El equipo formado por los investigadores Sánchez, L.E., Villafranca, D., Fernández Medina, E. y Piattini, M. y con la colaboración de la división de ciberseguridad MARISMA del grupo Sicaman, ha participado con un artículo denominado Practical Application of a Security Management Maturity Model for SMEs Based on Predefined Schemas dentro del  International Conference on Security and Cryptography (SECRYPT08), Porto, Portugal, Julio, 2008,  Pp. 391-398. ISBN: 978-989-8111-59-3, IDSNumber: BIE55, EID: 2-s2.0-58049181431, WOS: 000258929000061. Core: B.

Este documento forma parte de los avances e investigaciones en el campo de la Ciberseguridad desarrolladas por el Grupo GSyA y la división de seguridad MARISMA del Grupo Sicaman.

For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system and tools which allow them to manage it. In small and medium-sized enterprises, the application of security standards has an additional problem, which is the fact that they do not have enough resources to carry out an appropriate management. This security management system must have highly reduced costs for its implementation and maintenance in small and medium-sized enterprises (from here on refered to as SMEs) to be feasible. In this paper we show the practical application of our proposal for a maturity model with which to manage the security in SMEs, centring upon the phase which determines the state of the enterprise and some of the mechanisms which allow the security level to be kept up to date without the need for continuous audits. This focus is continuously refined through its application to real cases, the results of which are shown in this paper.


