Cybersecurity framework for SMEs in Peru based on ISO/IEC 27001 and CSF NIST controls
Average rating
Cast your vote
You can rate an item by clicking the amount of stars they wish to award to this item.
When enough users have cast their vote on this item, the average rating will also be shown.
Star rating
Your vote was cast
Thank you for your feedback
Thank you for your feedback
Issue Date
2023-01-01
Metadata
Show full item recordPublisher
IEEE Computer SocietyJournal
Iberian Conference on Information Systems and Technologies, CISTIDOI
10.23919/CISTI58278.2023.10211874Abstract
Due to the global pandemic that was experienced in 2020, the Small and Medium Enterprises (SMEs) sector in Peru chose to store all their information in cloud services. However, a 2021 Kaspersky study indicates that SMBs have few resources to implement security solutions to protect their information. For this reason, this article proposes a cybersecurity framework composed of controls from ISO/IEC 27001 and the Cybersecurity Framework (CSF) of the National Institute of Standards and Technology (NIST) to mitigate cyber-threats against SMEs in Peru. The framework consists of 7 steps having as reference the Deming cycle (PDCA). For the implementation of the composite framework, we worked with 12 domains and 40 controls for a Peruvian SME in the technology sector. The results showed an increase in cybersecurity of 40 %, after applying the 40 controls, improving its level of maturity from the 'insufficient' state to a 'mature' state, according to the assessment given.Type
info:eu-repo/semantics/articleRights
info:eu-repo/semantics/embargoedAccessLanguage
engISSN
21660727EISSN
21660735ae974a485f413a2113503eed53cd6c53
10.23919/CISTI58278.2023.10211874
Scopus Count
Collections