- Universidad Piloto de Colombia
- Trabajos de grado - Posgrado
- Facultad de Ingenierías
- Especialización en Seguridad Informática
- View Item
Seguridad de los sistemas de información bajo la plataforma de iseries y cómo manejar adecuadamente los incidentes de seguridad de la información
Abstract
Los incidentes de seguridad de la
información en las organizaciones actualmente están
creciendo de forma muy rápida por tal razón es
importante que la detección de un ataque cibernético
en una organización sea lo más rápido posible, porque
en ocasiones un ataque puede durar días, meses e
incluso años. Lo importante en la estrategia de
seguridad es que la respuesta sea rápida y eficiente.
Cuando hablamos de un impacto en el negocio y no sólo
en el área de TI, nuestro nivel de seguridad será más
maduro y por tanto nuestro nivel de visibilidad y
respuesta será mayor. Por tal razón en este documento
se establece un modelo de buenas prácticas para el
manejo y tratamiento de un incidente de seguridad de la
información basándose en los mejores estándares
como la NIST (National Institute of Standards and
Technology – (Computer Security Incident Handling
Guide), tomando como base los lineamientos y
recomendaciones de la norma ISO IEC 27001 – 2013
para la plataforma de iSeries. The Incidents of information security in
organizations are currently growing very quickly for that
reason it is important that the detection of a cyber attack
in an organization as fast as possible because sometimes
an attack can last for days, months and even years. What
is important in the security strategy is that the response
is quick and efficient. When we talk about an impact on
the business and not just in the IT area, our security level
will be more mature and therefore our visibility and
response will be higher. For this reason in this paper a
model of good practice for the management and
treatment of a security incident information based on
the best standards such as NIST (National Institute of
Standards and Technology is established - (Computer
Security Incident Handling Guide) based on the
guidelines and recommendations of the ISO 27001 -
2013 for the iSeries platform




