• English
    • español
  • English 
    • English
    • español
  • Login
View Item 
  •   Home
  • Artículos científicos
  • Pregrado
  • Seccion en procesamiento
  • View Item
  •   Home
  • Artículos científicos
  • Pregrado
  • Seccion en procesamiento
  • View Item
JavaScript is disabled for your browser. Some features of this site may not work without it.

Browse

All of UPCCommunitiesTitleAuthorsAdvisorIssue DateSubmit DateSubjectsThis CollectionTitleAuthorsAdvisorIssue DateSubmit DateSubjectsProfilesView

My Account

LoginRegister

Quick Guides

AcercaPolíticasPlantillas de tesis y trabajos de investigaciónFormato de publicación de tesis y trabajos de investigaciónFormato de publicación de otros documentosLista de verificación

Statistics

Display statistics

Mitigating Information Leakage in Tech-Sector SMEs: Implementing ISO 27001:2022 for Comprehensive Security

  • CSV
  • RefMan
  • EndNote
  • BibTex
  • RefWorks
Average rating
 
   votes
Cast your vote
You can rate an item by clicking the amount of stars they wish to award to this item. When enough users have cast their vote on this item, the average rating will also be shown.
Star rating
 
Your vote was cast
Thank you for your feedback
Authors
Quispe, Gabriel O.
Zuloaga, Cesar K.
Castañeda, Pedro S.
Issue Date
2026-01-01
Keywords
Data Leakage
Information Security
Information Security Management System (ISMS)
ISO 27001:2022
NIST SP 800-53
SMEs

Metadata
Show full item record
Publisher
Springer Science and Business Media Deutschland GmbH
Journal
Communications in Computer and Information Science
URI
http://hdl.handle.net/10757/689048
DOI
https://doi.org/10.1007/978-3-031-99353-4_24
Abstract
This paper presents a model for implementing an Information Security Management System (ISMS) based on ISO 27001:2022 tailored to the needs of small and medium-sized enterprises (SMEs) in the technology sector in Lima Metropolitana. The model focuses on mitigating data leakage, a critical issue exacerbated by the increasing digitization of business operations. The proposed framework integrates controls from ISO 27001 aligned with NIST SP 800-53 to enhance information security practices. Results from applying the model to two technology SMEs indicate that one company (Company A) achieved a 94.44% Critical Control Implementation Index (IICC), a 70% Critical Vulnerability Resolution Rate (TRVC), and an 85% Policy Compliance Rate (TCPS), while the second company (Company B) achieved significantly lower rates of 50%, 40%, and 60%, respectively. These findings highlight both strengths in technological controls and weaknesses in organizational security management. This research contributes to the field by providing a practical, scalable approach for SMEs to enhance their information security posture, addressing both human and technological factors.
Type
http://purl.org/coar/resource_type/c_6501
Rights
http://purl.org/coar/access_right/c_16ec
Language
eng
ISSN
1865-0929
EISSN
1865-0937
ae974a485f413a2113503eed53cd6c53
https://doi.org/10.1007/978-3-031-99353-4_24
Scopus Count
Collections
Seccion en procesamiento

entitlement

 

DSpace software (copyright © 2002 - 2026)  DuraSpace
Quick Guide | Contact Us
Alicia
La Referencia
Open Repository is a service operated by 
Atmire NV
 

Export search results

The export option will allow you to export the current search results of the entered query to a file. Different formats are available for download. To export the items, click on the button corresponding with the preferred download format.

By default, clicking on the export buttons will result in a download of the allowed maximum amount of items.

To select a subset of the search results, click "Selective Export" button and make a selection of the items you want to export. The amount of items that can be exported at once is similarly restricted as the full export.

After making a selection, click one of the export format buttons. The amount of items that will be exported is indicated in the bubble next to export format.