The Information Security Management System (ISMS) is responsible for protecting information by implementing strategies to ensure its confidentiality, availability, and integrity. Information for the ISMS is collected through a Statement of Applicability, allowing for an ISMS audit of the organization and demonstrating its condition. This work proposes an agile internal audit methodology based on ISO/IEC 27001, aimed at reducing the time required for internal audits and preparing the institution for formal certification.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Agile Audit Proposal for ISO IEC 27001 Standard Implementation in Higher Education Faculties

  • David Ruete Zúñiga,
  • Pilar López Lira,
  • Alejandro Caroca Navarro,
  • Mailiú Díaz Peña,
  • Nicolás Caselli Benavente,
  • Danilo Leal Moraga,
  • Marcelo Reyes Rogget,
  • Jean Paul Maidana González

摘要

The Information Security Management System (ISMS) is responsible for protecting information by implementing strategies to ensure its confidentiality, availability, and integrity. Information for the ISMS is collected through a Statement of Applicability, allowing for an ISMS audit of the organization and demonstrating its condition. This work proposes an agile internal audit methodology based on ISO/IEC 27001, aimed at reducing the time required for internal audits and preparing the institution for formal certification.