Publicación: CyberTrack 360: una guía de autodiagnóstico para pymes basada en ISO/IEC 27001
| dc.contributor.advisor | López Castrillón, William | |
| dc.contributor.author | Tovar Perea, Flor Alba | |
| dc.contributor.author | Aguirre Cañón, Jhon Fredy | |
| dc.creator.id | 35531387 | |
| dc.creator.id | 1031180880 | |
| dc.date.accessioned | 2026-06-29T23:38:42Z | |
| dc.date.issued | 2026-06-11 | |
| dc.description.abstract | La creciente dependencia de los sistemas digitales ha incrementado la exposición de las microempresas a riesgos relacionados con la seguridad de la información. Aunque existen marcos reconocidos internacionalmente como ISO/IEC 27001, ISO/IEC 27002 y NIST Cybersecurity Framework, su complejidad dificulta su adopción en organizaciones con recursos limitados. En este contexto, el objetivo de la investigación fue diseñar y evaluar un producto mínimo viable (MVP) denominado CyberTrack 360, orientado a facilitar el diagnóstico inicial de madurez en seguridad de la información y la adopción progresiva de controles esenciales en microempresas colombianas. La investigación se desarrolló bajo un enfoque mixto, alcance descriptivo y diseño no experimental transversal, apoyado en la metodología Design Science Research Methodology (DSRM). Se aplicó una encuesta a 50 propietarios y cargos gerenciales de microempresas para identificar necesidades, barreras y percepciones relacionadas con la ciberseguridad. Los resultados evidenciaron que el 82% de los participantes considera que la pérdida de acceso a la información tendría un impacto alto o muy alto en sus operaciones, mientras que solo el 28% percibe una alta probabilidad de sufrir incidentes. Asimismo, se identificaron bajos niveles de adopción de controles básicos, predominando barreras asociadas a la falta de conocimiento técnico (72%), desconocimiento sobre cómo iniciar (68%) y percepción de altos costos (54%). A partir de estos hallazgos se desarrolló CyberTrack 360, una plataforma web basada en cuestionarios por roles, evaluación de madurez, generación de recomendaciones priorizadas, gestión de evidencias y políticas básicas de seguridad. Los resultados obtenidos respaldan la hipótesis de que las microempresas requieren herramientas prácticas, comprensibles y accesibles para facilitar la adopción de controles de seguridad. Se concluye que CyberTrack 360 constituye una alternativa viable para reducir la brecha entre el conocimiento de buenas prácticas y su implementación efectiva, promoviendo una cultura de mejora continua en organizaciones con recursos limitados. | spa |
| dc.description.abstract | The increasing reliance on digital systems has heightened microenterprises’ exposure to risks related to information security. Although internationally recognized frameworks such as ISO/IEC 27001, ISO/IEC 27002, and the NIST Cybersecurity Framework exist, their complexity makes them difficult to adopt in organizations with limited resources. In this context, the objective of this research was to design and evaluate a minimum viable product (MVP) called CyberTrack 360, aimed at facilitating the initial assessment of information security maturity and the progressive adoption of essential security controls in Colombian microenterprises. The research was conducted using a mixed-method approach with a descriptive scope and a non-experimental cross-sectional design, supported by the Design Science Research Methodology (DSRM). A survey was administered to 50 owners and managerial personnel of microenterprises to identify cybersecurity needs, barriers, and perceptions. The results revealed that 82% of participants considered the loss of access to information to have a high or very high operational impact, while only 28% perceived a high probability of experiencing a cybersecurity incident. Additionally, low levels of adoption of basic security controls were identified, with the main barriers being lack of technical knowledge (72%), uncertainty about how to begin (68%), and perceived implementation costs (54%). Based on these findings, CyberTrack 360 was developed as a web-based platform incorporating role-based questionnaires, maturity assessment, prioritized recommendations, evidence management, and basic security policies. The results support the hypothesis that microenterprises require practical, understandable, and affordable tools to facilitate the adoption of information security controls. It is concluded that CyberTrack 360 represents a viable alternative to reduce the gap between awareness of best practices and their effective implementation, promoting a culture of continuous improvement in organizations with limited resources. | eng |
