IT Security Balanced Scorecard based on ISO 27001:2022

Authors

DOI:

https://doi.org/10.61961/injei.v3i1.23

Keywords:

Monitoring, Dashboard, Computer security, ISO, 27001:2022

Abstract

The growing need to protect the IT systems of telecommunications companies drives the development of monitoring tools based on international standards. This paper presents the development of an endpoint-oriented IT security Balanced Scorecard (BSC) based on the ISO 27001:2022 standard, in order to implement and monitor security controls in a telecommunications company. The main objective is to design a KPI visualisation system using Power BI that allows real-time evaluation of the specific security requirements of the standard. This work analyses the requirements of ISO 27001:2022 relevant to endpoints, selects key indicators based on the controls of the standard, also develops the BSC with tools that ensure the availability and usability of the data, and finally validates the effectiveness of the BSC against the stipulated security standards. It is concluded that the adoption of a Balanced Scorecard based on ISO 27001:2022 not only facilitates real-time decision making, but also reinforces the organisational culture oriented towards information protection, promoting business continuity and user and customer confidence.

Downloads

Download data is not yet available.

References

B. Krumay, E. W. Bernroider, and R. Walser, “Evaluation of cybersecurity management controls and metrics of critical infrastructures: A literature review considering the nist cybersecurity framework,” in Secure IT Systems: 23rd Nordic Conference, NordSec 2018, Oslo, Norway, November 28-30, 2018, Proceedings 23. Springer, 2018, pp. 369–384. DOI: https://doi.org/10.1007/978-3-030-03638-6_23

A. Michelena, “Ministerio de telecomunicaciones y de la socidad de la informaci´on,” Quito, Pichincha, Ecuador. Obtenido de https://www. telecomunicaciones. gob. ec/wp-content/uploads/2020/06/ACUERDO- MINISTERIAL-12-signed-1.pdf, 2020

J. Brenner, “Iso 27001 risk management and compliance.” Risk management, vol. 54, no. 1, pp. 24–29, 2007.

M. I. Ladino, P. A. Villa, and A. L. E. Mar´ıa, “Funda- mentos de iso 27001 y su aplicaci´on en las empresas,” Scientia et technica, vol. 1, no. 47, pp. 334–339, 2011.

F. Morales, S. Toapanta, and R. M. Toasa, “Implementaci´on de un sistema de seguridad perimetral como estrategia de seguridad de la informaci´on,” Revista Iber- ica de sistemas e tecnolog´ıas de informacao, no. E27, pp. 553–565, 2020

D. A. Hern´andez Mera, “Dise˜no de un esquema de seguridad inform´atica para el ´area de sistematizaci´on de la universidad israel, aplicando iso 27002 y csf de nits.” Master’s thesis, Quito, Ecuador: Universidad Tecnol´ogica Israel, 2023

D. Pont´on Cevallos, “Progresismo y tecnolog´ıa policial: an´alisis del boom punitivo en ecuador,” Perfiles latinoamericanos, vol. 31, no. 62, 2023. DOI: https://doi.org/10.18504/pl3162-006-2023

E. R. Armenta and A. L. I. Carrillo, “Towards an implementation of information technologies governance,” in 2022 IEEE Mexican International Conference on Computer Science (ENC). IEEE, 2022, pp. 1–6. DOI: https://doi.org/10.1109/ENC56672.2022.9882923

E. Falc´on Huallpa and E. J. Mart´ınez Zambrano, “Propuesta de mejora para la gesti´on de seguridad de la informaci´on sgsi bajo normas iso 27001, para el departamento de an´alisis de telecomunicaciones de la unidad nacional de telecomunicaci´on m´ovil”(quito-ecuador),” 2023.

C. Schr¨oer, F. Kruse, and J. M. G´omez, “A systematic literature review on applying crisp-dm process model,” Procedia Computer Science, vol. 181, pp. 526–534, 2021. DOI: https://doi.org/10.1016/j.procs.2021.01.199

Toasa, Renato, et al. "Data visualization techniques for real-time information—A custom and dynamic dashboard for analyzing surveys' results." 2018 13th Iberian Conference on Information Systems and Technologies (CISTI). IEEE, 2018. DOI: https://doi.org/10.23919/CISTI.2018.8398641

Published

2025-11-15

How to Cite

Velasco T´eran, J. L., & Toasa Guachi, R. (2025). IT Security Balanced Scorecard based on ISO 27001:2022. International Journal of Engineering Insights, 3(1), 1–5. https://doi.org/10.61961/injei.v3i1.23

Issue

Section

Articles