Guía Práctica para la Implementación de ISO/IEC 27001
| dc.contributor.advisor | Contreras Ortiz , Martha Susana | |
| dc.contributor.author | Bermudez Nuñez, Samuel Ricardo | |
| dc.contributor.corporatename | Universidad Santo Tomás | |
| dc.contributor.cvlac | https://scienti.minciencias.gov.co/cvlac/visualizador/generarCurriculoCv.do?cod_rh=0000901571 | |
| dc.contributor.googlescholar | https://scholar.google.com.co/citations?user=L45gJqUAAAAJ&hl=es&oi=ao | |
| dc.contributor.orcid | https://orcid.org/0000-0002-7715-6420 | |
| dc.date.accessioned | 2026-10-08T15:04:07Z | |
| dc.date.available | 2026-10-08T15:04:07Z | |
| dc.date.issued | 2026-10-06 | |
| dc.description | En el contexto tecnológico actual, definido por el incremento en las ciberamenazas y la acelerada transformación digital de las organizaciones, el resguardo de los activos de información se ha convertido en un pilar estratégico. Sin embargo, existen vacíos significativos respecto a la realización de marcos internacionales actualizados en entornos empresariales concretos. En este escenario concreto, la elaboración del presente análisis sobre la norma ISO/IEC 27001:2022 da una respuesta a una necesidad sectorial real, que desemboca de las carencias en la gestión estructurada de la seguridad de la información. La ausencia de procesos establecidos incrementa de manera considerable la exposición a incidentes que comprometen la continuidad operativa, la confianza institucional y la custodia de datos sensibles (Alassaf & Alkhalifah, 2021). Gracias a una perspectiva académica y disciplinar, esta investigación justifica su desarrollo al sintetizar y sistematizar la aplicación práctica del estándar ISO/IEC 27001:2022 en el contexto organizacional. El trabajo da un valor al conocimiento mediante la identificación analítica de brechas de seguridad, la evaluación de controles actualizados (incluidos los nuevos controles del Anexo A) y la propuesta de lineamientos conceptuales que tienen como fin la mitigación del riesgo. De este modo, la monografía no solo tiene como fin estructurar un modelo de prevención de amenazas, sino que a su vez establece bases teóricas y metodológicas para impulsa procesos de mejora continua y respaldar la toma de decisiones informadas (Andersson et al., 2022). El conocimiento resultado en este estudio da como beneficio directamente a profesionales del área de la seguridad de la información, auditores de sistemas dentro del sector productivo, ofreciéndoles un marco de referencia analítico para diagnosticar y fortalecer sus empresas. Asimismo, sirve como fuente de consulta para la comunidad académica interesada en la gestión | |
| dc.description.abstract | In the current technological landscape—defined by rising cyber threats and the accelerated digital transformation of organizations—safeguarding information assets has become a strategic pillar. However, significant gaps exist regarding the implementation of up-to-date international frameworks within specific business environments. Against this backdrop, this analysis of the ISO/IEC 27001:2022 standard addresses a genuine sectoral need arising from deficiencies in structured information security management. The absence of established processes considerably increases exposure to incidents that compromise operational continuity, institutional trust, and the protection of sensitive data (Alassaf & Alkhalifah, 2021). Grounded in an academic and disciplinary perspective, this research justifies its undertaking by synthesizing and systematizing the practical application of the ISO/IEC 27001:2022 standard within an organizational context. The study adds value to the field through the analytical identification of security gaps, the evaluation of updated controls (including the new controls in Annex A), and the proposal of conceptual guidelines aimed at risk mitigation. Thus, this monograph not only seeks to structure a threat prevention model but also establishes the theoretical and methodological foundations to drive continuous improvement processes and support informed decision-making (Andersson et al., 2022). The knowledge generated by this study directly benefits information security professionals and systems auditors in the productive sector by offering them an analytical framework to assess and strengthen their organizations. Furthermore, it serves as a reference for the academic community interested in management. | |
| dc.description.degreelevel | Pregrado | spa |
| dc.description.degreename | Ingeniero Informático | spa |
| dc.description.domain | http://www.ustatunja.edu.co/investigacion | |