| dc.description.degreelevel | Pregrado | |
| dc.description.degreename | Ingeniero de Sistemas | |
| dc.format | ||
| dc.format.extent | 100 páginas | |
| dc.format.medium | Recurso electrónico | spa |
| dc.format.mimetype | application/pdf | |
| dc.identifier.instname | instname:Universidad Ean | spa |
| dc.identifier.local | BDM-FISV | spa |
| dc.identifier.reponame | reponame:Repositorio Institucional Biblioteca Digital Minerva | spa |
| dc.identifier.repourl | https://repository.ean.edu.co/ | |
| dc.identifier.uri | https://hdl.handle.net/10882/19346 | |
| dc.language.iso | spa | |
| dc.relation.references | Adriko, R., & Nurse, J. R. C. (2026). Cybersecurity and Cyber insurance for Small to Medium-sized Enterprises (SMEs): Perceptions, challenges and decision-making dynamics. Computers & Security, 163, 104818. https://doi.org/10.1016/j.cose.2025.104818 Azinheira, B., Antunes, M., Maximiano, M., & Gomes, R. (2023). A methodology for mapping cybersecurity standards into governance guidelines for SME in Portugal. Procedia Computer Science, 219, 121–128. https://doi.org/10.1016/j.procs.2023.01.272 Bada, M. & Nurse J. R. C. (2019). Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs). Emerald insight, 27, 3. https://www.emerald.com/ics/article-abstract/27/3/393/105969/Developing-cybersecurity-education-and-awareness?redirectedFrom=fulltext Barreras, R., Elja, G., Posada, A., y Daza, F. (2012). Ley 1581 de 2012 (Régimen general de protección de datos personales). https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=49981 CIS. (2024). CIS Critical Security Controls. http://www.cisecurity.org/controls/ Creswell, J. & Creswell J. (2018). Research Design: Qualitative, Quantitative, and Mixed Methods Approaches (5th edition). Sage Publications, Inc. Drata. (2026a). Compliance automation platform (SOC 2, ISO 27001, HIPAA). https://drata.com/compliance Drata. (2026b). Expand global reach by accelerating ISO 27001:2022. https://drata.com/product/iso-27001 Edwards, Max. (2026). Best ISO 27001 Compliance Software. https://www.isms.online/compliance-software/ Gundu, T., & Mmango, N. (2026). Password Hygiene Guidelines for SMEs in South Africa: A Systematic Literature Review (pp. 287–298). https://doi.org/10.1007/978-3-032-12999-4_26 Hao, C., Jiajia, F., & Tu, L. (2026). Manager information security-related stress and organizational information security performance. Emerald Publishing. https://doi.org/10.1108/MD-10-2024-2308 Hernández, R., Fernández, C., y Baptista, M. (2018). Metodología de la Investigación (Sexta edición.). McGraw-Hill Education. Hevner, Alan., March, Salvatore., Park, Jinsoo., & Ram, Sudha. (2004). Design Science in Information Systems Research. https://misq.umn.edu/misq/article-abstract/28/1/75/261/Design-Science-in-Information-Systems-Research1?redirectedFrom=fulltext Humphreys, Edward. (2025). Implementing the ISO/IEC 27001 Information Security Management System Standard. https://books.google.hn/books?hl=es&lr=&id=5s_BEQAAQBAJ&oi=fnd&pg=PR13&dq=Humphreys+2025+27001&ots=qAL3YYFYpU&sig=sbXWNLIJFLML3LUQyHPL_-VpDNw&redir_esc=y#v=onepage&q=Humphreys%202025%2027001&f=false IBM. (2025). Cost of a Data Breach Report 2025 The AI Oversight Gap think report. ISO TOOLS. (2026a). Auditoria con casos reales a través de un software ISO. https://isotools.org/2026/02/17/auditoria-con-casos-reales/ ISO TOOLS. (2026b). Beneficios del software ISO 27001 La gestión de la Seguridad de la Información, más ágil que nunca. https://isotools.org/software/riesgos-y-seguridad/iso-27001/ ISO/IEC. (2022a). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. https://www.iso.org/es/norma/27001 ISO/IEC. (2022b). ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls. https://www.iso.org/standard/75652.html Microsoft. (2025). Microsoft Digital Defense Report 2025. https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/ NIST. (2024a). NIST cybersecurity framework 2.0: https://doi.org/10.6028/NIST.SP.1300.spa NIST, G. M. (2024b). Spanish Translation of the NIST Cybersecurity Framework 2.0. https://doi.org/10.6028/NIST.CSWP.29.spa OECD. (2026). SMEs and entrepreneurship. https://www.oecd.org/en/topics/smes-and-entrepreneurship.html OWASP Foundation. (2025). OWASP Top 10:2025. https://owasp.org/Top10/2025/ Peffers, Ken., Tuunanen, Tuure., Rothenberger, Marcus., & Chatterjee, Samir. