{"id":66497,"date":"2023-03-13T11:56:37","date_gmt":"2023-03-13T11:56:37","guid":{"rendered":"https:\/\/www.kriativ-tech.com\/?p=66497"},"modified":"2023-03-13T12:02:10","modified_gmt":"2023-03-13T12:02:10","slug":"application-tool-for-information-security-and-cybersecurity-risk-management-in-an-organization","status":"publish","type":"post","link":"http:\/\/www.kriativ-tech.com\/?p=66497","title":{"rendered":"Application tool for information security and cybersecurity risk management in an organization"},"content":{"rendered":"<p>[vc_row][vc_column width=&#8221;1\/2&#8243;][vc_custom_heading heading_semantic=&#8221;p&#8221; text_font=&#8221;font-213936&#8243; text_size=&#8221;h5&#8243; text_height=&#8221;fontheight-843833&#8243; uncode_shortcode_id=&#8221;175189&#8243;]Kriativ-tech Volume 1, Issue 9, January 2023, Pages: xxx Received: Jan. 22, 2023; Accepted: Jan. 27, 2023. Published: Mar. 13, 2023.[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]Authors[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_size=&#8221;h5&#8243; uncode_shortcode_id=&#8221;171851&#8243;]<\/p>\n<p style=\"font-weight: 400;\">S\u00e9rgio Pinto,\u00a0Assistant Professor at ISTEC<\/p>\n<p>[\/vc_custom_heading][\/vc_column][vc_column width=&#8221;1\/2&#8243;][vc_custom_heading]Media[\/vc_custom_heading][vc_button button_color=&#8221;accent&#8221; border_animation=&#8221;btn-ripple-out&#8221; border_width=&#8221;0&#8243; link=&#8221;url:http%3A%2F%2Fwww.kriativ-tech.com%2Fwp-content%2Fuploads%2F2023%2F03%2FSergioPinto_Article_RiskManagement_final.pdf|target:_blank&#8221; button_color_type=&#8221;uncode-palette&#8221; uncode_shortcode_id=&#8221;132202&#8243;]PDF[\/vc_button][vc_custom_heading heading_semantic=&#8221;h4&#8243; text_size=&#8221;h4&#8243;]To cite this article[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_size=&#8221;h6&#8243; uncode_shortcode_id=&#8221;692815&#8243;]S\u00e9rgio Pinto, <b>Application tool for information security and cybersecurity risk management in an organization<\/b><br \/>\nDOI: 10.31112\/kriativ-tech-2022-06-81[\/vc_custom_heading][\/vc_column][\/vc_row][vc_row row_height_percent=&#8221;0&#8243; overlay_alpha=&#8221;50&#8243; gutter_size=&#8221;1&#8243; column_width_percent=&#8221;100&#8243; shift_y=&#8221;0&#8243; z_index=&#8221;0&#8243;][vc_column column_width_percent=&#8221;100&#8243; gutter_size=&#8221;0&#8243; override_padding=&#8221;yes&#8221; column_padding=&#8221;1&#8243; overlay_alpha=&#8221;50&#8243; shift_x=&#8221;0&#8243; shift_y=&#8221;0&#8243; shift_y_down=&#8221;0&#8243; z_index=&#8221;0&#8243; medium_width=&#8221;0&#8243; mobile_width=&#8221;0&#8243; width=&#8221;1\/1&#8243;][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]Abstract[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_font=&#8221;font-213936&#8243; text_size=&#8221;h5&#8243; text_height=&#8221;fontheight-843833&#8243; uncode_shortcode_id=&#8221;560523&#8243;]Currently organizations are increasingly exposed to information security and cybersecurity attacks. Therefore, this article intends to describe a process for analyzing\/auditing potential risks to be able to assist an organization in choosing the security measures and controls to define and implement an adequate level of security. Additionally, this article also intends to be a reference for the development of an application tool to implement this process.[\/vc_custom_heading][vc_empty_space empty_h=&#8221;2&#8243;][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]Keywords[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_size=&#8221;h5&#8243; uncode_shortcode_id=&#8221;479787&#8243;]Cybersecurity, Impact, Organization, Probability, Risk, Threat, Vulnerability.[\/vc_custom_heading][\/vc_column][\/vc_row][vc_row][vc_column column_width_percent=&#8221;100&#8243; gutter_size=&#8221;0&#8243; overlay_alpha=&#8221;50&#8243; shift_x=&#8221;0&#8243; shift_y=&#8221;0&#8243; shift_y_down=&#8221;0&#8243; z_index=&#8221;0&#8243; medium_width=&#8221;0&#8243; mobile_width=&#8221;0&#8243; width=&#8221;1\/1&#8243;][vc_custom_heading heading_semantic=&#8221;h3&#8243; text_size=&#8221;h3&#8243;]References[\/vc_custom_heading][vc_custom_heading heading_semantic=&#8221;p&#8221; text_font=&#8221;font-213936&#8243; text_size=&#8221;h5&#8243; text_height=&#8221;fontheight-843833&#8243; uncode_shortcode_id=&#8221;777612&#8243;][1] CNCS (2022), \u201cGuia para Gest\u00e3o de Riscos em mat\u00e9rias de Seguran\u00e7a da Informa\u00e7\u00e3o e Ciberseguran\u00e7a\u201d, retrieved from: https:\/\/www.cncs.gov.pt\/docs\/guia-de-gestao-dos-riscos.pdf<\/p>\n<p>[2] CNCS (2019), \u201cQNRCS: Quadro Nacional de Refer\u00eancia para a Ciberseguran\u00e7a\u201d, retrieved from:<br \/>\nhttps:\/\/www.cncs.gov.pt\/docs\/cncs-qnrcs-2019.pdf<\/p>\n<p>[3] Artigo 10\u00ba Decreto Lei n\u00ba 65\/2021, 30 de julho, \u201cRegime Jur\u00eddico da Seguran\u00e7a do Ciberespa\u00e7o\u201c, retrieved from:<br \/>\nhttps:\/\/www.cncs.gov.pt\/pt\/regime-juridico\/<\/p>\n<p>[4] CNCS (2020), \u201cQuadro de Avalia\u00e7\u00e3o de Capacidades de Ciberseguran\u00e7a\u201d, retrieved from: https:\/\/www.cncs.gov.pt\/docs\/cncs-quadrodeavaliacao.pdf<\/p>\n<p>[5] ISO\/IEC 27005:2018, \u201cInformation technology &#8212; Security techniques &#8212; Information security risk management\u201d, retrieved from: https:\/\/www.standards-pdf-download.com\/iso-iec-27005-2018-download-free.html<\/p>\n<p>[6] NIST (2022), \u201cRisk Management Framework: Security and Privacy Controls for Information Systems and Organizations, Revision 5\u201d, SP 800-53, retrieved from: https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53\/rev-5\/final<\/p>\n<p>[7] NP ISO\/IEC 31000, \u201cGest\u00e3o do Risco \u2013 Linhas de orienta\u00e7\u00e3o\u201d, retrieved from: http:\/\/qualitividade.pt\/wp-content\/uploads\/2016\/04\/NPISO031000_2012.pdf<\/p>\n<p>[8] ISO\/IEC 27001:2022, \u201cInformation security, cybersecurity and privacy protection \u2014 Information security management systems \u2014 Requirements\u201d<br \/>\n, retrieved from: http:\/\/www.itref.ir\/uploads\/editor\/2ef522.pdf<br \/>\n[\/vc_custom_heading][\/vc_column][\/vc_row]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>S\u00e9rgio Pinto,\u00a0Assistant Professor at ISTEC<br \/>\nDOI: 10.31112\/kriativ-tech-2022-06-81<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[70],"tags":[],"_links":{"self":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts\/66497"}],"collection":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=66497"}],"version-history":[{"count":2,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts\/66497\/revisions"}],"predecessor-version":[{"id":66504,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=\/wp\/v2\/posts\/66497\/revisions\/66504"}],"wp:attachment":[{"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=66497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=66497"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.kriativ-tech.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=66497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}