| dc.format.mimetype | application/pdf | |
| dc.identifier.citation | Bermúdez Núñez, S. R. (2026). Guía Práctica para la Implementación de ISO/IEC 27001 [Trabajo de Grado, Universidad Santo Tomás].Repositorio Institucional | |
| dc.identifier.instname | instname:Universidad Santo Tomás | spa |
| dc.identifier.reponame | reponame:Repositorio Institucional Universidad Santo Tomás | spa |
| dc.identifier.repourl | repourl:https://repository.usta.edu.co | spa |
| dc.identifier.uri | http://hdl.handle.net/11634/74498 | |
| dc.language.iso | spa | |
| dc.publisher | Universidad Santo Tomás | spa |
| dc.publisher.branch | CRAI-USTA Tunja | |
| dc.publisher.faculty | Facultad de Ingeniería de Sistemas | spa |
| dc.publisher.program | Ingeniería Informática | spa |
| dc.relation.references | Abeykoonge, K. (2024). Organizational culture influence on ISO 27001 implementation. ResearchGate. https://www.researchgate.net/publication/391181885 | |
| dc.relation.references | Abroshan, H., Devos, J., Poels, G., & Laermans, E. (2021). Phishing happens beyond technology: The effects of human behaviors and demographics on each step of a phishing process. IEEE Access, 9, 44928–44949. https://doi.org/10.1109/ACCESS.2021.3066383 | |
| dc.relation.references | Advisera. (2024). ISO 27001 clause 9.3 – Management review. 27001Academy. https://advisera.com/iso27001/clause-9-3-management-review/ | |
| dc.relation.references | Advisera. (2024). ISO 27001 risk assessment & risk treatment: The complete guide. 27001Academy. https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/ | |
| dc.relation.references | Al-Amiri, A., et al. (2024). Adoption of new technologies in university environments and its impact on information security. Al-Kut College Journal. https://js.alkutcollege.edu.iq/article_24703.html | |
| dc.relation.references | Alassaf, N., & Alkhalifah, A. (2021). Exploring the influence of direct and indirect factors on information security policy compliance: A systematic literature review. IEEE Access, 9, 162687–162705. https://doi.org/10.1109/ACCESS.2021.3132574 | |
| dc.relation.references | Aljuaid, T. A. A. M., Abdul Wahab, A. W., & Idris, M. Y. I. (2023). Systematic literature review on security access control policies and techniques based on privacy requirements in a BYOD environment: State of the art and future directions. Applied Sciences, 13(14), 8048. https://doi.org/10.3390/app13148048 | |
| dc.relation.references | Almorsy, M., Grundy, J., & Müller, I. (2018). ISCP: In-depth model for selecting critical security controls. Computers & Security, 77, 565–577. https://doi.org/10.1016/j.cose.2018.05.009 Andersson, A., Hedström, K., & Karlsson, F. (2022). Standardizing information security: A structurational analysis. Information & Management, 59(3), 103623. https://doi.org/10.1016/j.im.2022.103623 | |
| dc.relation.references | Angelini, M., et al. (2022). Security gaps and policy updates in IT companies. arXiv. https://arxiv.org/abs/2207.03269 | |
| dc.relation.references | Annarelli, A., Battistella, C., & Nonino, F. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/TQM-09-2020-0202 | |
| dc.relation.references | Arumdiya, R., & Rudianto, R. (2025). Training deficiencies and their impact on information security management systems. ResearchGate. https://www.researchgate.net/publication/394151106 | |
| dc.relation.references | Assolin, J., Kreutz, D., & Bertholdo, L. M. (2025). IoTEdu: Access control, detection, and automatic incident response in academic IoT networks. arXiv. https://doi.org/10.48550/arXiv.2512.09934 | |
| dc.relation.references | AES Tech. (2026). ISO 27001: Clause 10 – Improvement. AES Tech. Consultar fuente | |
| dc.relation.references | Ayinoluwa, O. (2024). Organizational factors affecting governance and ISO standards adoption. ResearchGate. https://www.researchgate.net/publication/380129833 | |
| dc.relation.references | Bada, M., Sasse, A. M., & Nurse, J. R. C. (2015). Cyber security awareness campaigns: Why do they fail to change behaviour? International Conference on Cyber Security for Sustainable Society, 118 131. https://ora.ox.ac.uk/objects/uuid:cfed4907-d32a-4450-b075-ad37477b10d8 Biswas, P. (2022, diciembre 8). ISO 27001:2022 A.5.2 Information security roles and responsibilities. PRETESH BISWAS. https://preteshbiswas.com/2022/12/08/a-5-2-information-security-roles-and responsibilities/ | |
| dc.relation.references | Chai, K. Y., & Zolkipli, M. F. (2021). Review on confidentiality, integrity and availability in information security. Journal of ICT in Education, 8(2), 34–42. https://doi.org/10.37134/jictie.vol8.2.4.2021 | |
