Publicación:
CyberTrack 360: una guía de autodiagnóstico para pymes basada en ISO/IEC 27001

dc.contributor.advisorLópez Castrillón, William
dc.contributor.authorTovar Perea, Flor Alba
dc.contributor.authorAguirre Cañón, Jhon Fredy
dc.creator.id35531387
dc.creator.id1031180880
dc.date.accessioned2026-06-29T23:38:42Z
dc.date.issued2026-06-11
dc.description.abstractLa creciente dependencia de los sistemas digitales ha incrementado la exposición de las microempresas a riesgos relacionados con la seguridad de la información. Aunque existen marcos reconocidos internacionalmente como ISO/IEC 27001, ISO/IEC 27002 y NIST Cybersecurity Framework, su complejidad dificulta su adopción en organizaciones con recursos limitados. En este contexto, el objetivo de la investigación fue diseñar y evaluar un producto mínimo viable (MVP) denominado CyberTrack 360, orientado a facilitar el diagnóstico inicial de madurez en seguridad de la información y la adopción progresiva de controles esenciales en microempresas colombianas. La investigación se desarrolló bajo un enfoque mixto, alcance descriptivo y diseño no experimental transversal, apoyado en la metodología Design Science Research Methodology (DSRM). Se aplicó una encuesta a 50 propietarios y cargos gerenciales de microempresas para identificar necesidades, barreras y percepciones relacionadas con la ciberseguridad. Los resultados evidenciaron que el 82% de los participantes considera que la pérdida de acceso a la información tendría un impacto alto o muy alto en sus operaciones, mientras que solo el 28% percibe una alta probabilidad de sufrir incidentes. Asimismo, se identificaron bajos niveles de adopción de controles básicos, predominando barreras asociadas a la falta de conocimiento técnico (72%), desconocimiento sobre cómo iniciar (68%) y percepción de altos costos (54%). A partir de estos hallazgos se desarrolló CyberTrack 360, una plataforma web basada en cuestionarios por roles, evaluación de madurez, generación de recomendaciones priorizadas, gestión de evidencias y políticas básicas de seguridad. Los resultados obtenidos respaldan la hipótesis de que las microempresas requieren herramientas prácticas, comprensibles y accesibles para facilitar la adopción de controles de seguridad. Se concluye que CyberTrack 360 constituye una alternativa viable para reducir la brecha entre el conocimiento de buenas prácticas y su implementación efectiva, promoviendo una cultura de mejora continua en organizaciones con recursos limitados.spa
dc.description.abstractThe increasing reliance on digital systems has heightened microenterprises’ exposure to risks related to information security. Although internationally recognized frameworks such as ISO/IEC 27001, ISO/IEC 27002, and the NIST Cybersecurity Framework exist, their complexity makes them difficult to adopt in organizations with limited resources. In this context, the objective of this research was to design and evaluate a minimum viable product (MVP) called CyberTrack 360, aimed at facilitating the initial assessment of information security maturity and the progressive adoption of essential security controls in Colombian microenterprises. The research was conducted using a mixed-method approach with a descriptive scope and a non-experimental cross-sectional design, supported by the Design Science Research Methodology (DSRM). A survey was administered to 50 owners and managerial personnel of microenterprises to identify cybersecurity needs, barriers, and perceptions. The results revealed that 82% of participants considered the loss of access to information to have a high or very high operational impact, while only 28% perceived a high probability of experiencing a cybersecurity incident. Additionally, low levels of adoption of basic security controls were identified, with the main barriers being lack of technical knowledge (72%), uncertainty about how to begin (68%), and perceived implementation costs (54%). Based on these findings, CyberTrack 360 was developed as a web-based platform incorporating role-based questionnaires, maturity assessment, prioritized recommendations, evidence management, and basic security policies. The results support the hypothesis that microenterprises require practical, understandable, and affordable tools to facilitate the adoption of information security controls. It is concluded that CyberTrack 360 represents a viable alternative to reduce the gap between awareness of best practices and their effective implementation, promoting a culture of continuous improvement in organizations with limited resources.eng
