Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ Recolector de Cienci...arrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
addClaim

Plan de Implementación del SGSI basado en la ISO/IEC 27001:2022 de la empresa TRADUX

Authors: Busto Pérez de Mendiguren, Estíbaliz;

Plan de Implementación del SGSI basado en la ISO/IEC 27001:2022 de la empresa TRADUX

Abstract

La información es uno de los principales activos que posee cualquier organización; por ello, se debe preservar su confidencialidad, integridad y disponibilidad para alcanzar los objetivos del negocio. El objetivo del presente proyecto es la elaboración de un Plan de Implementación de un Sistema de Gestión de Seguridad de la Información (SGSI) de la organización ficticia TRADUX, empresa de traducción e interpretación, siguiendo la ISO/IEC 27001:2022. Se comienza con la descripción de la organización y un análisis diferencial de la ISO 27001:2022 e ISO 27002:2022 como las referencias básicas del documento. Seguidamente, se definen todos los documentos necesarios para el cumplimiento normativo de la ISO 27001:2022 utilizando la metodología de análisis de riesgos basada en MAGERIT. Posteriormente, se proponen diferentes proyectos con el propósito de reducir los principales riesgos encontrados y mejorar la seguridad de la información de dicha organización. Para finalizar, se llevará a cabo la auditoría de cumplimiento donde se evaluará el grado de madurez de los controles de la ISO 27002:2022 y así conocer el estado de seguridad de la información de TRADUX.

Information is one of the main assets that any organization has. Its confidentiality, integrity and availability must be preserved to achieve business objectives. Therefore, the objective of this project is the preparation of an Implementation Plan for an Information Security Management System (ISMS) of the fictitious organization TRADUX, translation and interpretation company, following the ISO/IEC 27001:2022. It begins with the description of the organization and a differential analysis of ISO 27001:2022 and ISO 27002:2022 as the basic references of the document. Next, all the documents necessary for regulatory compliance with ISO 27001:2022 are defined using the risk analysis methodology based on MAGERIT. Subsequently, different projects are proposed with the purpose of reducing the main risks found and improving the information security of said organization. Finally, the compliance audit will be carried out where the degree of maturity of the ISO 27002:2022 controls will be evaluated and thus know the information security status of TRADUX.

Keywords

ISO 27002:2022, MAGERIT, ISO 27001:2022, SGSI, Management information systems -- TFM, Sistemes d'informació per a la gestió -- TFM

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green