MMISS-SME Practical Development: Maturity Model for Information Systems Security Management in SMEs
Luis Enrique Sanchez, Daniel Villafranca, Mario G. Piattini · 2007
Abstract. For enterprises to be able to use information technologies and communications with guarantees, it is necessary to have an adequate security management system. However, this requires that enterprises know in every moment their security maturity level and to what extend their information security system must evolve. Moreover, this security management system must have very reduced costs for its implementation and maintenance in small and medium-size enterprises (from now on, SMEs) to be feasible. In this paper, we will put forward our proposal of a maturity model for security management in SMEs and we will briefly analyse other models that exist in the market. This approach is being directly applied to real cases, thus obtaining an improvement in its application. 1 Introduction Information and processes supporting systems and nets are the most important assets for any organization [1] and they suppose the main differentiating factor in an enterprise evolution. These assets are exposed to a great variety of risks that can critically affect enterprises. There are many sources that provide us with figures that show the importance of the problems caused by the lack of adequate security measures [2-6]. At present, tackling the implementation of a security management system is very complex for a small or medium-size enterprise. The tendency in the field of enterprises security is that of migrating little by little their culture towards the creation of a security management system (ISMS) although this progression is very slow. Thus, studies such as that of Rene Sant-Germain [7] estimate that with the current models, in 2009, only 35% of the enterprises of the world with more than 2000 employees will