Hybrid Information Security Framework Based on ISO/IEC 27005:2022 and the NIST Framework for the Ministry of Education of Ecuador (TIC)
摘要
Currently, the National Directorate of Information and Communication Technologies (NDICT) of the Ministry of Education (MOE) of Ecuador faces significant security management challenges. Within its IT structure, the entity has implemented information systems and optimized processes to automate previously manual tasks. This article aims to design a hybrid framework to address three key security issues through a thorough research review. Prominent vulnerabilities include weak passwords and the risk of unauthorized physical access. ISO 27005 and NIST 800–53 offer a robust approach to manage information security risks. Validating the framework and controls’ applicability ensures suitability for specific infrastructure and operations. Security tests and simulations identify weaknesses, strengthening controls against cyber threats. Leadership approval is crucial for a proactive security improvement approach. This combination provides a comprehensive approach to security risk management, ensuring confidentiality, integrity, and availability of information and systems at the National Directorate of ICT. Following these guidelines prepares the department to address current and future security challenges effectively.