首页> 外文会议>IEEE Sciences and Humanities International Research Conference >Information Security Risk Management Model for Peruvian SMEs
【24h】

Information Security Risk Management Model for Peruvian SMEs

机译:秘鲁中小企业信息安全风险管理模式

获取原文

摘要

In this paper, we propose a risk management model of information security for Peruvian SMEs, taking as reference the OCTAVE-S methodology and the ISO/IEC 27005 standard. The model consists of the 3 phases of OCTAVE-S (Construction of the threats profile, Identification of infrastructure vulnerabilities, and Strategies and security plans). This model contains the contemplated lists of ISO / IEC 27005, it also contains the calculation and the risk treatment of this standard. Likewise, the model adopts a quantitative approach that allows calculating the residual risk, for example, the most critical asset identified obtained 216 of risk value and the residual risk obtained was 109 of risk value, this is obtained on the basis of the effectiveness of the controls that are part of the proposed model, for example, formalize procedures and policies and their occasional review. This model provides guidelines for information security risks for companies. It was implemented in the sales process of a Peruvian SME of the ceramic sector, proving to be easy to use and it was possible to identify the necessary controls to reduce the risk, whose implementation reduces the risk by 53%.
机译:在本文中,我们提出了秘鲁中小企业信息安全风险管理模型,参考Octave-S方法和ISO / IEC 27005标准。该模型由Octave-s的3个阶段组成(构建威胁概况,识别基础设施漏洞和战略和安全计划)。该模型包含ISO / IEC 27005的预期列表,还包含本标准的计算和风险处理。同样,该模型采用定量方法,允许计算残余风险,例如,所识别的最关键资产216的风险值,并且获得的残余风险为109个风险值,这是基于效果获得的作为所提出的模型的一部分,例如,正式化程序和政策以及偶尔审查的控件。该模型为公司提供了信息安全风险的指导。它在陶瓷部门的秘鲁中小企业销售过程中实施,证明易于使用,有可能确定降低风险的必要控制,其实施将风险降低53%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号