The present study provides valuable insights into the techniques and technologies to identify vulnerabilities and mitigate risks in computer systems implemented in university institutions in Quito, Ecuador. This study carried out a review of the Government Information Security Scheme (EGSI) and its scope of action in public universities in Ecuador. The main purpose of this work was to establish an evaluation instrument for information security in public universities in Ecuador, for which baselines were established regarding aspects to be analyzed to be later applied in a public university and thus test its operation. The methodological approach of this research used quantitative information to obtain a complete view of the information security scheme. Research techniques included field activities, interviews, surveys, analysis of results and presentation of results. These findings have practical implications for the information security practices in universities, as they highlight the most frequent computer risks in universities, such as external cyber-attacks and internal human errors, which can compromise the security, integrity, availability, and confidentiality of information and the functioning of systems. This tool is proposed as a comprehensive mechanism that will allow technology departments and relevant areas within public universities to carry out a thorough evaluation. The objective of this assessment tool is to determine to what extent the standards and guidelines of the Government Information Security Scheme are being complied with and if they are efficiently using its principles to safeguard sensitive information and critical processes. This assessment tool will provide institutions with a clear and objective view of their cybersecurity status. In addition, by standardizing assessment across all areas of technology at public universities, a solid foundation will be established for informed decision-making and for the implementation of continuous improvements in the field of information security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Study of Techniques and Technologies to Identify Vulnerabilities and Mitigate Risks in Computer Systems in University Institutions in Quito, Ecuador

  • Omar Puetate-Sarzosa,
  • Leticia Vaca-Cardenas

摘要

The present study provides valuable insights into the techniques and technologies to identify vulnerabilities and mitigate risks in computer systems implemented in university institutions in Quito, Ecuador. This study carried out a review of the Government Information Security Scheme (EGSI) and its scope of action in public universities in Ecuador. The main purpose of this work was to establish an evaluation instrument for information security in public universities in Ecuador, for which baselines were established regarding aspects to be analyzed to be later applied in a public university and thus test its operation. The methodological approach of this research used quantitative information to obtain a complete view of the information security scheme. Research techniques included field activities, interviews, surveys, analysis of results and presentation of results. These findings have practical implications for the information security practices in universities, as they highlight the most frequent computer risks in universities, such as external cyber-attacks and internal human errors, which can compromise the security, integrity, availability, and confidentiality of information and the functioning of systems. This tool is proposed as a comprehensive mechanism that will allow technology departments and relevant areas within public universities to carry out a thorough evaluation. The objective of this assessment tool is to determine to what extent the standards and guidelines of the Government Information Security Scheme are being complied with and if they are efficiently using its principles to safeguard sensitive information and critical processes. This assessment tool will provide institutions with a clear and objective view of their cybersecurity status. In addition, by standardizing assessment across all areas of technology at public universities, a solid foundation will be established for informed decision-making and for the implementation of continuous improvements in the field of information security.