<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1390-6542</journal-id>
<journal-title><![CDATA[Enfoque UTE]]></journal-title>
<abbrev-journal-title><![CDATA[Enfoque UTE]]></abbrev-journal-title>
<issn>1390-6542</issn>
<publisher>
<publisher-name><![CDATA[Universidad UTE]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1390-65422018000100127</article-id>
<article-id pub-id-type="doi">10.29019/enfoqueute.v9n1.214</article-id>
<title-group>
<article-title xml:lang="en"><![CDATA[A Practical Model to Perform Comprehensive Cybersecurity Audits]]></article-title>
<article-title xml:lang="es"><![CDATA[Un modelo práctico para realizar auditorías exhaustivas de Ciberseguridad]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Sabillon]]></surname>
<given-names><![CDATA[Regner]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Universitat Oberta de Catalunya Internet Interdisciplinary Institute ]]></institution>
<addr-line><![CDATA[Calgary ]]></addr-line>
<country>Canada</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>03</month>
<year>2018</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>03</month>
<year>2018</year>
</pub-date>
<volume>9</volume>
<numero>1</numero>
<fpage>127</fpage>
<lpage>137</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://scielo.senescyt.gob.ec/scielo.php?script=sci_arttext&amp;pid=S1390-65422018000100127&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.senescyt.gob.ec/scielo.php?script=sci_abstract&amp;pid=S1390-65422018000100127&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.senescyt.gob.ec/scielo.php?script=sci_pdf&amp;pid=S1390-65422018000100127&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract: These days organizations are continually facing being targets of cyberattacks and cyberthreats; the sophistication and complexity of modern cyberattacks and the modus operandi of cybercriminals including Techniques, Tactics and Procedures (TTP) keep growing at unprecedented rates. Cybercriminals are always adopting new strategies to plan and launch cyberattacks based on existing cybersecurity vulnerabilities and exploiting end users by using social engineering techniques. Cybersecurity audits are extremely important to verify that information security controls are in place and to detect weaknesses of inexistent cybersecurity or obsolete controls. This article presents an innovative and comprehensive cybersecurity audit model. The CyberSecurity Audit Model (CSAM) can be implemented to perform internal or external cybersecurity audits. This model can be used to perform single cybersecurity audits or can be part of any corporate audit program to improve cybersecurity controls. Any information security or cybersecurity audit team has either the options to perform a full audit for all cybersecurity domains or by selecting specific domains to audit certain areas that need control verification and hardening. The CSAM has 18 domains; Domain 1 is specific for Nation States and Domains 2-18 can be implemented at any organization. The organization can be any small, medium or large enterprise, the model is also applicable to any Non-Profit Organization (NPO).]]></p></abstract>
<abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen: En la actualidad, las organizaciones se enfrentan continuamente a ser blanco de ciberataques y amenazas cibernéticas; la sofisticación y complejidad de los ciberataques modernos y el modus operandi de los ciberdelincuentes, incluidas las Técnicas, Tácticas y Procedimientos (TTP), continúan creciendo a un ritmo sin precedentes. Los ciberdelincuentes siempre están adoptando nuevas estrategias para planificar y lanzar ataques cibernéticos basados &#8203;&#8203;en las vulnerabilidades de ciberseguridad existentes y explotar a los usuarios finales mediante el uso de técnicas de ingeniería social. Este artículo presenta un modelo de auditoría de ciberseguridad innovador e integral. El Modelo de Auditoría de Ciberseguridad (CSAM) se puede implementar para realizar auditorías de ciberseguridad internas o externas. Este modelo se puede usar para efectuar auditorías únicas de ciberseguridad o puede ser parte de cualquier programa de auditoría corporativa para mejorar los controles de ciberseguridad. Cualquier equipo de auditoría de seguridad de la información o ciberseguridad tiene la opción de aplicar una auditoría completa para todos los dominios de ciberseguridad o seleccionando dominios específicos para auditar ciertas áreas que necesitan verificación y fortalecimiento del control. El CSAM tiene 18 dominios; el Dominio 1 es específico para Estados y los dominios 2-18 se pueden implementar en cualquier organización. La organización puede ser cualquier empresa pequeña, mediana o grande, el modelo también es aplicable a cualquier organización sin fines de lucro (OSFL).]]></p></abstract>
<kwd-group>
<kwd lng="es"><![CDATA[ciberseguridad]]></kwd>