dc.description.degreelevelPregrado
dc.description.degreenameIngeniero de Sistemas
dc.formatpdf
dc.format.extent100 páginas
dc.format.mediumRecurso electrónicospa
dc.format.mimetypeapplication/pdf
dc.identifier.instnameinstname:Universidad Eanspa
dc.identifier.localBDM-FISVspa
dc.identifier.reponamereponame:Repositorio Institucional Biblioteca Digital Minervaspa
dc.identifier.repourlhttps://repository.ean.edu.co/
dc.identifier.urihttps://hdl.handle.net/10882/19346
dc.language.isospa
dc.relation.referencesAdriko, R., & Nurse, J. R. C. (2026). Cybersecurity and Cyber insurance for Small to Medium-sized Enterprises (SMEs): Perceptions, challenges and decision-making dynamics. Computers & Security, 163, 104818. https://doi.org/10.1016/j.cose.2025.104818 Azinheira, B., Antunes, M., Maximiano, M., & Gomes, R. (2023). A methodology for mapping cybersecurity standards into governance guidelines for SME in Portugal. Procedia Computer Science, 219, 121–128. https://doi.org/10.1016/j.procs.2023.01.272 Bada, M. & Nurse J. R. C. (2019). Developing cybersecurity education and awareness programmes for small- and medium-sized enterprises (SMEs). Emerald insight, 27, 3. https://www.emerald.com/ics/article-abstract/27/3/393/105969/Developing-cybersecurity-education-and-awareness?redirectedFrom=fulltext Barreras, R., Elja, G., Posada, A., y Daza, F. (2012). Ley 1581 de 2012 (Régimen general de protección de datos personales). https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=49981 CIS. (2024). CIS Critical Security Controls. http://www.cisecurity.org/controls/ Creswell, J. & Creswell J. (2018). Research Design: Qualitative, Quantitative, and Mixed Methods Approaches (5th edition). Sage Publications, Inc. Drata. (2026a). Compliance automation platform (SOC 2, ISO 27001, HIPAA). https://drata.com/compliance Drata. (2026b). Expand global reach by accelerating ISO 27001:2022. https://drata.com/product/iso-27001 Edwards, Max. (2026). Best ISO 27001 Compliance Software. https://www.isms.online/compliance-software/ Gundu, T., & Mmango, N. (2026). Password Hygiene Guidelines for SMEs in South Africa: A Systematic Literature Review (pp. 287–298). https://doi.org/10.1007/978-3-032-12999-4_26 Hao, C., Jiajia, F., & Tu, L. (2026). Manager information security-related stress and organizational information security performance. Emerald Publishing. https://doi.org/10.1108/MD-10-2024-2308 Hernández, R., Fernández, C., y Baptista, M. (2018). Metodología de la Investigación (Sexta edición.). McGraw-Hill Education. Hevner, Alan., March, Salvatore., Park, Jinsoo., & Ram, Sudha. (2004). Design Science in Information Systems Research. https://misq.umn.edu/misq/article-abstract/28/1/75/261/Design-Science-in-Information-Systems-Research1?redirectedFrom=fulltext Humphreys, Edward. (2025). Implementing the ISO/IEC 27001 Information Security Management System Standard. https://books.google.hn/books?hl=es&lr=&id=5s_BEQAAQBAJ&oi=fnd&pg=PR13&dq=Humphreys+2025+27001&ots=qAL3YYFYpU&sig=sbXWNLIJFLML3LUQyHPL_-VpDNw&redir_esc=y#v=onepage&q=Humphreys%202025%2027001&f=false IBM. (2025). Cost of a Data Breach Report 2025 The AI Oversight Gap think report. ISO TOOLS. (2026a). Auditoria con casos reales a través de un software ISO. https://isotools.org/2026/02/17/auditoria-con-casos-reales/ ISO TOOLS. (2026b). Beneficios del software ISO 27001 La gestión de la Seguridad de la Información, más ágil que nunca. https://isotools.org/software/riesgos-y-seguridad/iso-27001/ ISO/IEC. (2022a). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. https://www.iso.org/es/norma/27001 ISO/IEC. (2022b). ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls. https://www.iso.org/standard/75652.html Microsoft. (2025). Microsoft Digital Defense Report 2025. https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/ NIST. (2024a). NIST cybersecurity framework 2.0: https://doi.org/10.6028/NIST.SP.1300.spa NIST, G. M. (2024b). Spanish Translation of the NIST Cybersecurity Framework 2.0. https://doi.org/10.6028/NIST.CSWP.29.spa OECD. (2026). SMEs and entrepreneurship. https://www.oecd.org/en/topics/smes-and-entrepreneurship.html OWASP Foundation. (2025). OWASP Top 10:2025. https://owasp.org/Top10/2025/ Peffers, Ken., Tuunanen, Tuure., Rothenberger, Marcus., & Chatterjee, Samir. (2007). A design science research methodology for information systems research. Journal of Management Information Systems, 24(3), 45–77. https://doi.org/10.2753/MIS0742-1222240302 Peters, Sam. (2025). Statement of Applicability (SoA): The Complete Guide. https://www.isms.online/iso-27001/statement-of-applicability/ Rombaldo, Carlos., Becker, Ingolf., & Johnson, Shane. (2023). Unaware, Unfunded and Uneducated: A Systematic Review of SME Cybersecurity. https://arxiv.org/html/2309.17186v1#S1 Santos, Juan. (2013). Decreto 1377 de 2013 (Reglamenta parcialmente la Ley 1581 de 2012). https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=53646 Santos, Juan. (2014). Decreto 886 de 2014 (Registro Nacional de Bases de Datos – RNBD). https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=57338 Sarri, Anna., Paggio, Viktor., & Bafoutsou, Georgia. (2021). Cybersecurity for SMEs : challenges and recommendations. [Publications Office of the European Union]. Scytale. (2026). Where compliance happens. https://scytale.ai/ Secureframe. (2026a). ISO 27001 Automatice el cumplimiento de la norma ISO 27001. https://secureframe.com/frameworks/iso-27001 Secureframe. (2026b). ISO 27001 Evidence Collection List for Your Certification Audit. https://secureframe.com/hub/iso-27001/evidence-list Sprinto. (2026a). Do a lot more with a lot less. https://sprinto.com/automate-evidence-collection/ Sprinto. (2026b). ISO 27001 Gaining your ISO 27001 Certification Evidence Collection. https://sprinto.com/hub/iso-27001-evidence-collection/ Tan Jia Jun, Dennis., Rafsanjani, Ahmad., Aslam, Saad., & Behjati, Mehran. (2025). Human Factors in Information Security: A Qantitative Study with Technical Solutions to Prevent Social Engineering Atacks. https://dl.acm.org/doi/full/10.1145/3767320 Thoropass. (2026). Global business starts here Unlock new markets and build trust with streamlined ISO 27001 software. https://www.thoropass.com/frameworks/iso-27001 Venkatesh, V., Thong, J., & Xu, X. (2016). Unified Theory of Acceptance and Use of Technology: A Synthesis and the Road Ahead. Journal of the Association for Information Systems, 17(5), 328–376. https://doi.org/10.17705/1jais.00428 Verizon. (2025). 2025 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf World Bank Group. (2026). SME Finance. https://www.worldbank.org/ext/en/topic/competitiveness/small-and-medium-enterprises-smes-finance?utm
dc.rights.accessrightsinfo:eu-repo/semantics/openAccess
dc.rights.coarhttp://purl.org/coar/access_right/c_abf2
dc.rights.creativecommonsAtribución-NoComercial-CompartirIgual 4.0 Internacional (CC BY-NC-SA 4.0)
dc.rights.licenseAtribución-NoComercial-CompartirIgual 4.0 Internacional (CC BY-NC-SA 4.0)
dc.rights.localAbierto (Texto Completo)spa
dc.rights.urihttps://creativecommons.org/licenses/by-nc-sa/4.0/
dc.subject.armarcSeguridad informáticaspa
dc.subject.armarcProtección de datosspa
dc.subject.armarcSistemas de seguridadspa
dc.subject.armarcSeguridad de bases de datosspa
dc.subject.lembPequeña y mediana empresaspa
dc.subject.proposalCiberseguridad
dc.subject.proposalMicroempresas
dc.subject.proposalISO 27001
dc.subject.proposalCybersecurity
dc.subject.proposalMicroenterprises
dc.subject.proposalSGSI
dc.titleCyberTrack 360: una guía de autodiagnóstico para pymes basada en ISO/IEC 27001spa
dc.titleCyberTrack 360: a self-assessment guide for SMEs based on ISO/IEC 27001eng
dc.typeTrabajo de grado - Pregrado
dc.type.coarhttp://purl.org/coar/resource_type/c_7a1f
dc.type.coarversionhttp://purl.org/coar/version/c_ab4af688f83e57aa
dc.type.contentText
dc.type.driverinfo:eu-repo/semantics/bachelorThesis
dc.type.otherTrabajo de grado - Pregrado
dc.type.redcolhttp://purl.org/redcol/resource_type/TP
dc.type.versioninfo:eu-repo/semantics/acceptedVersion
dspace.entity.typePublication
person.affiliation.nameIngeniería de Sistemas - Virtual
person.affiliation.nameIngeniería de Sistemas - Virtual

Archivos

Bloque original

Mostrando 1 - 2 de 2
Cargando...
Miniatura
Nombre:
TovarFlor2026.pdf
Tamaño:
2.16 MB
Formato:
Adobe Portable Document Format
Descripción:
Trabajo de Grado
Cargando...
Miniatura
Nombre:
TovarFlor2026_Anexo.pdf
Tamaño:
337.47 KB
Formato:
Adobe Portable Document Format
Descripción:
Autorización Publicación

Bloque de licencias

Mostrando 1 - 1 de 1
Cargando...
Miniatura
Nombre:
license.txt
Tamaño:
1.92 KB
Formato:
Item-specific license agreed upon to submission
Descripción: