Please use this identifier to cite or link to this item: http://hdl.handle.net/10609/126386
Title: Plan Director de Seguridad en la Administración Local bajo la perspectiva de la Calidad del Dato
Author: Asensio Palao, Ramón
Director: Garrigues, Carles  
Tutor: Segovia Henares, Antonio José
Abstract: Practical work to implement a Security Master Plan in a Spanish Local Public Administration under the protection of standards such as the National Security Scheme (ENS) and ISO/IEC 27001, while considering the quality of the data and its interoperability. A new simple application methodology on ISO 25012 is created to find a balance that allows us to have secure and applicable information systems. An implementation of the ENS conditioned by ISO 25012 is approached to later move closer to ISO/IEC 27001 and obtain the advantages of the three standards. We develop all the necessary main documentation, a risk analysis is carried out using MAGERIT methodology, we propose projects to improve the security of the information system by substituting those parts that do not meet the data quality objectives and we carry out an audit to evaluate the compliance with regulations. Our approach from ENS to ISO/IEC 27001 has allowed us to prioritize those high risk projects, always assuming the approval of the administration's high direction, we have managed to improve security in both standards although more progress has been made in ENS than in ISO/IEC 27001, due to the type of approach made for a public entity. The screening of ISO 25012 projects has enabled us to not invest resources in parts of the system that are better replaced than secured, and has managed to put the citizen at the center of electronic administration.
Keywords: ISMS
National Security Framework
ISO 25012
MAGERIT
National Interoperability Schema
ISO 27001
Document type: info:eu-repo/semantics/masterThesis
Issue Date: 28-Dec-2020
Publication license: http://creativecommons.org/licenses/by-nc-nd/3.0/es/  
Appears in Collections:Trabajos finales de carrera, trabajos de investigación, etc.

Files in This Item:
File Description SizeFormat 
analisis de riesgos.mgr39,71 kBUnknownView/Open
Evaluación madurez actual ISO 27001.mgr43,56 kBUnknownView/Open
Evaluación madurez actual ENS.mgr39,7 kBUnknownView/Open
Gap_Inicial_ISO27001_2020.xlsx118,85 kBMicrosoft Excel XMLView/Open
patterns_27000_2013.xml8 kBXMLView/Open
presentación AR.odp16,85 MBOpenDocument PresentationView/Open
Relación entre activos.jpg794,7 kBJPEGThumbnail
View/Open
asensiopalaoTFM0121memoria.pdfMemoria del TFM3,19 MBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121planmejora.pdfPlan de mejora de la seguridad del TFM246,9 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121categorización.pdfCategorización del sistema del TFM262,65 kBAdobe PDFThumbnail
View/Open
Gap_Inicial_ISO27002_2020.xlsx26,75 kBMicrosoft Excel XMLView/Open
presentacion resumen TFM.odp25,85 MBOpenDocument PresentationView/Open
asensiopalaoTFM0121presentación.pdfPresentación en PDF del TFM10,63 MBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121Declaración de Aplicabilidad.pdfDeclaración de aplicabilidad del TFM347,52 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121Decreto.pdfDecreto Comité de Seguridad del TFM91,98 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121ejmploPPT.pdfEjemplo PPT del TFM269,57 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121planadecuación.pdfPlan de adecuación al ENS del TFM186,8 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121políticadeseguridad.pdfPolítica de seguridad del TFM242,9 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121auditorias.pdfProcedimiento de auditorías internas del TFM247,84 kBAdobe PDFThumbnail
View/Open
asensiopalaoTFM0121amenazas.pdfAnálisis de amenazas del TFM1,46 MBAdobe PDFThumbnail
View/Open