<kwd lng="es"><![CDATA[auditoría de ciberseguridad]]></kwd>
<kwd lng="es"><![CDATA[modelo de auditoría de ciberseguridad]]></kwd>
<kwd lng="es"><![CDATA[aseguramiento de ciberseguridad]]></kwd>
<kwd lng="es"><![CDATA[controles de ciberseguridad.]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity audit]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity audit model]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity assurance]]></kwd>
<kwd lng="en"><![CDATA[cybersecurity controls.]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Bodeau]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Boyle]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Fabius-Greene]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Graubart R.]]></surname>
</name>
</person-group>
<source><![CDATA[Cyber Security Governance]]></source>
<year>2010</year>
<publisher-name><![CDATA[MITRE]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B2">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Boyce]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<source><![CDATA[Vulnerability Assessment: The Pro-Active Steps to Secure your Organization]]></source>
<year>2001</year>
<publisher-name><![CDATA[SANS Institute]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B3">
<nlm-citation citation-type="book">
<collab>CERT Division</collab>
<source><![CDATA[CSIRT Frequently Asked Questions]]></source>
<year>2017</year>
<publisher-name><![CDATA[Carnegie Mellon University]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B4">
<nlm-citation citation-type="book">
<collab>Department of Homeland Security</collab>
<source><![CDATA[Vulnerability Assessment and Management]]></source>
<year>2012</year>
<publisher-name><![CDATA[NICSS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B5">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Donaldson]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Siegel]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Williams]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Aslam]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
</person-group>
<source><![CDATA[Enterprise Cybersecurity: How to Build a Successful Cyberdefense Program Against Advanced Threats]]></source>
<year>2015</year>
<page-range>pp. 201-4</page-range><publisher-loc><![CDATA[New York ]]></publisher-loc>
<publisher-name><![CDATA[Apress]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B6">
<nlm-citation citation-type="book">
<collab>Financial Executives International - FEI</collab>
<source><![CDATA[&#8220;Financial Executives, Cyber Security &amp; Business Continuity]]></source>
<year>2014</year>
<publisher-name><![CDATA[Canadian Executives Research Foundation (CFERF)]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B7">
<nlm-citation citation-type="">
<collab>Financial Regulatory Authority - FINRA.</collab>
<source><![CDATA[Report on Cybersecurity Practices]]></source>
<year></year>
<page-range>pp 1- 46.</page-range></nlm-citation>
</ref>
<ref id="B8">
<nlm-citation citation-type="">
<collab>Foresite</collab>
<source><![CDATA[Quick guide to common Cybersecurity Frameworks]]></source>
<year>2016</year>
</nlm-citation>
</ref>
<ref id="B9">
<nlm-citation citation-type="book">
<collab>ISACA</collab>
<source><![CDATA[Implementing the NIST Cybersecurity Framework]]></source>
<year>2014</year>
<publisher-loc><![CDATA[Rolling Meadows ]]></publisher-loc>
<publisher-name><![CDATA[ISACA]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B10">
<nlm-citation citation-type="book">
<collab>ISACA</collab>
<source><![CDATA[Transforming Cybersecurity]]></source>
<year>2013</year>
<publisher-loc><![CDATA[Rolling Meadows ]]></publisher-loc>
<publisher-name><![CDATA[ISACA]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B11">
<nlm-citation citation-type="book">
<collab>ISACA</collab>
<source><![CDATA[Cybersecurity Fundamentals]]></source>
<year>2015</year>
<publisher-loc><![CDATA[Rolling Meadows ]]></publisher-loc>
<publisher-name><![CDATA[ISACA]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B12">
<nlm-citation citation-type="book">
<collab>Karspersky Lab</collab>
<source><![CDATA[Top 10 Tips for Educating Employees about Cybersecurity]]></source>
<year>2015</year>
<publisher-name><![CDATA[AO Kaspersky Lab]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B13">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Lee]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
</person-group>
<source><![CDATA[The Sliding Scale of Cybersecurity]]></source>
<year>2015</year>
<publisher-name><![CDATA[SANS Institute]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B14">
<nlm-citation citation-type="book">
<collab>Ministry of Economic Affairs and Communication</collab>
<source><![CDATA[2014-2017 Estonia Cybersecurity Strategy]]></source>
<year>2017</year>
