Mitigating Information Leakage in Tech-Sector SMEs: Implementing ISO 27001:2022 for Comprehensive Security

Gabriel O. Quispe, Cesar K. Zuloaga, Pedro S. Castañeda

Producción científica: Libro o Capítulo del libro Contribución a la conferenciarevisión exhaustiva

Resumen

This paper presents a model for implementing an Information Security Management System (ISMS) based on ISO 27001:2022 tailored to the needs of small and medium-sized enterprises (SMEs) in the technology sector in Lima Metropolitana. The model focuses on mitigating data leakage, a critical issue exacerbated by the increasing digitization of business operations. The proposed framework integrates controls from ISO 27001 aligned with NIST SP 800-53 to enhance information security practices. Results from applying the model to two technology SMEs indicate that one company (Company A) achieved a 94.44% Critical Control Implementation Index (IICC), a 70% Critical Vulnerability Resolution Rate (TRVC), and an 85% Policy Compliance Rate (TCPS), while the second company (Company B) achieved significantly lower rates of 50%, 40%, and 60%, respectively. These findings highlight both strengths in technological controls and weaknesses in organizational security management. This research contributes to the field by providing a practical, scalable approach for SMEs to enhance their information security posture, addressing both human and technological factors.

Idioma originalInglés estadounidense
Título de la publicación alojadaInformation Management - 11th International Conference, ICIM 2025, Revised Selected Papers
EditoresShuliang Li
EditorialSpringer Science and Business Media Deutschland GmbH
Páginas273-285
-13
ISBN (versión impresa)9783031993527
DOI
EstadoIndizado - 2026
Publicado de forma externa
Evento11th International Conference on Information Management, ICIM 2025 - London, Reino Unido
Duración: 28 mar. 202530 mar. 2025

Serie de la publicación

NombreCommunications in Computer and Information Science
Volumen2540 CCIS
ISSN (versión impresa)1865-0929
ISSN (versión digital)1865-0937

Conferencia

Conferencia11th International Conference on Information Management, ICIM 2025
País/TerritorioReino Unido
CiudadLondon
Período28/03/2530/03/25

Nota bibliográfica

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.

Huella

Profundice en los temas de investigación de 'Mitigating Information Leakage in Tech-Sector SMEs: Implementing ISO 27001:2022 for Comprehensive Security'. En conjunto forman una huella única.

Citar esto