Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado Practical Application of a Security Management Maturity Model for SMEs Based on Predefined Schemas dentro del  International Conference on Security and Cryptography (SECRYPT08), Porto, Portugal, Julio, 2008,  Pp. 391-398. ISBN: 978-989-8111-59-3, IDSNumber: BIE55, EID: 2-s2.0-58049181431, WOS: 000258929000061. Core: B.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system and tools which allow them to manage it. In small and medium-sized enterprises, the application of security standards has an additional problem, which is the fact that they do not have enough resources to carry out an appropriate management. This security management system must have highly reduced costs for its implementation and maintenance in small and medium-sized enterprises (from here on refered to as SMEs) to be feasible. In this paper we show the practical application of our proposal for a maturity model with which to manage the security in SMEs, centring upon the phase which determines the state of the enterprise and some of the mechanisms which allow the security level to be kept up to date without the need for continuous audits. This focus is continuously refined through its application to real cases, the results of which are shown in this paper.

 

Más información:

URL Noticia 1: https://www.researchgate.net

URL Noticia 2: https://pdfs.semanticscholar.org

Learn More

Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado Developing a model and a tool to manage the information security in Small and Medium Enterprises dentro del  2nd International Conference on Security and Cryptography (SECRYPT07), Barcelona, España, 28-31 Julio de 2007, Pp. 355-362. ISBN: 978-989-8111-12-8, IDSNumber: BGV85, EID: 2-s2.0-58049181431, WOS: 000250830700050. Core: B.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
The maturity and security management systems are essential in order to guarantee the continuity and stability of the companies in the current market situation. However, this requires that enterprises know in every moment their security maturity level and to what extend their information security system must evolve. In small and medium-sized enterprises, the application of security standards has an additional problem, which is the fact that they do not have enough resources to carry out an appropriate management. This security management system must have highly reduced costs for its implementation and maintenance in small and medium-sized enterprises (from here on refered to as SMEs) to be feasible. In this paper, we will put forward our proposal of a maturity model for security management in SMEs and we will briefly analyse other models that exist in the market. This approach is being directly applied to real cases, thus obtaining a constant improvement in its application.

 

Más información:

URL Noticia 1: https://www.researchgate.net

 

Learn More

Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado SCMM-TOOL: Tool for computer automation of the Information Security Management System dentro del  2nd International Conference on Software and Data Technologies (ICSOFT07), Barcelona, España., 22-25 Julio de 2007, Pp. 311-318. ISBN: 978-989-8111-06-7, IDSNumber: BHE30, EID: 2-s2.0-67650215500, WOS: 000252427700049. Core: B.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system and tools which allow them to manage it. In addition, security management system must have highly reduced costs for its implementation and maintenance in small and medium-sized enterprises (from here on refered to as SMEs) to be feasible. In this paper, we will show the tool we have developed using our model for the development, implementation and maintenance of a security management system, adapted to the needs and resources of a SME. Furthermore, we will state how this tool lets enterprises with limited resources manage their security system very efficiently. This approach is being directly applied to real cases, thus obtaining a constant improvement in its application.

 

Más información:

URL Noticia1: https://www.researchgate.net

Learn More

Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Piattini, M y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado  Practical Development: Maturity Model for Information Systems Security Management in SMEs dentro del  INSTICC Press, 5th International Workshop on Security in Information Systems (WOSIS07) In conjunction with 9th International Conference on Enterprise Information Systems (ICEIS08), Funchal, Madeira – Portugal, June, 2007, Pp. 233-244. ISBN: 978-972-8865-96-2, EID: 2-s2.0-58149112795. Core: C.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system. However, this requires that enterprises know in every moment their security maturity level and to what extend their information security system must evolve. Moreover, this security management system must have very reduced costs for its implementation and maintenance in small and medium-size enterprises (from now on, SMEs) to be feasible. In this paper, we will put forward our proposal of a maturity model for security management in SMEs and we will briefly analyse other models that exist in the market. This approach is being directly applied to real cases, thus obtaining an improvement in its application.

 

 

Más información:

URL Noticia 1: https://www.researchgate.net

URL Noticia 2: http://www.scitepress.org

Learn More

Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado  Developing a Maturity Model for Information System Security Management within Small and Medium Size Enterprises dentro del 5th International Workshop on Security in Information Systems (WOSIS06) In conjunction with 9th International Conference on Enterprise Information Systems (ICEIS07). Paphos, Chipre, 23 y 24 de Mayo de 2006, Pp. 256-265. ISBN: 972-8865-52-X, EID: 2-s2.0-77954138335. Core: C.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
For enterprises to be able to use information and communication technologies with guarantees, it is necessary to have an adequate security management available. This requires that enterprises always know their current maturity level and to what extend their security must evolve. Current maturity models are showing us that they are inefficient in small and medium size enterprises since these enterprises have a series of additional problems when implementing security management systems. In this paper, we will make an analysis of the maturity models oriented to security existing in the market by analysing their main disadvantages regarding small and medium size enterprises using as a reference framework ISO/IEC 17799. This approach is being directly applied to real cases, thus obtaining a constant improvement in its application.

 

Más información:

URL Noticia 1:https://www.researchgate.net

URL Noticia 2: http://www.scitepress.org

Learn More

Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado Building a Maturity Security Model Based on ISO 17799 dentro del The 2006 International Conference on Computational Sciences and Its Applications (ICCSA06), Glasgow, Reino Unido, 8-11 Mayo de 2006, Pp. 173-175, ISBN: 3-540-34075-0. Core: C.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
For enterprises to be able to properly use information and communications technologies, it is necessary to have guides, metrics and tools that allow us to always know the level of our security and the points in which we are not covering it. In small and medium-size enterprises, the application of security standards has an additional problem, that is, the fact that they do not have enough resources to perform an appropriate management. In this paper, we will present a new approach to manage security within this kind of enterprises, adapted to the size of the enterprise and its maturity level, using as a reference ISO/IEC 17799. This approach is being directly applied to real cases and it is obtaining a constant improvement in its application.

