Guía Práctica para la Implementación de ISO/IEC 27001

dc.contributor.advisorContreras Ortiz , Martha Susana
dc.contributor.authorBermudez Nuñez, Samuel Ricardo
dc.contributor.corporatenameUniversidad Santo Tomás
dc.contributor.cvlachttps://scienti.minciencias.gov.co/cvlac/visualizador/generarCurriculoCv.do?cod_rh=0000901571
dc.contributor.googlescholarhttps://scholar.google.com.co/citations?user=L45gJqUAAAAJ&hl=es&oi=ao
dc.contributor.orcidhttps://orcid.org/0000-0002-7715-6420
dc.date.accessioned2026-10-08T15:04:07Z
dc.date.available2026-10-08T15:04:07Z
dc.date.issued2026-10-06
dc.descriptionEn el contexto tecnológico actual, definido por el incremento en las ciberamenazas y la acelerada transformación digital de las organizaciones, el resguardo de los activos de información se ha convertido en un pilar estratégico. Sin embargo, existen vacíos significativos respecto a la realización de marcos internacionales actualizados en entornos empresariales concretos. En este escenario concreto, la elaboración del presente análisis sobre la norma ISO/IEC 27001:2022 da una respuesta a una necesidad sectorial real, que desemboca de las carencias en la gestión estructurada de la seguridad de la información. La ausencia de procesos establecidos incrementa de manera considerable la exposición a incidentes que comprometen la continuidad operativa, la confianza institucional y la custodia de datos sensibles (Alassaf & Alkhalifah, 2021). Gracias a una perspectiva académica y disciplinar, esta investigación justifica su desarrollo al sintetizar y sistematizar la aplicación práctica del estándar ISO/IEC 27001:2022 en el contexto organizacional. El trabajo da un valor al conocimiento mediante la identificación analítica de brechas de seguridad, la evaluación de controles actualizados (incluidos los nuevos controles del Anexo A) y la propuesta de lineamientos conceptuales que tienen como fin la mitigación del riesgo. De este modo, la monografía no solo tiene como fin estructurar un modelo de prevención de amenazas, sino que a su vez establece bases teóricas y metodológicas para impulsa procesos de mejora continua y respaldar la toma de decisiones informadas (Andersson et al., 2022). El conocimiento resultado en este estudio da como beneficio directamente a profesionales del área de la seguridad de la información, auditores de sistemas dentro del sector productivo, ofreciéndoles un marco de referencia analítico para diagnosticar y fortalecer sus empresas. Asimismo, sirve como fuente de consulta para la comunidad académica interesada en la gestión
dc.description.abstractIn the current technological landscape—defined by rising cyber threats and the accelerated digital transformation of organizations—safeguarding information assets has become a strategic pillar. However, significant gaps exist regarding the implementation of up-to-date international frameworks within specific business environments. Against this backdrop, this analysis of the ISO/IEC 27001:2022 standard addresses a genuine sectoral need arising from deficiencies in structured information security management. The absence of established processes considerably increases exposure to incidents that compromise operational continuity, institutional trust, and the protection of sensitive data (Alassaf & Alkhalifah, 2021). Grounded in an academic and disciplinary perspective, this research justifies its undertaking by synthesizing and systematizing the practical application of the ISO/IEC 27001:2022 standard within an organizational context. The study adds value to the field through the analytical identification of security gaps, the evaluation of updated controls (including the new controls in Annex A), and the proposal of conceptual guidelines aimed at risk mitigation. Thus, this monograph not only seeks to structure a threat prevention model but also establishes the theoretical and methodological foundations to drive continuous improvement processes and support informed decision-making (Andersson et al., 2022). The knowledge generated by this study directly benefits information security professionals and systems auditors in the productive sector by offering them an analytical framework to assess and strengthen their organizations. Furthermore, it serves as a reference for the academic community interested in management.
dc.description.degreelevelPregradospa
dc.description.degreenameIngeniero Informáticospa
dc.description.domainhttp://www.ustatunja.edu.co/investigacion
dc.format.mimetypeapplication/pdf
dc.identifier.citationBermúdez Núñez, S. R. (2026). Guía Práctica para la Implementación de ISO/IEC 27001 [Trabajo de Grado, Universidad Santo Tomás].Repositorio Institucional
dc.identifier.instnameinstname:Universidad Santo Tomásspa
dc.identifier.reponamereponame:Repositorio Institucional Universidad Santo Tomásspa
dc.identifier.repourlrepourl:https://repository.usta.edu.cospa
dc.identifier.urihttp://hdl.handle.net/11634/74498
dc.language.isospa
dc.publisherUniversidad Santo Tomásspa
dc.publisher.branchCRAI-USTA Tunja
dc.publisher.facultyFacultad de Ingeniería de Sistemasspa
dc.publisher.programIngeniería Informáticaspa
dc.relation.referencesAbeykoonge, K. (2024). Organizational culture influence on ISO 27001 implementation. ResearchGate. https://www.researchgate.net/publication/391181885
dc.relation.referencesAbroshan, H., Devos, J., Poels, G., & Laermans, E. (2021). Phishing happens beyond technology: The effects of human behaviors and demographics on each step of a phishing process. IEEE Access, 9, 44928–44949. https://doi.org/10.1109/ACCESS.2021.3066383
dc.relation.referencesAdvisera. (2024). ISO 27001 clause 9.3 – Management review. 27001Academy. https://advisera.com/iso27001/clause-9-3-management-review/
dc.relation.referencesAdvisera. (2024). ISO 27001 risk assessment & risk treatment: The complete guide. 27001Academy. https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/
dc.relation.referencesAl-Amiri, A., et al. (2024). Adoption of new technologies in university environments and its impact on information security. Al-Kut College Journal. https://js.alkutcollege.edu.iq/article_24703.html
dc.relation.referencesAlassaf, N., & Alkhalifah, A. (2021). Exploring the influence of direct and indirect factors on information security policy compliance: A systematic literature review. IEEE Access, 9, 162687–162705. https://doi.org/10.1109/ACCESS.2021.3132574
dc.relation.referencesAljuaid, T. A. A. M., Abdul Wahab, A. W., & Idris, M. Y. I. (2023). Systematic literature review on security access control policies and techniques based on privacy requirements in a BYOD environment: State of the art and future directions. Applied Sciences, 13(14), 8048. https://doi.org/10.3390/app13148048
dc.relation.referencesAlmorsy, M., Grundy, J., & Müller, I. (2018). ISCP: In-depth model for selecting critical security controls. Computers & Security, 77, 565–577. https://doi.org/10.1016/j.cose.2018.05.009 Andersson, A., Hedström, K., & Karlsson, F. (2022). Standardizing information security: A structurational analysis. Information & Management, 59(3), 103623. https://doi.org/10.1016/j.im.2022.103623
dc.relation.referencesAngelini, M., et al. (2022). Security gaps and policy updates in IT companies. arXiv. https://arxiv.org/abs/2207.03269
dc.relation.referencesAnnarelli, A., Battistella, C., & Nonino, F. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/TQM-09-2020-0202
dc.relation.referencesArumdiya, R., & Rudianto, R. (2025). Training deficiencies and their impact on information security management systems. ResearchGate. https://www.researchgate.net/publication/394151106
dc.relation.referencesAssolin, J., Kreutz, D., & Bertholdo, L. M. (2025). IoTEdu: Access control, detection, and automatic incident response in academic IoT networks. arXiv. https://doi.org/10.48550/arXiv.2512.09934
dc.relation.referencesAES Tech. (2026). ISO 27001: Clause 10 – Improvement. AES Tech. Consultar fuente
dc.relation.referencesAyinoluwa, O. (2024). Organizational factors affecting governance and ISO standards adoption. ResearchGate. https://www.researchgate.net/publication/380129833
dc.relation.referencesBada, M., Sasse, A. M., & Nurse, J. R. C. (2015). Cyber security awareness campaigns: Why do they fail to change behaviour? International Conference on Cyber Security for Sustainable Society, 118 131. https://ora.ox.ac.uk/objects/uuid:cfed4907-d32a-4450-b075-ad37477b10d8 Biswas, P. (2022, diciembre 8). ISO 27001:2022 A.5.2 Information security roles and responsibilities. PRETESH BISWAS. https://preteshbiswas.com/2022/12/08/a-5-2-information-security-roles-and responsibilities/
dc.relation.referencesChai, K. Y., & Zolkipli, M. F. (2021). Review on confidentiality, integrity and availability in information security. Journal of ICT in Education, 8(2), 34–42. https://doi.org/10.37134/jictie.vol8.2.4.2021
