building phases according to De Bruin's methodology. In the second stage, the evaluation scope, and the level structure according to CMMI are defined as well as the criteria of the model where the evaluation is based on a user life cycle, type of access and regulatory compliance. Finally, in the third stage, the model is validated by experts in the field and deployed in an enterprise in the sector. The results obtained from the validation showed that 'understandability', 'usefulness and practicality', 'accuracy', 'comprehensiveness', 'sufficiency', 'relevance', 'usability' and 'accuracy' obtained an average rating of 4.6 (agree). Finally, with respect to the implementation of the proposed model, the elimination phase had a maturity index of 0.14, which placed it at an initial maturity level. On the other hand, the other phases exceeded an index of 0.55, placing them in the three highest levels of maturity achievable. In this way, an improvement proposal for the enterprise was made and accepted.
Nota importante:
La información contenida en este registro es de entera responsabilidad de la institución que gestiona el repositorio institucional donde esta contenido este documento o set de datos. El CONCYTEC no se hace responsable por los contenidos (publicaciones y/o datos) accesibles a través del Repositorio Nacional Digital de Ciencia, Tecnología e Innovación de Acceso Abierto (ALICIA).