错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Information Security Management in Higher Education Institutions in Compliance with the Organic Law for the Protection of Personal Data

  • Karen Estacio

摘要

Information security has become crucial for any organization due to a large amount of data handled daily and the need to protect it from possible external and internal threats. Organic Law for the Protection of Personal Data (LOPDP) regulates in Ecuadorian territory the protection and exercise of the rights of individuals concerning the processing of their data. The objective of this research is to analyze information security (IS) standards that have adequate controls to ensure the confidentiality, availability, and integrity of information. The ISO/IEC 27001:2022 and NIST 800–53 r5 standards were selected because they are widely recognized in the IS field and provide solid guidance for the implementation of security controls. The resulting instrument, a tool with 64 controls, will allow evaluation of IS compliance within Ecuadorian institutions of higher education to mitigate IS risks and avoid sanctions by the national data protection authority.