dc.relation.referencesChávez, D., et al. (2024). Information security in internet service companies. IEEE. https://www.researchgate.net/publication/379162806
dc.relation.referencesChen, H., & Hai, Y. (2024). Exploring the critical success factors of information security management: A mixed-method approach. Information and Computer Security, 32(5), 545–572. https://doi.org/10.1108/ICS-03-2023-0034
dc.relation.referencesCulot, G., Nassimbeni, G., Orzes, G., & Sartor, M. (2021). Behind the definition of ISO 27001 information security management systems: A literature review. Computers & Security, 103, 102192. https://doi.org/10.1016/j.cose.2021.102192
dc.relation.referencesConfluence IEEE Study. (2024). Risk methodologies for ISMS implementation. IEEE Xplore. https://ieeexplore.ieee.org/document/10463392
dc.relation.referencesDomínguez, J., et al. (2023). Organizational factors in ISO 27001 implementation. arXiv. https://arxiv.org/abs/2306.11050
dc.relation.referencesDomínguez, J., et al. (2023b). Organizational chall
dc.relation.referencesDomínguez, J., et al. (2023b). Organizational challenges in ISO implementation. EasyChair. https://easychair.org/publications/preprint/wS2G
dc.relation.referencesDomínguez-Domínguez, J., López, A., & Martínez, F. (2023). Organizational leadership and security awareness gaps in higher education institutions. arXiv. https://arxiv.org/abs/2306.11050
dc.relation.referencesFinancial Institution ISO Study. (2024). ISO 27001 integration in banking sector. IEEE Xplore. https://ieeexplore.ieee.org/document/10569415
dc.relation.referencesFujs, D., Mihelič, A., & Vrhovec, S. L. R. (2025). Implementing and integrating security controls: A practitioners’ perspective. Computers & Security, 156, 104516. https://doi.org/10.1016/j.cose.2025.104516
dc.relation.referencesGonzález-Granadillo, G., González-Zarzosa, S., & Diaz, R. (2021). Security information and event management (SIEM): Analysis, trends, and usage in critical infrastructures. Sensors, 21(14), 4759. https://doi.org/10.3390/s21144759
dc.relation.referencesHernandez, L., Pranolo, A., & Wibawa, A. P. (2024). Implementation plan of the information security management system based on the NTC-ISO-IEC 27001:2013 standard and security risk analysis: Case study: Higher education institution. Transactions on Energy Systems and Engineering
dc.relation.referencesApplications, 5(2), 1–20. https://doi.org/10.32397/tesea.vol5.n2.635 Horne, C. A., Maynard, S. B., & Ahmad, A. (2022). A survey on empirical security analysis of access control systems: A real-world perspective. ACM Computing Surveys, 55(6), 1–36. https://doi.org/10.1145/3533703
dc.relation.referencesInternational Organization for Standardization. (2022). ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org/standard/27001.html
dc.relation.referencesJevelin, R., & Faza, M. (2023). Early stages of ISMS implementation in private organizations. Journal of Information Systems and Informatics. https://journal-isi.org/index.php/isi/article/view/572
dc.relation.referencesKamil, M., Hallikainen, P., et al. (2023). Organizational knowledge and ISO 27001 adoption challenges. Information Systems and e-Business Management. https://doi.org/10.1007/s10257-023 00646-y
dc.relation.referencesKamil, Y., Lund, S., & Islam, M. S. (2023). Information security objectives and the output legitimacy of ISO/IEC 27001: Stakeholders’ perspective on expectations in private organizations in Sweden. Information Systems and e-Business Management, 21, 699–722. https://doi.org/10.1007/s10257-023 00646-y
dc.relation.referencesLópez-Vasco, J., et al. (2025). Structured approaches for ISO 27001 implementation in technology companies. IEEE. https://www.researchgate.net/publication/390369079
dc.relation.referencesNiemeläinen, T., et al. (2024). Resource allocation issues in technology companies. arXiv. https://arxiv.org/abs/2409.19029
dc.relation.referencesRamadhan, A., & Sopiah, S. (2024). Security breaches in transportation sector organizations. UNESA Journal. https://ejournal.unesa.ac.id/index.php/jdbim/article/view/65912
dc.relation.referencesReuben-Owoh, B., & Haig, E. (2025). A systematic review of voluntary cybersecurity standards and frameworks. International Journal of Information Security, 24, Article 206. https://doi.org/10.1007/s10207-025-01121-0
