
2 International Journal of Engineering Insights, (2025) 3:1
improvements in risk management and provides a more
flexible framework to adapt to emerging cyber threats.
Several studies highlight the benefits of implementing
this standard, especially in increasing resilience to cyber-
attacks and improving data privacy management. Ac-
cording to one study [3], Organisations that adopt ISO
27001 experience greater effectiveness in protecting their
digital infrastructure and strengthening their compli-
ance processes.
The telecommunications sector, due to its essential
role in the transmission of data and services, is par-
ticularly exposed to cyber risks, such as attacks on its
critical infrastructure and data theft. The implementa-
tion of international standards such as ISO 27001 in this
sector has been shown to improve IT security manage-
ment. Telecommunications companies that adopt these
standards are said to significantly improve operational
efficiency and the protection of their networks [4]. In
[5] conclude that the adoption of security frameworks
also facilitates compliance with international regula-
tions, which increases the competitiveness of companies
in the global marketplace.
In Ecuador, although there are legislative advances,
such as the Organic Law on Personal Data Protection
and the Regulation to the Telecommunications Law,
there are still challenges in the effective implementation
of security frameworks in companies in the telecommu-
nications sector. According to the Ministry of Telecom-
munications of Ecuador[2], Ecuadorian companies face
obstacles such as lack of technical training and integra-
tion of security policies with national regulatory frame-
works. In the academy, research has also been carried
out on the proposed topic. For example, a degree project
of an Ecuadorian University proposes an Information
Security Management System based on the ISO 27000:
2013 standard, which will protect the integrity, avail-
ability and confidentiality of information [6], On the
other hand, state institutions also address an Integral
Command Control (CMI) Policy of Use, carried out by
the Ministry of Government, Police and Worship, in
coordination with the National Police, as a fundamen-
tal actor of the Citizen Security Policy, have assumed
the commitment to self-evaluate the operational man-
agement of the police institution to examine strategies
associated with result goals with respect to crime be-
haviour and the application of efficient and timely ac-
tions for the prevention and control of crime, as well
as to evaluate their effectiveness on an ongoing basis,
taking the necessary corrective measures to achieve the
strengthening of Citizen Security[7]. In this context, a
Balanced Scorecard (BSC) based on ISO 27001 offers
an effective solution for monitoring security risks and
aligning these indicators with strategic objectives. It
should be noted that BSCs allow for a comprehensive
measurement of organisational performance, facilitat-
ing decision making and the implementation of secu-
rity policies. In the field of IT security, a BSC adapted
to ISO 27001 helps to manage technological risks and
improves organisational transparency[8].
Studies as in [9] The results show that the inte-
gration of ISO 27001 with a BSC in the telecommu-
nications sector improves the effectiveness of decision-
making and facilitates the alignment of security efforts
with business objectives, which contributes to better
protection of information assets.
The document is organized as follows: Section 1 in-
cludes the Introduction, Section 2 the Methodology,
Section 3 the Proposal, and Section 4 the Conclusions.
2 Methodology
2.1 Research methodology
For the development of an ISO 27001:2022-based ‘Bal-
anced Scorecard for Endpoint Security (BSCSS) for a
telecommunications company’, the following research
process will be used:
Qualitative research approach The choice of a
qualitative research approach is justified by the com-
plex nature of the topic and the need to gain a com-
prehensive and general understanding, allowing both
the individual experiences and perceptions of partici-
pants to be explored, thus providing valuable insights
and in-depth understanding. By integrating these per-
spectives into the Information Security Balanced Score-
card, a more complete and contextualised view of the
challenges, practices and opportunities related to infor-
mation security will be obtained, identifying areas for
improvement, adapting strategies and making decisions
to strengthen information security in the enterprise [9].
Convenience sampling Convenience sampling is jus-
tified by the difficulty of accessing a specific population,
such as computer security experts and professionals in
the telecommunications sector. Since these individuals
are limited in number and not always readily available,
convenience sampling allows for flexible selection of par-
ticipants, taking advantage of available connections and
contacts.
This facilitates sample formation without requiring
a specific population frame and allows for a variety of
perspectives relevant to the study.
Interview-based research technique Semi- struc-
tured interviews with information security experts and
telecommunications professionals will provide detailed
insights into the specific challenges and implementa-
tion requirements of the Balanced Scorecard. These in-