Implementación del primer sistema de gestión de seguridad de la información, en el Ecuador, certificado bajo la norma iso27001:2005

Given the evolution of information technologies and their direct relationship with the business objectives of organizations, the universe of threats and vulnerabilities increase, then is necessary to protect one of the most important assets of the organization, The information, ensuring always the a...

Full description

Saved in:
Bibliographic Details
Main Author: Aranda Segovia, José Alfonso (author)
Format: article
Language:eng
Published: 2009
Subjects:
Online Access:http://www.dspace.espol.edu.ec/handle/123456789/8080
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Given the evolution of information technologies and their direct relationship with the business objectives of organizations, the universe of threats and vulnerabilities increase, then is necessary to protect one of the most important assets of the organization, The information, ensuring always the availability, confidentiality and integrity of it. The most appropriate way to protect information assets is through proper risk management, achieving identify and focus efforts on those elements that are most exposed. Implementing a Information Security Management System guarantees to organization that adopt the best practices recommended by the ISO 27001:2005 for the proper treatment of risk. Then we are going to show a successful case in the implementation of an ISMS and their respective certification under the ISO 27001:2005