dc.relation.referencesRietveld, J., Slob, E., & van Kalmthout, R. (2022). What drives the growth of start-up firms? A tool for mapping the state-of-the-art of the empirical literature. Journal of Business Venturing Insights, 18, e00345. https://doi.org/10.1016/j.jbvi.2022.e00345 Ryanto, R., & Tundjungsari, V. (2024). Data leakage risks in banking institutions. ResearchGate. https://www.researchgate.net/publication/383041040
dc.relation.referencesShekhawat, A. S., Di Troia, F., & Stamp, M. (2019). Feature analysis of encrypted malicious traffic. Expert Systems with Applications, 125, 130–141. https://doi.org/10.1016/j.eswa.2019.01.064 Shen, B. (2023). A survey of access control misconfiguration detection techniques. arXiv. https://doi.org/10.48550/arXiv.2304.07704 Silva, E. M., Abreu, A., & Pires, G. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & Security, 99, 102030. https://doi.org/10.1016/j.cose.2020.102030
dc.relation.referencesSuorsa, M., & Helo, P. (2024). Information security failures identified and measured: ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis. Information Security Journal: A Global Perspective, 33(3), 285–306. https://doi.org/10.1080/19393555.2023.2270984
dc.relation.referencesSyafitri, W., Shukur, Z., Mokhtar, U. A., Sulaiman, R., & Ibrahim, M. A. (2022). Social engineering attacks prevention: A systematic literature review. IEEE Access, 10, 39325–39343. https://doi.org/10.1109/ACCESS.2022.3164739
dc.relation.referencesTanadi, T., et al. (2021). External audits and ISMS continuous improvement in ISO 27001 certified organizations. Reaksi. https://journals.ums.ac.id/index.php/reaksi/article/view/15146
dc.relation.referencesWarkentin, M., & Orgeron, C. (2020). Using the security triad to assess ransomware risks. International Journal of Information Management, 52, 102090. https://doi.org/10.1016/j.ijinfomgt.2020.102090
dc.relation.referencesWibowo, A., & Aji, P. (2024). ISMS implementation in healthtech organizations. IJCS. https://www.ijcs.net/ijcs/index.php/ijcs/article/view/4166
dc.relation.referencesWijayarathne, W. (2022). ISO 27001 implementation in laboratory environments. ResearchGate. https://www.researchgate.net/publication/372523436
dc.relation.referencesZammani, M., & Razali, R. (2016). An empirical study of information security management success factors. International Journal on Advanced Science, Engineering and Information Technology, 6(6), 904–913. https://doi.org/10.18517/ijaseit.6.6.1371
dc.relation.referencesZhang, Z., He, W., Li, W., & Abdous, M. H. (2021). Cybersecurity awareness training programs: A cost–benefit analysis framework. Industrial Management & Data Systems, 121(3), 613–636. https://doi.org/10.1108/IMDS-06-2020-0321
dc.rightsAttribution-NonCommercial-NoDerivs 2.5 Colombiaen
dc.rights.accessrightsinfo:eu-repo/semantics/openAccess
dc.rights.coarhttp://purl.org/coar/access_right/c_abf2
dc.rights.localAbierto (Texto Completo)spa
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/2.5/co/
dc.subject.keywordInformation Security
dc.subject.keywordCybersecurity Systems
dc.subject.keywordAuditing Systems Information
dc.subject.keywordTechnology Management
dc.subject.keywordInformation Systems
dc.subject.proposalISO/IEC 27001:2022
dc.subject.proposalSeguridad de la información
dc.subject.proposalSistema de Gestión de Seguridad de la Información (SGSI)
dc.subject.proposalGestión de riesgos
dc.subject.proposalControles de seguridad
dc.subject.proposalImplementación
dc.subject.proposalFactores críticos de éxito
dc.titleGuía Práctica para la Implementación de ISO/IEC 27001
dc.typebachelor thesis
dc.type.coarhttp://purl.org/coar/resource_type/c_7a1f
dc.type.coarversionhttp://purl.org/coar/version/c_ab4af688f83e57aa
dc.type.driveinfo:eu-repo/semantics/bachelorThesis
dc.type.localTrabajo de gradospa
dc.type.versioninfo:eu-repo/semantics/acceptedVersion

Archivos

Bloque original

Mostrando 1 - 3 de 3
Cargando...
Miniatura
Nombre:
2026SamuelBermudez
Tamaño:
1.58 MB
Formato:
Adobe Portable Document Format
Cargando...
Miniatura
Nombre:
Autorización facultad
Tamaño:
301.33 KB
Formato:
Adobe Portable Document Format
Cargando...
Miniatura
Nombre:
Autorización estudiante
Tamaño:
849.12 KB
Formato:
Adobe Portable Document Format

Bloque de licencias

Mostrando 1 - 1 de 1
Cargando...
Miniatura
Nombre:
license.txt
Tamaño:
807 B
Formato:
Item-specific license agreed upon to submission
Descripción: