Information Security Risk Management Model for Peruvian SMEs

Chris García-Porras, Sarita Huamani-Pastor, Jimmy Armas-Aguirre
{"title":"Information Security Risk Management Model for Peruvian SMEs","authors":"Chris García-Porras, Sarita Huamani-Pastor, Jimmy Armas-Aguirre","doi":"10.1109/SHIRCON.2018.8592994","DOIUrl":null,"url":null,"abstract":"In this paper, we propose a risk management model of information security for Peruvian SMEs, taking as reference the OCTAVE-S methodology and the ISO / IEC 27005 standard. The model consists of the 3 phases of OCTAVE-S (Construction of the threats profile, Identification of infrastructure vulnerabilities, and Strategies and security plans). This model contains the contemplated lists of ISO / IEC 27005, it also contains the calculation and the risk treatment of this standard. Likewise, the model adopts a quantitative approach that allows calculating the residual risk, for example, the most critical asset identified obtained 216 of risk value and the residual risk obtained was 109 of risk value, this is obtained on the basis of the effectiveness of the controls that are part of the proposed model, for example, formalize procedures and policies and their occasional review. This model provides guidelines for information security risks for companies. It was implemented in the sales process of a Peruvian SME of the ceramic sector, proving to be easy to use and it was possible to identify the necessary controls to reduce the risk, whose implementation reduces the risk by 53%.","PeriodicalId":408525,"journal":{"name":"2018 IEEE Sciences and Humanities International Research Conference (SHIRCON)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE Sciences and Humanities International Research Conference (SHIRCON)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SHIRCON.2018.8592994","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

In this paper, we propose a risk management model of information security for Peruvian SMEs, taking as reference the OCTAVE-S methodology and the ISO / IEC 27005 standard. The model consists of the 3 phases of OCTAVE-S (Construction of the threats profile, Identification of infrastructure vulnerabilities, and Strategies and security plans). This model contains the contemplated lists of ISO / IEC 27005, it also contains the calculation and the risk treatment of this standard. Likewise, the model adopts a quantitative approach that allows calculating the residual risk, for example, the most critical asset identified obtained 216 of risk value and the residual risk obtained was 109 of risk value, this is obtained on the basis of the effectiveness of the controls that are part of the proposed model, for example, formalize procedures and policies and their occasional review. This model provides guidelines for information security risks for companies. It was implemented in the sales process of a Peruvian SME of the ceramic sector, proving to be easy to use and it was possible to identify the necessary controls to reduce the risk, whose implementation reduces the risk by 53%.
秘鲁中小企业信息安全风险管理模式
本文借鉴OCTAVE-S方法和ISO / IEC 27005标准,提出了秘鲁中小企业信息安全风险管理模型。该模型由OCTAVE-S的3个阶段组成(构建威胁概要、识别基础设施漏洞以及策略和安全计划)。本模型包含ISO / IEC 27005的预期清单,也包含本标准的计算和风险处理。同样,该模型采用定量方法,可以计算剩余风险,例如,识别出的最关键资产获得了216个风险值,获得的剩余风险为109个风险值,这是基于所提出模型的一部分控制的有效性而获得的,例如,形式化的程序和政策及其偶尔的审查。该模型为企业提供了信息安全风险的指导方针。在秘鲁一家陶瓷行业中小企业的销售过程中实施了该系统,事实证明该系统易于使用,并且可以识别必要的控制措施以降低风险,其实施将风险降低了53%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信