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302 Peters, Sam. (2025). Statement of Applicability (SoA): The Complete Guide. https://www.isms.online/iso-27001/statement-of-applicability/ Rombaldo, Carlos., Becker, Ingolf., & Johnson, Shane. (2023). Unaware, Unfunded and Uneducated: A Systematic Review of SME Cybersecurity. https://arxiv.org/html/2309.17186v1#S1 Santos, Juan. (2013). Decreto 1377 de 2013 (Reglamenta parcialmente la Ley 1581 de 2012). https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=53646 Santos, Juan. (2014). Decreto 886 de 2014 (Registro Nacional de Bases de Datos – RNBD). https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=57338 Sarri, Anna., Paggio, Viktor., & Bafoutsou, Georgia. (2021). Cybersecurity for SMEs : challenges and recommendations. [Publications Office of the European Union]. Scytale. (2026). Where compliance happens. https://scytale.ai/ Secureframe. (2026a). ISO 27001 Automatice el cumplimiento de la norma ISO 27001. https://secureframe.com/frameworks/iso-27001 Secureframe. (2026b). ISO 27001 Evidence Collection List for Your Certification Audit. https://secureframe.com/hub/iso-27001/evidence-list Sprinto. (2026a). Do a lot more with a lot less. https://sprinto.com/automate-evidence-collection/ Sprinto. (2026b). ISO 27001 Gaining your ISO 27001 Certification Evidence Collection. https://sprinto.com/hub/iso-27001-evidence-collection/ Tan Jia Jun, Dennis., Rafsanjani, Ahmad., Aslam, Saad., & Behjati, Mehran. (2025). Human Factors in Information Security: A Qantitative Study with Technical Solutions to Prevent Social Engineering Atacks. https://dl.acm.org/doi/full/10.1145/3767320 Thoropass. (2026). Global business starts here Unlock new markets and build trust with streamlined ISO 27001 software. https://www.thoropass.com/frameworks/iso-27001 Venkatesh, V., Thong, J., & Xu, X. (2016). Unified Theory of Acceptance and Use of Technology: A Synthesis and the Road Ahead. Journal of the Association for Information Systems, 17(5), 328–376. https://doi.org/10.17705/1jais.00428 Verizon. (2025). 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf World Bank Group. (2026). SME Finance. https://www.worldbank.org/ext/en/topic/competitiveness/small-and-medium-enterprises-smes-finance?utm | |
| dc.rights.accessrights | info:eu-repo/semantics/openAccess | |
| dc.rights.coar | http://purl.org/coar/access_right/c_abf2 | |
| dc.rights.creativecommons | Atribución-NoComercial-CompartirIgual 4.0 Internacional (CC BY-NC-SA 4.0) | |
| dc.rights.license | Atribución-NoComercial-CompartirIgual 4.0 Internacional (CC BY-NC-SA 4.0) | |
| dc.rights.local | Abierto (Texto Completo) | spa |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-sa/4.0/ | |
| dc.subject.armarc | Seguridad informática | spa |
| dc.subject.armarc | Protección de datos | spa |
| dc.subject.armarc | Sistemas de seguridad | spa |
| dc.subject.armarc | Seguridad de bases de datos | spa |
| dc.subject.lemb | Pequeña y mediana empresa | spa |
| dc.subject.proposal | Ciberseguridad | |
| dc.subject.proposal | Microempresas | |
| dc.subject.proposal | ISO 27001 | |
| dc.subject.proposal | Cybersecurity | |
| dc.subject.proposal | Microenterprises | |
| dc.subject.proposal | SGSI | |
| dc.title | CyberTrack 360: una guía de autodiagnóstico para pymes basada en ISO/IEC 27001 | spa |
| dc.title | CyberTrack 360: a self-assessment guide for SMEs based on ISO/IEC 27001 | eng |
| dc.type | Trabajo de grado - Pregrado | |
| dc.type.coar | http://purl.org/coar/resource_type/c_7a1f | |
| dc.type.coarversion | http://purl.org/coar/version/c_ab4af688f83e57aa | |
| dc.type.content | Text | |
| dc.type.driver | info:eu-repo/semantics/bachelorThesis | |
| dc.type.other | Trabajo de grado - Pregrado | |
| dc.type.redcol | http://purl.org/redcol/resource_type/TP | |
| dc.type.version | info:eu-repo/semantics/acceptedVersion | |
| dspace.entity.type | Publication | |
| person.affiliation.name | Ingeniería de Sistemas - Virtual | |
| person.affiliation.name | Ingeniería de Sistemas - Virtual |
Archivos
Bloque de licencias
1 - 1 de 1
Cargando...
- Nombre:
- license.txt
- Tamaño:
- 1.92 KB
- Formato:
- Item-specific license agreed upon to submission
- Descripción:
