Please use this identifier to cite or link to this item: http://hdl.handle.net/10609/126406
Title: Elaboración de un plan de implementación de la ISO/IEC 27001:2013 para una ISP
Author: Sáenz Casallas, Mayerly
Director: Garrigues, Carles  
Tutor: Segovia Henares, Antonio José
Abstract: This master¿s thesis proposes to implement the master plan to ISP Company located in Imbabura Ecuador. Following the specifications for the implementation of the information security management according to the International Organization for Standardization ISO/IEC 27001: 2013, and the standards on the best practice recommendations in ISO 27002: 2013. As a starting point, a diagnosis of the company's current situation with respect to information security requirements was carried out to analyze its degree of compliance. Subsequently, a risk analysis was made on the relevant assets in terms of safety, to determine the potential impact, they would suffer in any case exposed to threat. Indeed, with this information it is possible to determine the acceptable level of risk and propose projects to reduce those risks that are treatable. Each of these projects is designed with the planning to be executed, and the estimated cost that the Company would have to assume. Which will not be more costly than taking the risk. Finally, the expected results are presented, after starting each of the proposed projects, regarding the compliance conforming to ISO/IEC 27002:2013, and each of its fourteen domains.
Keywords: SGSI
ISO/IEC 27001:2013
ISO 27002
ISP
risk analysis
Document type: info:eu-repo/semantics/masterThesis
Issue Date: Dec-2020
Publication license: http://creativecommons.org/licenses/by-nc-nd/3.0/es/  
Appears in Collections:Trabajos finales de carrera, trabajos de investigación, etc.

Files in This Item:
File Description SizeFormat 
Presentación a la Dirección de la ISP.pptx572,57 kBMicrosoft Powerpoint XMLView/Open
msaenzcTFM1220memoria.pdfMemoria del TFM1,73 MBAdobe PDFThumbnail
View/Open