<publisher-name><![CDATA[ENISA]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B15">
<nlm-citation citation-type="book">
<collab>National Cyber Security Alliance</collab>
<source><![CDATA[Stay Safe Online]]></source>
<year>2017</year>
<publisher-name><![CDATA[NCS]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B16">
<nlm-citation citation-type="">
<collab>National Institute of Standards and Technology - NIST</collab>
<source><![CDATA[Framework for Improving Critical Infrastructure Cybersecurity]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B17">
<nlm-citation citation-type="">
<collab>National Institute of Standards and Technology - NIST.</collab>
<source><![CDATA[NIST Special Publications SP]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B18">
<nlm-citation citation-type="">
<collab>NATO Cooperative Cyber Defence Centre of Excellence - CCDCOE.</collab>
<source><![CDATA[Cyber Security Strategy Documents]]></source>
<year>2015</year>
</nlm-citation>
</ref>
<ref id="B19">
<nlm-citation citation-type="book">
<collab>North American Electric Relaibility Corporation - NERC</collab>
<source><![CDATA[Security Guideline for the Electricity Sector: Identifying Critical Cyber Assets]]></source>
<year>2010</year>
<publisher-name><![CDATA[NERC]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B20">
<nlm-citation citation-type="book">
<collab>Organisation for Economic Co-Operation and Development - OECD</collab>
<source><![CDATA[Cybersecurity Policy Making at a Turning Poin]]></source>
<year>2012</year>
<publisher-name><![CDATA[OECD]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B21">
<nlm-citation citation-type="book">
<collab>PCI Security Standards Council.</collab>
<source><![CDATA[Best Practices for implementing a Security Awareness Program]]></source>
<year>2014</year>
<publisher-name><![CDATA[PCI DSS.]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B22">
<nlm-citation citation-type="">
<collab>Pricewaterhouse Coopers - PwC</collab>
<source><![CDATA[PwC&#8217;s Board Cybersecurity Governance Framework]]></source>
<year>2016</year>
</nlm-citation>
</ref>
<ref id="B23">
<nlm-citation citation-type="journal">
<article-title xml:lang=""><![CDATA[Knowledge based systems as an aid in information systems audit]]></article-title>
<person-group person-group-type="author">
<name>
<surname><![CDATA[Proaño]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Saguay]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Jacome]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Sandoval]]></surname>
<given-names><![CDATA[F.]]></given-names>
</name>
</person-group>
<source><![CDATA[Enfoque UTE]]></source>
<year>2017</year>
<volume>8</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>pp.148-59</page-range></nlm-citation>
</ref>
<ref id="B24">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Sabillon]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Serra-Ruiz]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Cavaller]]></surname>
<given-names><![CDATA[V.]]></given-names>
</name>
<name>
<surname><![CDATA[Cano]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<source><![CDATA[A Comprehensive Cybersecurity Audit Model to Improve Cybersecurity Assurance: The CyberSecurity Audit Model (CSAM)]]></source>
<year>2017</year>
<conf-name><![CDATA[ 2017, SecondInternational Conference on Information Systems and Computer Science (INCISCOS),]]></conf-name>
<conf-loc>Quito, Ecuador </conf-loc>
</nlm-citation>
</ref>
<ref id="B25">
<nlm-citation citation-type="book">
<collab>SANS Institute</collab>
<source><![CDATA[SANS Forensics Whitepaper]]></source>
<year></year>
<publisher-name><![CDATA[SANS Institute]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B26">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Shackleford]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
</person-group>
<source><![CDATA[Who&#8217;s using Cyberthreat Intelligence and how?]]></source>
<year>2015</year>
<publisher-name><![CDATA[SANS Instit]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B27">
<nlm-citation citation-type="">
<collab>Trusted Computing Group</collab>
<source><![CDATA[Architect&#8217;s Guide: Cybersecurity]]></source>
<year>2013</year>
</nlm-citation>
</ref>
<ref id="B28">
<nlm-citation citation-type="book">
<collab>United States Computer Emergency Readiness Team - US-CERT</collab>
<source><![CDATA[Cybersecurity Framework]]></source>
<year>2017</year>
<publisher-name><![CDATA[US-CERT]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B29">
<nlm-citation citation-type="">
<collab>U.S. Department of Homeland Security</collab>
<source><![CDATA[Cybersecurity]]></source>
<year>2016</year>
</nlm-citation>
</ref>
<ref id="B30">
<nlm-citation citation-type="">
<collab>U.S. Department of Energy</collab>
<source><![CDATA[IT Security Architecture]]></source>
<year>2007</year>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
