SciELO - Scientific Electronic Library Online

 
vol.12 issue2Speed profile prediction model of rural roads in flat terrain in Costa RicaEfficiency in the removal of organic matter by wormfilters (Eisenia foetida) in domestic wastewater for rural areas author indexsubject indexarticles search
Home Pagealphabetic serial listing  

Services on Demand

Journal

Article

Indicators

Related links

  • Have no similar articlesSimilars in SciELO

Share


Enfoque UTE

On-line version ISSN 1390-6542Print version ISSN 1390-9363

Abstract

BUSTAMANTE GARCIA, Shonerly; VALLES CORAL, Miguel Ángel; CUELLAR RODRIGUEZ, Immer Elías  and  LEVANO RODRIGUEZ, Danny. Policies based on ISO 27001: 2013 and its influence on information security management in municipalities of Peru. Enfoque UTE [online]. 2021, vol.12, n.2, pp.69-79. ISSN 1390-6542.  https://doi.org/10.29019/enfoqueute.743.

Information security management within an organization must be a well-defined process, as it involves a huge effort from users, area managers and other servers to know how to respond to suspicious events and how to manage identified vulnerabilities. The objective of this research was to improve information security management in a Peruvian district municipality, through the implementation of a policy model under ISO 27001: 2013. For this, a preexperimental investigation was carried out with a sample of 30 workers, to whom a questionnaire was applied to measure the degree of satisfaction with the implanted model. On average, more than 90 % of those surveyed recognized improvements in the municipality, marking a great difference between the pre and postest, from 49 % to 96 %. It is concluded that the security policy model, based on three fundamental pillars: confidentiality, integrity, and availability, improved information security management, guaranteeing adequate data protection.

Keywords : information; management; organization; policies; security.

        · abstract in Spanish     · text in Spanish     · Spanish ( pdf )