Skip to main navigation Skip to search Skip to main content

Mitigating Information Leakage in Tech-Sector SMEs: Implementing ISO 27001:2022 for Comprehensive Security

Research output: Chapter in Book/ReportConference contributionpeer-review

Abstract

This paper presents a model for implementing an Information Security Management System (ISMS) based on ISO 27001:2022 tailored to the needs of small and medium-sized enterprises (SMEs) in the technology sector in Lima Metropolitana. The model focuses on mitigating data leakage, a critical issue exacerbated by the increasing digitization of business operations. The proposed framework integrates controls from ISO 27001 aligned with NIST SP 800-53 to enhance information security practices. Results from applying the model to two technology SMEs indicate that one company (Company A) achieved a 94.44% Critical Control Implementation Index (IICC), a 70% Critical Vulnerability Resolution Rate (TRVC), and an 85% Policy Compliance Rate (TCPS), while the second company (Company B) achieved significantly lower rates of 50%, 40%, and 60%, respectively. These findings highlight both strengths in technological controls and weaknesses in organizational security management. This research contributes to the field by providing a practical, scalable approach for SMEs to enhance their information security posture, addressing both human and technological factors.

Original languageAmerican English
Title of host publicationInformation Management - 11th International Conference, ICIM 2025, Revised Selected Papers
EditorsShuliang Li
PublisherSpringer Science and Business Media Deutschland GmbH
Pages273-285
Number of pages13
ISBN (Print)9783031993527
DOIs
StateIndexed - 2026
Externally publishedYes
Event11th International Conference on Information Management, ICIM 2025 - London, United Kingdom
Duration: 28 Mar 202530 Mar 2025

Publication series

NameCommunications in Computer and Information Science
Volume2540 CCIS
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference11th International Conference on Information Management, ICIM 2025
Country/TerritoryUnited Kingdom
CityLondon
Period28/03/2530/03/25

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.

Keywords

  • Data Leakage
  • ISO 27001:2022
  • Information Security
  • Information Security Management System (ISMS)
  • NIST SP 800-53
  • SMEs

Fingerprint

Dive into the research topics of 'Mitigating Information Leakage in Tech-Sector SMEs: Implementing ISO 27001:2022 for Comprehensive Security'. Together they form a unique fingerprint.

Cite this