Cybersecurity framework for SMEs in Peru based on ISO/IEC 27001 and CSF NIST controls

Descripción del Articulo

Due to the global pandemic that was experienced in 2020, the Small and Medium Enterprises (SMEs) sector in Peru chose to store all their information in cloud services. However, a 2021 Kaspersky study indicates that SMBs have few resources to implement security solutions to protect their information....

Descripción completa

Detalles Bibliográficos
Autores: Angelo Edu, Munoz Luyo, Alexis, Garibay Palomino, Lenis, Wong Portillo
Formato: artículo
Fecha de Publicación:2023
Institución:Universidad Peruana de Ciencias Aplicadas
Repositorio:UPC-Institucional
Lenguaje:inglés
OAI Identifier:oai:repositorioacademico.upc.edu.pe:10757/669501
Enlace del recurso:http://hdl.handle.net/10757/669501
Nivel de acceso:acceso embargado
Materia:CFS NIST
controls
cyber-attacks
Cybersecurity
Framework
ISO/IEC 27001
SMEs
Descripción
Sumario:Due to the global pandemic that was experienced in 2020, the Small and Medium Enterprises (SMEs) sector in Peru chose to store all their information in cloud services. However, a 2021 Kaspersky study indicates that SMBs have few resources to implement security solutions to protect their information. For this reason, this article proposes a cybersecurity framework composed of controls from ISO/IEC 27001 and the Cybersecurity Framework (CSF) of the National Institute of Standards and Technology (NIST) to mitigate cyber-threats against SMEs in Peru. The framework consists of 7 steps having as reference the Deming cycle (PDCA). For the implementation of the composite framework, we worked with 12 domains and 40 controls for a Peruvian SME in the technology sector. The results showed an increase in cybersecurity of 40 %, after applying the 40 controls, improving its level of maturity from the 'insufficient' state to a 'mature' state, according to the assessment given.
Nota importante:
La información contenida en este registro es de entera responsabilidad de la institución que gestiona el repositorio institucional donde esta contenido este documento o set de datos. El CONCYTEC no se hace responsable por los contenidos (publicaciones y/o datos) accesibles a través del Repositorio Nacional Digital de Ciencia, Tecnología e Innovación de Acceso Abierto (ALICIA).