IT Security Balanced Scorecard based on ISO 27001:2022
DOI:
https://doi.org/10.61961/injei.v3i1.23Keywords:
Monitoring, Dashboard, Computer security, ISO, 27001:2022Abstract
The growing need to protect the IT systems of telecommunications companies drives the development of monitoring tools based on international standards. This paper presents the development of an endpoint-oriented IT security Balanced Scorecard (BSC) based on the ISO 27001:2022 standard, in order to implement and monitor security controls in a telecommunications company. The main objective is to design a KPI visualisation system using Power BI that allows real-time evaluation of the specific security requirements of the standard. This work analyses the requirements of ISO 27001:2022 relevant to endpoints, selects key indicators based on the controls of the standard, also develops the BSC with tools that ensure the availability and usability of the data, and finally validates the effectiveness of the BSC against the stipulated security standards. It is concluded that the adoption of a Balanced Scorecard based on ISO 27001:2022 not only facilitates real-time decision making, but also reinforces the organisational culture oriented towards information protection, promoting business continuity and user and customer confidence.
Downloads
References
B. Krumay, E. W. Bernroider, and R. Walser, “Evaluation of cybersecurity management controls and metrics of critical infrastructures: A literature review considering the nist cybersecurity framework,” in Secure IT Systems: 23rd Nordic Conference, NordSec 2018, Oslo, Norway, November 28-30, 2018, Proceedings 23. Springer, 2018, pp. 369–384. DOI: https://doi.org/10.1007/978-3-030-03638-6_23
A. Michelena, “Ministerio de telecomunicaciones y de la socidad de la informaci´on,” Quito, Pichincha, Ecuador. Obtenido de https://www. telecomunicaciones. gob. ec/wp-content/uploads/2020/06/ACUERDO- MINISTERIAL-12-signed-1.pdf, 2020
J. Brenner, “Iso 27001 risk management and compliance.” Risk management, vol. 54, no. 1, pp. 24–29, 2007.
M. I. Ladino, P. A. Villa, and A. L. E. Mar´ıa, “Funda- mentos de iso 27001 y su aplicaci´on en las empresas,” Scientia et technica, vol. 1, no. 47, pp. 334–339, 2011.
F. Morales, S. Toapanta, and R. M. Toasa, “Implementaci´on de un sistema de seguridad perimetral como estrategia de seguridad de la informaci´on,” Revista Iber- ica de sistemas e tecnolog´ıas de informacao, no. E27, pp. 553–565, 2020
D. A. Hern´andez Mera, “Dise˜no de un esquema de seguridad inform´atica para el ´area de sistematizaci´on de la universidad israel, aplicando iso 27002 y csf de nits.” Master’s thesis, Quito, Ecuador: Universidad Tecnol´ogica Israel, 2023
D. Pont´on Cevallos, “Progresismo y tecnolog´ıa policial: an´alisis del boom punitivo en ecuador,” Perfiles latinoamericanos, vol. 31, no. 62, 2023. DOI: https://doi.org/10.18504/pl3162-006-2023
E. R. Armenta and A. L. I. Carrillo, “Towards an implementation of information technologies governance,” in 2022 IEEE Mexican International Conference on Computer Science (ENC). IEEE, 2022, pp. 1–6. DOI: https://doi.org/10.1109/ENC56672.2022.9882923
E. Falc´on Huallpa and E. J. Mart´ınez Zambrano, “Propuesta de mejora para la gesti´on de seguridad de la informaci´on sgsi bajo normas iso 27001, para el departamento de an´alisis de telecomunicaciones de la unidad nacional de telecomunicaci´on m´ovil”(quito-ecuador),” 2023.
C. Schr¨oer, F. Kruse, and J. M. G´omez, “A systematic literature review on applying crisp-dm process model,” Procedia Computer Science, vol. 181, pp. 526–534, 2021. DOI: https://doi.org/10.1016/j.procs.2021.01.199
Toasa, Renato, et al. "Data visualization techniques for real-time information—A custom and dynamic dashboard for analyzing surveys' results." 2018 13th Iberian Conference on Information Systems and Technologies (CISTI). IEEE, 2018. DOI: https://doi.org/10.23919/CISTI.2018.8398641
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Jorge Luis Velasco T´eran, Renato Toasa

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License 4.0 that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.