 

Más información:

URL Noticia 1: https://www.researchgate.net

Learn More

Participación en Congresos

El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado Practical Approach of a Secure Management System based on ISO/IEC 17799 dentro del IEEE Computer Society, IEEE International Symposium on Frontiers on Availability, Reliability and Security (ARES 2006), Viena, Austria, 20-22 de Abril de 2006,  Pp. 585-592. ISBN: 0-7695-2567-9, IDSNumber: BEL18, DOI: 10.1109/ARES.2006.94, EID: 2-s2.0-33750931974, WOS: 000237699600076. Core: B

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT

For enterprises to be able to properly use information and communications technologies, it is necessary to have guides, metrics and tools that allow us to always know the level of our security and the points in which we are not covering it. In small and medium-size enterprises, the application of security standards has an additional problem, that is, the fact that they do not have enough resources to perform an appropriate management. In this article we analyze some of the existing maturity models and we compare them to the maturity model we are applying in practice. Finally we introduce a first approach to a scoreboard which is being developed as part of a security management tool for IT systems. This approach is being directly applied to real cases and it is obtaining a constant improvement in its application.

Más información:

URL Noticia 1: https://ieeexplore.ieee.org

URL Noticia 2: https://www.researchgate.net

Learn More

Participación en Congresos

El equipo formado por los investigadores “Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M.” y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado Gestión de la seguridad de los sistemas de información en las empresas desde la perspectiva de su tamaño y nivel de madurez, tomando como base la ISO/IEC 17799 dentro del IV Congreso Internacional de Auditoría y Seguridad de la Información (CIASI05), Madrid, España,  Dic, 2005,  Pp. 39-52, ISBN: 84-689-5752-6.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
Para que las empresas puedan utilizar las tecnologías de la información y las comunicaciones con garantías, es necesario disponer de guías, métricas y herramientas que nos permitan conocer en cada momento el nivel de nuestra seguridad y los puntos que no estamos cubriendo en la misma. En las pequeñas y medianas empresas, la aplicación de normativas de seguridad cuenta con el problema adicional de no tener recursos humanos y económicos suficientes para realizar una adecuada gestión. En este artículo mostramos un nuevo enfoque para desarrollar e implantar sistemas de gestión de seguridad, teniendo en cuenta aspectos como el tamaño de la empresa y los niveles de madurez, utilizando como marco de referencia la norma ISO/IEC 17799. Este enfoque está siendo aplicado directamente a casos reales, consiguiendo así una constante mejora en su aplicación.

 

Más información:

URL Noticia 1: https://www.researchgate.net

URL Noticia 2: https://www.researchgate.net/pdf

Learn More

Publicación de Artículos en Revistas

El equipo formado por los investigadores Santos-Olmo, A.; Sánchez, L.E.; García, D.; Fernandez-Medina, E.; Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha publicado un artículo denominado The Application of the Action Research Method in order to Develop an Agile Information Security Management Methodology dentro de la revista Future Internet 2016, 8(3), 36, Pp.1-24. doi:10.3390/fi8030036. ISSN: 1999-5903. Global Impact factor: 0.789 (2015). Researchgate Journal Impact: 1.65 (2015).

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT

Society is increasingly dependent on Information Security Management Systems (ISMS), and having these kind of systems has become vital for the development of Small and Medium-Sized Enterprises (SMEs). However, these companies require ISMS that have been adapted to their special features and have been optimized as regards the resources needed to deploy and maintain them, with very low costs and short implementation periods. This paper discusses the different cycles carried out using the ‘Action Research (AR)’ method, which have allowed the development of a security management methodology for SMEs that is able to automate processes and reduce the implementation time of the ISMS.

 

Más información:

URL Noticia 1: http://www.mdpi.com

URL Noticia 2:https://www.mdpi.com/pdf

Learn More

Publicación de Artículos en Revistas

El equipo formado por los investigadores Santos-Olmo, A.; Sánchez, L.E.; Caballero, I.; Camacho, S.; Fernandez-Medina, E. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha publicado un artículo denominado The Importance of the Security Culture in SMEs as Regards the Correct Management of the Security of Their Assets  dentro de la revista Future Internet 2016, 8(3), 30, Pp.1-27. doi:10.3390/fi8030030. ISSN: 1999-5903. Global Impact factor: 0.789 (2015). Researchgate Journal Impact: 1.65 (2015).

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

ABSTRACT
The information society is increasingly more dependent on Information Security Management Systems (ISMSs), and the availability of these kinds of systems is now vital for the development of Small and Medium-Sized Enterprises (SMEs). However, these companies require ISMSs that have been adapted to their special features, and which are optimized as regards the resources needed to deploy and maintain them. This article shows how important the security culture within ISMSs is for SMEs, and how the concept of security culture has been introduced into a security management methodology (MARISMA is a Methodology for “Information Security Management System in SMEs” developed by the Sicaman Nuevas Tecnologías Company, Research Group GSyA and Alarcos of the University of Castilla-La Mancha.) for SMEs. This model is currently being directly applied to real cases, thus allowing a steady improvement to be made to its implementation.

 

Más información:

URL Noticia 1: https://www.researchgate.net

URL Noticia 2: http://www.mdpi.com/pdf

Learn More