Authors:
Luís Enrique Sánchez
1
;
Daniel Villafranca
1
;
Eduardo Fernández-Medina
2
and
Mario Piattini
2
Affiliations:
1
SICAMAN NT., Spain
;
2
University of Castilla-La Mancha, Spain
Keyword(s):
ISMS, SME, Maturity Level, ISO27001, Security System, Information Security Management System, Small-Medium Size Enterprise.
Related
Ontology
Subjects/Areas/Topics:
Ethical and Legal Implications of Security and Privacy
;
Information and Systems Security
;
Information Assurance
;
Information Systems Auditing
;
Management of Computing Security
;
Organizational Security Policies
;
Planning Security
;
Risk Assessment
;
Security Area Control
Abstract:
For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system and tools which allow them to manage it. In small and
medium-sized enterprises, the application of security standards has an additional problem, which is the fact that they do not have enough resources to carry out an appropriate management. This security management system must have highly reduced costs for its implementation and maintenance in small and medium-sized enterprises (from here on refered to as SMEs) to be feasible. In this paper we show the practical application of our proposal for a maturity model with which to manage the security in SMEs, centring upon the phase which determines the state of the enterprise and some of the mechanisms which allow the security level to be kept up to date without the need for continuous audits. This focus is continuously refined through its application to real cases, the results of
which are shown in this paper.
(More)