International Journal of Engineering Insights: (2025) Vol. 3, Nro.1, Regular Paper
https://doi.org/10.61961/injei.v3i1.23
IT Security Balanced Scorecard based on ISO 27001:2022
Jorge Luis Velasco eran · Renato M. Toasa
Received: 10 May 2025 / Accepted: 25 Sep 2025 / Published: 15 Nov 2025
Abstract: The growing need to protect the IT sys-
tems of telecommunications companies drives the de-
velopment of monitoring tools based on international
standards. This paper presents the development of an
endpoint-oriented IT security Balanced Scorecard (BSC)
based on the ISO 27001:2022 standard, in order to im-
plement and monitor security controls in a telecom-
munications company. The main objective is to design
a KPI visualisation system using Power BI that al-
lows real-time evaluation of the specific security require-
ments of the standard. This work analyses the require-
ments of ISO 27001:2022 relevant to endpoints, selects
key indicators based on the controls of the standard,
also develops the BSC with tools that ensure the avail-
ability and usability of the data, and finally validates
the effectiveness of the BSC against the stipulated se-
curity standards. It is concluded that the adoption of a
Balanced Scorecard based on ISO 27001:2022 not only
facilitates real-time decision making, but also reinforces
the organisational culture oriented towards information
protection, promoting business continuity and user and
customer confidence.
Keywords Monitoring · Dashboard · Computer
security · ISO · 27001:2022
1 Introduction
The growing threat to information security in the digi-
tal realm has created an urgent need for robust regula-
tory frameworks to protect the assets and privacy of or-
ganisations. Internationally, ISO 27001:2022 has estab-
lished itself as the reference standard for the implemen-
tation of an Information Security Management System
Jorge Luis Velasco eran
Universidad Tecnol´ogica Israel
Quito, Ecuador
E-mail: e1719068098@uisrael.edu.ec
Renato M. Toasa
Universidad Tecnol´ogica Israel
Quito, Ecuador
E-mail: rtoasa@uisrael.edu.ec
(ISMS), providing a structured approach to mitigate
cyber risks. This standard has been adopted by several
global organisations, especially in sensitive sectors such
as telecommunications, where the protection of data
and critical infrastructure is crucial. Telecommunica-
tions companies, being a key communication and data
bridge, are a frequent target of cyber-attacks, underlin-
ing the importance of having effective IT security mech-
anisms in place [1]. In Ecuador, the adoption of interna-
tional cyber security standards is progressing, although
there are still significant challenges for companies, espe-
cially in the telecommunications sector, to implement
solid cyber protection frameworks. The Ley Org´anica
de Protecci´on de Datos Personales and the Reglamento
a la Ley de Telecomunicaciones are examples of national
efforts to ensure information security and privacy. How-
ever, many Ecuadorian companies still face challenges
in integrating these regulations with their internal se-
curity management systems[2] . This article proposes
the implementation of a Balanced Scorecard (BSC) for
IT security, based on ISO 27001:2022, as an effective
solution to address these challenges. By integrating key
performance indicators (KPIs) tailored to the needs of
the telecommunications sector, the BSC can provide
a comprehensive tool for risk monitoring, policy com-
pliance assessment and strategic decision making. This
approach not only responds to global security needs,
but also to the particularities of the Ecuadorian en-
vironment, enabling telecommunications companies to
improve their ability to respond to security incidents
and strengthen the confidence of their users.
1.1 Related Works
A review of the literature in scientific databases found
the following related studies.
ISO 27001 is a globally recognised standard for infor-
mation security management. Its adoption enables or-
ganisations to effectively manage the risks associated
with cybersecurity and protect critical information as-
sets. The latest version, ISO 27001:2022, incorporates
2 International Journal of Engineering Insights, (2025) 3:1
improvements in risk management and provides a more
flexible framework to adapt to emerging cyber threats.
Several studies highlight the benefits of implementing
this standard, especially in increasing resilience to cyber-
attacks and improving data privacy management. Ac-
cording to one study [3], Organisations that adopt ISO
27001 experience greater effectiveness in protecting their
digital infrastructure and strengthening their compli-
ance processes.
The telecommunications sector, due to its essential
role in the transmission of data and services, is par-
ticularly exposed to cyber risks, such as attacks on its
critical infrastructure and data theft. The implementa-
tion of international standards such as ISO 27001 in this
sector has been shown to improve IT security manage-
ment. Telecommunications companies that adopt these
standards are said to significantly improve operational
efficiency and the protection of their networks [4]. In
[5] conclude that the adoption of security frameworks
also facilitates compliance with international regula-
tions, which increases the competitiveness of companies
in the global marketplace.
In Ecuador, although there are legislative advances,
such as the Organic Law on Personal Data Protection
and the Regulation to the Telecommunications Law,
there are still challenges in the effective implementation
of security frameworks in companies in the telecommu-
nications sector. According to the Ministry of Telecom-
munications of Ecuador[2], Ecuadorian companies face
obstacles such as lack of technical training and integra-
tion of security policies with national regulatory frame-
works. In the academy, research has also been carried
out on the proposed topic. For example, a degree project
of an Ecuadorian University proposes an Information
Security Management System based on the ISO 27000:
2013 standard, which will protect the integrity, avail-
ability and confidentiality of information [6], On the
other hand, state institutions also address an Integral
Command Control (CMI) Policy of Use, carried out by
the Ministry of Government, Police and Worship, in
coordination with the National Police, as a fundamen-
tal actor of the Citizen Security Policy, have assumed
the commitment to self-evaluate the operational man-
agement of the police institution to examine strategies
associated with result goals with respect to crime be-
haviour and the application of efficient and timely ac-
tions for the prevention and control of crime, as well
as to evaluate their effectiveness on an ongoing basis,
taking the necessary corrective measures to achieve the
strengthening of Citizen Security[7]. In this context, a
Balanced Scorecard (BSC) based on ISO 27001 offers
an effective solution for monitoring security risks and
aligning these indicators with strategic objectives. It
should be noted that BSCs allow for a comprehensive
measurement of organisational performance, facilitat-
ing decision making and the implementation of secu-
rity policies. In the field of IT security, a BSC adapted
to ISO 27001 helps to manage technological risks and
improves organisational transparency[8].
Studies as in [9] The results show that the inte-
gration of ISO 27001 with a BSC in the telecommu-
nications sector improves the effectiveness of decision-
making and facilitates the alignment of security efforts
with business objectives, which contributes to better
protection of information assets.
The document is organized as follows: Section 1 in-
cludes the Introduction, Section 2 the Methodology,
Section 3 the Proposal, and Section 4 the Conclusions.
2 Methodology
2.1 Research methodology
For the development of an ISO 27001:2022-based ‘Bal-
anced Scorecard for Endpoint Security (BSCSS) for a
telecommunications company’, the following research
process will be used:
Qualitative research approach The choice of a
qualitative research approach is justified by the com-
plex nature of the topic and the need to gain a com-
prehensive and general understanding, allowing both
the individual experiences and perceptions of partici-
pants to be explored, thus providing valuable insights
and in-depth understanding. By integrating these per-
spectives into the Information Security Balanced Score-
card, a more complete and contextualised view of the
challenges, practices and opportunities related to infor-
mation security will be obtained, identifying areas for
improvement, adapting strategies and making decisions
to strengthen information security in the enterprise [9].
Convenience sampling Convenience sampling is jus-
tified by the difficulty of accessing a specific population,
such as computer security experts and professionals in
the telecommunications sector. Since these individuals
are limited in number and not always readily available,
convenience sampling allows for flexible selection of par-
ticipants, taking advantage of available connections and
contacts.
This facilitates sample formation without requiring
a specific population frame and allows for a variety of
perspectives relevant to the study.
Interview-based research technique Semi- struc-
tured interviews with information security experts and
telecommunications professionals will provide detailed
insights into the specific challenges and implementa-
tion requirements of the Balanced Scorecard. These in-
3 International Journal of Engineering Insights, (2025) 3:1
terviews will enable an in-depth exploration of partici-
pants’ experiences and perspectives.
2.2 CRISP-DM Methodology
The cross-industry standard process for data mining
(CRISPDM) is a framework for translating business
problems into data mining tasks and carrying out data
mining projects independent of both the application
area and the used technology [3]. It is a widely adopted
industry-oriented implementation of the generic Knowl-
edge Discovery (KD) process, as described in [10].
Fig. 1 CRISP-DM Phases.
The phases of the CRISP-DM methodology are:
1. Phase 1: Understanding the Business
2. Phase 2: Understanding the data
3. Phase 3: Data Preparation
4. Phase 4: Modelling
5. Phase 5: Evaluation
6. Phase 6. Deployment
3 Proposal
3.1 Development of CRISP DM phases
Phase 1: Understanding the Business In order to
better understand the requirements that are required
by the company’s staff in terms of IT security and com-
pliance with ISO 27001:2022, the following activities are
necessary:
Meetings with IT security experts and company pro-
fessionals, in order to conduct interviews to obtain
an overview of the problems that exist and to bet-
ter understand the requirements of the PC Infras-
tructure staff, in order to provide solutions to the
current problems in this area.
Review and analysis of the ISO 27001:2022 standard
in line with the company’s requirements.
Phase 2: Understanding the data In order to
understand all the information involved in the devel-
opment of the CMISPF, it is necessary to identify the
data that will be used and the source of the data, the
files that will be used are detailed below:
Security Console: Microsoft Intune, Microsoft De-
fender, Active Directory
PC formatting file
Service desk formatting ticket information
Application tickets USB whitelist
Application Tickets for Local Administrator Users
Phase 3: Data Preparations Once the sources
of information have been identified, it is necessary to
prepare the data from these sources in order to make
them part of the CMISPF, by doing the following:
Select data that is related to compliance with ISO
27001:2022.
Perform data cleansing, i.e. rectify or remove incon-
sistent, duplicate or erroneous information.
Establish security policies and key performance in-
dicators (KPIs), which will be measured in CMISPF.
Create a centralised database, which will be fed by
the different sources of information, as detailed in
point 2 Phase 2: Understanding the data.
Verify that the data that will be part of the database
is in an appropriate format, e.g. date format, text
format, etc.
Phase 4: Modelling In order to build models for
data analysis based on the ISO 27001:2022 Standard
and to be part of the CMISPF, which will help the
monitoring and management of the IT security of a
telecommunications company, the following will be car-
ried out:
Determine the security policies and KPIs that com-
ply with ISO 27001:2022 to be monitored through
the CMISPF, which will be developed through the
Power BI tool.
Define the method of evaluation of the model, for
the development of the CMISPF the method to be
used will be through user testing with the company’s
IT security experts.
Establish the test data to be used in the develop-
ment of the CMISPF.
4 International Journal of Engineering Insights, (2025) 3:1
Phase 5: Evaluation
The evaluation of results will assess the effectiveness
of the models designed and the accuracy of the security
policies and performance indicators according to ISO
27001:2022, including:
Compare the CMISPF against the business require-
ments that were established in phase 1.
Verify that the CMISPF complies with the com-
pany’s requirements.
Phase 6. Deployment Develop the CMISPF pro-
totype, for which the following should be done:
Perform an initial design of the Balanced Scorecard,
which should include the architecture and design of
the database, dashboard structure and user inter-
faces.
Development of the main dashboards, which should
be clear, user-friendly and present information that
is relevant to the user.
Establish and configure the automatic processes that
will continue to feed the database.
Execute unit tests of the CMISPF, in order to as-
sess whether the functionality of the CMISPF cor-
responds to what is expected according to the com-
pany’s requirements.
User testing, i.e. running functional tests with the
end user, in order to make adjustments if necessary.
Implement the developed CMISPF prototype, in a
pilot environment, so that it can be used by the PC
Infrastructure area.
3.2 Proposal Architecture
The CMISPF through an automatic process will take
the information from Microsoft Intune, Microsoft De-
fender, Active Directory from cloud-type repository, PC
formatting, USB white list and local administrator users,
with which it will feed the Power BI database, with this
information the PC Infrastructure staff, through a con-
trol panel, will verify compliance with the indicators
based on the ISO 27001:2022 Standard.
In Figure 2 it can be seen that the architecture and
the main components are related so that the devel-
oper is always in contact with the information sources
(Power BI can read a large amount of data types) that
can come from different sources, it has several extra ap-
plications that can be easily incorporated into the sys-
tem, there is also an online connection for other users
who wish to access the information or its results by
means of queries.
Fig. 2 Architecture with Power BI
3.3 Computer security policies
For the development of the CMISPF, the following IT
security policies have been defined to be implemented:
Operation of anti-virus and anti-malware soft-
ware
Implementation of specialised anti-virus and anti-
malware software on all endpoints (devices).
Perform automatic software updates so that the com-
pany and its information is protected against new
virus definitions and threats.
Patches and updates procedure
Procedure for continuous application of security patches
and updates to endpoints.
Continuous monitoring of the availability of new
patches to be applied immediately.
Acceptable use policies
Definition of the use of endpoints in the company,
i.e. permitted and prohibited devices.
Access and Authentication
Only authorised personnel may be granted admin-
istrator permissions.
Test
In order to carry out a proper quality assurance
and quality control (QA) in the development of the
CMISPF, the following documents have been elabo-
rated:
Test plan: This describes the steps to be taken and
the approach to testing, in order to ensure the qual-
ity and performance of the project.
Functional tests report: In which the functional tests
carried out by the PC Infrastructure area are evi-
denced and the use of the CMISPF is authorised.
Non-functional test report: In which the technical
tests carried out by the CMISPF are evidenced.
5 International Journal of Engineering Insights, (2025) 3:1
4 Conclusions
The Endpoint Security Balanced Scorecard project was
developed based on the controls in ISO 27001:2022, thus
aligning with international standards related to IT se-
curity, which allows for control and monitoring of the
risks that may occur in the telecommunications com-
pany. The CMISPF has a centralised display of key per-
formance indicators (KPIs), for which special rules have
been established to enable operational decisions to be
taken. Power BI is a powerful technological tool that
has enabled the development of the CMISPF, which
has facilitated the visualisation of information in real
time through interactive panels and graphs in order
to make it more comprehensible for the user to inter-
pret it. Through the verification of the operation of the
CMISPF, it has been possible to validate that it com-
plies with the IT security controls established in the ISO
27001:2022 Standard and which have been requested by
the PC Infrastructure area, thus providing a tool for the
management and monitoring of IT security.
References
1. B. Krumay, E. W. Bernroider, and R. Walser, “Evalu-
ation of cybersecurity management controls and metrics
of critical infrastructures: A literature review considering
the nist cybersecurity framework,” in Secure IT Systems:
23rd Nordic Conference, NordSec 2018, Oslo, Norway,
November 28-30, 2018, Proceedings 23. Springer, 2018,
pp. 369–384.
2. A. Michelena, “Ministerio de telecomunicaciones y
de la socidad de la informaci´on,” Quito, Pichincha,
Ecuador. Obtenido de https://www. telecomunicaciones.
gob. ec/wp-content/uploads/2020/06/ACUERDO-
MINISTERIAL-12-signed-1.pdf, 2020.
3. J. Brenner, “Iso 27001 risk management and compli-
ance.” Risk management, vol. 54, no. 1, pp. 24–29, 2007.
4. M. I. Ladino, P. A. Villa, and A. L. E. Mar´ıa, “Funda-
mentos de iso 27001 y su aplicaci´on en las empresas,”
Scientia et technica, vol. 1, no. 47, pp. 334–339, 2011.
5. F. Morales, S. Toapanta, and R. M. Toasa, “Imple-
mentaci´on de un sistema de seguridad perimetral como
estrategia de seguridad de la informaci´on,” Revista Iber-
ica de sistemas e tecnolog´ıas de informacao, no. E27, pp.
553–565, 2020.
6. D. A. Hern´andez Mera, “Dise˜no de un esquema de se-
guridad inform´atica para el ´area de sistematizaci´on de
la universidad israel, aplicando iso 27002 y csf de nits.”
Master’s thesis, Quito, Ecuador: Universidad Tecnol´ogica
Israel, 2023.
7. D. Ponon Cevallos, “Progresismo y tecnolog´ıa policial:
an´alisis del boom punitivo en ecuador,” Perfiles lati-
noamericanos, vol. 31, no. 62, 2023.
8. E. R. Armenta and A. L. I. Carrillo, “Towards an im-
plementation of information technologies governance,” in
2022 IEEE Mexican International Conference on Com-
puter Science (ENC). IEEE, 2022, pp. 1–6.
9. E. Falc´on Huallpa and E. J. Mart´ınez Zambrano, “Prop-
uesta de mejora para la gesti´on de seguridad de la infor-
maci´on sgsi bajo normas iso 27001, para el departamento
de an´alisis de telecomunicaciones de la unidad nacional
de telecomunicaci´on ovil”(quito-ecuador),” 2023.
10. C. Schr¨oer, F. Kruse, and J. M. omez, “A systematic
literature review on applying crisp-dm process model,”
Procedia Computer Science, vol. 181, pp. 526–534, 2021.
License
Copyright (2025) © Jorge Luis Velasco eran and
Renato M. Toasa.
This text is protected under an international Cre-
ative Commons 4.0 license.
You are free to share, copy, and redistribute the ma-
terial in any medium or format — and adapt the docu-
ment — remix, transform, and build upon the material
for any purpose, even commercially, provided you
comply with the conditions of Attribution. You must
give appropriate credit to the original work, provide a
link to the license, and indicate if changes were made.
You may do so in any reasonable manner, but not in
a way that suggests endorsement by the licensor or ap-
proval of your use of the work.
License summary - Full text of the license