| dc.relation.references | Chávez, D., et al. (2024). Information security in internet service companies. IEEE. https://www.researchgate.net/publication/379162806 | |
| dc.relation.references | Chen, H., & Hai, Y. (2024). Exploring the critical success factors of information security management: A mixed-method approach. Information and Computer Security, 32(5), 545–572. https://doi.org/10.1108/ICS-03-2023-0034 | |
| dc.relation.references | Culot, G., Nassimbeni, G., Orzes, G., & Sartor, M. (2021). Behind the definition of ISO 27001 information security management systems: A literature review. Computers & Security, 103, 102192. https://doi.org/10.1016/j.cose.2021.102192 | |
| dc.relation.references | Confluence IEEE Study. (2024). Risk methodologies for ISMS implementation. IEEE Xplore. https://ieeexplore.ieee.org/document/10463392 | |
| dc.relation.references | Domínguez, J., et al. (2023). Organizational factors in ISO 27001 implementation. arXiv. https://arxiv.org/abs/2306.11050 | |
| dc.relation.references | Domínguez, J., et al. (2023b). Organizational chall | |
| dc.relation.references | Domínguez, J., et al. (2023b). Organizational challenges in ISO implementation. EasyChair. https://easychair.org/publications/preprint/wS2G | |
| dc.relation.references | Domínguez-Domínguez, J., López, A., & Martínez, F. (2023). Organizational leadership and security awareness gaps in higher education institutions. arXiv. https://arxiv.org/abs/2306.11050 | |
| dc.relation.references | Financial Institution ISO Study. (2024). ISO 27001 integration in banking sector. IEEE Xplore. https://ieeexplore.ieee.org/document/10569415 | |
| dc.relation.references | Fujs, D., Mihelič, A., & Vrhovec, S. L. R. (2025). Implementing and integrating security controls: A practitioners’ perspective. Computers & Security, 156, 104516. https://doi.org/10.1016/j.cose.2025.104516 | |
| dc.relation.references | González-Granadillo, G., González-Zarzosa, S., & Diaz, R. (2021). Security information and event management (SIEM): Analysis, trends, and usage in critical infrastructures. Sensors, 21(14), 4759. https://doi.org/10.3390/s21144759 | |
| dc.relation.references | Hernandez, L., Pranolo, A., & Wibawa, A. P. (2024). Implementation plan of the information security management system based on the NTC-ISO-IEC 27001:2013 standard and security risk analysis: Case study: Higher education institution. Transactions on Energy Systems and Engineering | |
| dc.relation.references | Applications, 5(2), 1–20. https://doi.org/10.32397/tesea.vol5.n2.635 Horne, C. A., Maynard, S. B., & Ahmad, A. (2022). A survey on empirical security analysis of access control systems: A real-world perspective. ACM Computing Surveys, 55(6), 1–36. https://doi.org/10.1145/3533703 | |
| dc.relation.references | International Organization for Standardization. (2022). ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org/standard/27001.html | |
| dc.relation.references | Jevelin, R., & Faza, M. (2023). Early stages of ISMS implementation in private organizations. Journal of Information Systems and Informatics. https://journal-isi.org/index.php/isi/article/view/572 | |
| dc.relation.references | Kamil, M., Hallikainen, P., et al. (2023). Organizational knowledge and ISO 27001 adoption challenges. Information Systems and e-Business Management. https://doi.org/10.1007/s10257-023 00646-y | |
| dc.relation.references | Kamil, Y., Lund, S., & Islam, M. S. (2023). Information security objectives and the output legitimacy of ISO/IEC 27001: Stakeholders’ perspective on expectations in private organizations in Sweden. Information Systems and e-Business Management, 21, 699–722. https://doi.org/10.1007/s10257-023 00646-y | |
| dc.relation.references | López-Vasco, J., et al. (2025). Structured approaches for ISO 27001 implementation in technology companies. IEEE. https://www.researchgate.net/publication/390369079 | |
| dc.relation.references | Niemeläinen, T., et al. (2024). Resource allocation issues in technology companies. arXiv. https://arxiv.org/abs/2409.19029 | |
| dc.relation.references | Ramadhan, A., & Sopiah, S. (2024). Security breaches in transportation sector organizations. UNESA Journal. https://ejournal.unesa.ac.id/index.php/jdbim/article/view/65912 | |
| dc.relation.references | Reuben-Owoh, B., & Haig, E. (2025). A systematic review of voluntary cybersecurity standards and frameworks. International Journal of Information Security, 24, Article 206. https://doi.org/10.1007/s10207-025-01121-0 | |
| dc.relation.references | Rietveld, J., Slob, E., & van Kalmthout, R. (2022). What drives the growth of start-up firms? A tool for mapping the state-of-the-art of the empirical literature. Journal of Business Venturing Insights, 18, e00345. https://doi.org/10.1016/j.jbvi.2022.e00345 Ryanto, R., & Tundjungsari, V. (2024). Data leakage risks in banking institutions. ResearchGate. https://www.researchgate.net/publication/383041040 | |
| dc.relation.references | Shekhawat, A. S., Di Troia, F., & Stamp, M. (2019). Feature analysis of encrypted malicious traffic. Expert Systems with Applications, 125, 130–141. https://doi.org/10.1016/j.eswa.2019.01.064 Shen, B. (2023). A survey of access control misconfiguration detection techniques. arXiv. https://doi.org/10.48550/arXiv.2304.07704 Silva, E. M., Abreu, A., & Pires, G. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & Security, 99, 102030. https://doi.org/10.1016/j.cose.2020.102030 | |
| dc.relation.references | Suorsa, M., & Helo, P. (2024). Information security failures identified and measured: ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis. Information Security Journal: A Global Perspective, 33(3), 285–306. https://doi.org/10.1080/19393555.2023.2270984 | |
| dc.relation.references | Syafitri, W., Shukur, Z., Mokhtar, U. A., Sulaiman, R., & Ibrahim, M. A. (2022). Social engineering attacks prevention: A systematic literature review. IEEE Access, 10, 39325–39343. https://doi.org/10.1109/ACCESS.2022.3164739 | |
| dc.relation.references | Tanadi, T., et al. (2021). External audits and ISMS continuous improvement in ISO 27001 certified organizations. Reaksi. https://journals.ums.ac.id/index.php/reaksi/article/view/15146 | |
| dc.relation.references | Warkentin, M., & Orgeron, C. (2020). Using the security triad to assess ransomware risks. International Journal of Information Management, 52, 102090. https://doi.org/10.1016/j.ijinfomgt.2020.102090 | |
| dc.relation.references | Wibowo, A., & Aji, P. (2024). ISMS implementation in healthtech organizations. IJCS. https://www.ijcs.net/ijcs/index.php/ijcs/article/view/4166 | |
| dc.relation.references | Wijayarathne, W. (2022). ISO 27001 implementation in laboratory environments. ResearchGate. https://www.researchgate.net/publication/372523436 | |
| dc.relation.references | Zammani, M., & Razali, R. (2016). An empirical study of information security management success factors. International Journal on Advanced Science, Engineering and Information Technology, 6(6), 904–913. https://doi.org/10.18517/ijaseit.6.6.1371 | |
| dc.relation.references | Zhang, Z., He, W., Li, W., & Abdous, M. H. (2021). Cybersecurity awareness training programs: A cost–benefit analysis framework. Industrial Management & Data Systems, 121(3), 613–636. https://doi.org/10.1108/IMDS-06-2020-0321 | |
| dc.rights | Attribution-NonCommercial-NoDerivs 2.5 Colombia | en |
| dc.rights.accessrights | info:eu-repo/semantics/openAccess | |
| dc.rights.coar | http://purl.org/coar/access_right/c_abf2 | |
| dc.rights.local | Abierto (Texto Completo) | spa |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/2.5/co/ | |
| dc.subject.keyword | Information Security | |
| dc.subject.keyword | Cybersecurity Systems | |
| dc.subject.keyword | Auditing Systems Information | |
| dc.subject.keyword | Technology Management | |
| dc.subject.keyword | Information Systems | |
| dc.subject.proposal | ISO/IEC 27001:2022 | |
| dc.subject.proposal | Seguridad de la información | |
| dc.subject.proposal | Sistema de Gestión de Seguridad de la Información (SGSI) | |
| dc.subject.proposal | Gestión de riesgos | |
| dc.subject.proposal | Controles de seguridad | |
| dc.subject.proposal | Implementación | |
| dc.subject.proposal | Factores críticos de éxito | |
| dc.title | Guía Práctica para la Implementación de ISO/IEC 27001 | |
| dc.type | bachelor thesis | |
| dc.type.coar | http://purl.org/coar/resource_type/c_7a1f | |
| dc.type.coarversion | http://purl.org/coar/version/c_ab4af688f83e57aa | |
| dc.type.drive | info:eu-repo/semantics/bachelorThesis | |
| dc.type.local | Trabajo de grado | spa |
| dc.type.version | info:eu-repo/semantics/acceptedVersion |
Archivos
Bloque original
1 - 3 de 3
Cargando...
- Nombre:
- Autorización facultad
- Tamaño:
- 301.33 KB
- Formato:
- Adobe Portable Document Format
Cargando...
- Nombre:
- Autorización estudiante
- Tamaño:
- 849.12 KB
- Formato:
- Adobe Portable Document Format
Bloque de licencias
1 - 1 de 1
Cargando...
- Nombre:
- license.txt
- Tamaño:
- 807 B
- Formato:
- Item-specific license agreed upon to submission
- Descripción:

