2021
DOI: 10.3390/jcp1020012
|View full text |Cite
|
Sign up to set email alerts
|

Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal

Abstract: Information security plays a key role in enterprises management, as it deals with the confidentiality, privacy, integrity, and availability of one of their most valuable resources: data and information. Small and Medium-sized enterprises (SME) are seen as a blind spot in information security and cybersecurity management, which is mainly due to their size, regional and familiar scope, and financial resources. This paper presents an information security and cybersecurity management project, in which a methodolog… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
6
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
8
2

Relationship

1
9

Authors

Journals

citations
Cited by 31 publications
(6 citation statements)
references
References 24 publications
0
6
0
Order By: Relevance
“…Cybersecurity standards explain and provide methods one by one, specify what is expected to be done to complete the process, and clarify methods to coincide with the standard, whereas a cybersecurity framework is a general guideline that covers many components or domains that can be adopted by businesses/companies/institutions, which does not specify the steps that are required to be taken [21]. Satisfactory cybersecurity protection can be achieved by adopting a cybersecurity framework that describes the scope, implementation, and evaluation processes, and also provides a general structure and methodology for protecting critical digital assets [22]. In fact, organizations can refer to cybersecurity frameworks to realize guidelines in the successful implementation of cybersecurity standards to be better equipped to identify, detect, and respond to cyberattacks [23].…”
Section: Cybersecurity Standards and Frameworkmentioning
confidence: 99%
“…Cybersecurity standards explain and provide methods one by one, specify what is expected to be done to complete the process, and clarify methods to coincide with the standard, whereas a cybersecurity framework is a general guideline that covers many components or domains that can be adopted by businesses/companies/institutions, which does not specify the steps that are required to be taken [21]. Satisfactory cybersecurity protection can be achieved by adopting a cybersecurity framework that describes the scope, implementation, and evaluation processes, and also provides a general structure and methodology for protecting critical digital assets [22]. In fact, organizations can refer to cybersecurity frameworks to realize guidelines in the successful implementation of cybersecurity standards to be better equipped to identify, detect, and respond to cyberattacks [23].…”
Section: Cybersecurity Standards and Frameworkmentioning
confidence: 99%
“…In [62], a use case in Portugal for the implementation of information security actions in a group of SMEs was explained in detail. Some aspects of this work are similar to those adopted in our proposal: a set of information security controls from a recognized standard, which have been grouped into different groups of controls to respond to different needs.…”
Section: A Lack Of High-level Standards That Provide Procedural Eleme...mentioning
confidence: 99%
“…Regarding the impact of cyberawareness in Small-Medium Enterprises (SME), Boletsis et al [23] and Antunes et al [24] have pointed out the key factors and the cyberawareness best practices that should be adopted in this type of organization. In healthcare institutions, Nunes et al [25] evaluated the cybersecurity awareness level of health practitioners in hospitals and identified the associated risk.…”
Section: Literature Reviewmentioning
confidence: 99%