Logo do repositório
 
Publicação

Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal

datacite.subject.fosCiências Naturais::Ciências da Computação e da Informação
datacite.subject.sdg08:Trabalho Digno e Crescimento Económico
datacite.subject.sdg09:Indústria, Inovação e Infraestruturas
datacite.subject.sdg10:Reduzir as Desigualdades
dc.contributor.authorAntunes, Mário
dc.contributor.authorMaximiano, Marisa
dc.contributor.authorGomes, Ricardo
dc.contributor.authorPinto, Daniel
dc.date.accessioned2026-02-27T18:11:39Z
dc.date.available2026-02-27T18:11:39Z
dc.date.issued2021-04-08
dc.descriptionPinto, Daniel - Scopus ID: 58809541800 (ex-docente)
dc.description.abstractInformation security plays a key role in enterprises management, as it deals with the confidentiality, privacy, integrity, and availability of one of their most valuable resources: data and information. Small and Medium-sized enterprises (SME) are seen as a blind spot in information security and cybersecurity management, which is mainly due to their size, regional and familiar scope, and financial resources. This paper presents an information security and cybersecurity management project, in which a methodology based on the well-known ISO-27001:2013 standard was designed and implemented in fifty SMEs that were located in the center region of Portugal. The project was conducted by a business association located at the center of Portugal and mainly participated by SMEs. The Polytechnic of Leiria and an IT auditing/consulting team were the other two entities that participated on the project. The characterisation of the participating enterprises, the ISO-27001:2013 based methodology developed and implemented in SMEs, as well as the results obtained in this case study, are depicted and analysed in the paper. The attained results show a clear benefit to the audited and intervened SMEs, being mainly attested by the increasing of their information security management robustness and collaborators’ cyberawareness.eng
dc.description.sponsorshipFunding: This project was funded by “POCI—Programa Operacional para a Competitividade e Internacionalização” grant number POCI-02-0853-FEDER-026352. This publication and the APC is funded by FCT—Fundação para a Ciência e Tecnologia, I.P., under the project UIDB/04524/2020. Acknowledgments: The authors acknowledge NERLEI business association project team by the support given along the implementation of the project.
dc.identifier.citationAntunes,M.;Maximiano,M.; Gomes, R.; Pinto, D. Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal. J. Cybersecur. Priv. 2021, 1, 219–238. https://doi.org/ 10.3390/jcp1020012.
dc.identifier.doi10.3390/jcp1020012
dc.identifier.eissn2624-800X
dc.identifier.urihttp://hdl.handle.net/10400.8/15744
dc.language.isoeng
dc.peerreviewedyes
dc.publisherMDPI
dc.relationResearch Center in Informatics and Communications
dc.relation.hasversionhttps://www.mdpi.com/2624-800X/1/2/12
dc.relation.ispartofJournal of Cybersecurity and Privacy
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.subjectinformation security
dc.subjectcybersecurity
dc.subjectsmall and medium-sized enterprises
dc.subjectISO-27001:2013
dc.subjectauditing
dc.titleInformation Security and Cybersecurity Management: A Case Study with SMEs in Portugaleng
dc.typejournal article
dspace.entity.typePublication
oaire.awardTitleResearch Center in Informatics and Communications
oaire.awardURIinfo:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/UIDB%2F04524%2F2020/PT
oaire.citation.endPage238
oaire.citation.issue2
oaire.citation.startPage219
oaire.citation.titleJournal of Cybersecurity and Privacy
oaire.citation.volume1
oaire.fundingStream6817 - DCRRNI ID
oaire.versionhttp://purl.org/coar/version/c_970fb48d4fbd8a85
person.affiliation.nameCIIC / ESTG
person.familyNameAntunes
person.familyNameMaximiano
person.familyNamePereira Gomes
person.givenNameMário
person.givenNameMarisa
person.givenNameRicardo Jorge
person.identifierR-000-NX4
person.identifierurn:authenticus_id:R-002-SEG
person.identifier.ciencia-idAF10-7EDD-5153
person.identifier.ciencia-idA919-B117-A16D
person.identifier.ciencia-id2319-A0CE-6813
person.identifier.gsid6gzjmMkAAAAJ
person.identifier.orcid0000-0003-3448-6726
person.identifier.orcid0000-0002-1212-7864
person.identifier.orcid0000-0002-0438-9119
person.identifier.ridADM-8923-2022
person.identifier.scopus-author-id25930820200
person.identifier.scopus-author-id26767664900
person.identifier.scopus-author-id57413754100
project.funder.identifierhttp://doi.org/10.13039/501100001871
project.funder.nameFundação para a Ciência e a Tecnologia
relation.isAuthorOfPublicatione3e87fb0-d1d6-44c3-985d-920a5560f8c1
relation.isAuthorOfPublication18092229-fa61-402b-978c-56b8127d46e9
relation.isAuthorOfPublication21f92f87-2dd6-4d26-be3d-cd2b13a0e19a
relation.isAuthorOfPublication.latestForDiscoverye3e87fb0-d1d6-44c3-985d-920a5560f8c1
relation.isProjectOfPublication67435020-fe0d-4b46-be85-59ee3c6138c7
relation.isProjectOfPublication.latestForDiscovery67435020-fe0d-4b46-be85-59ee3c6138c7

Ficheiros

Principais
A mostrar 1 - 1 de 1
A carregar...
Miniatura
Nome:
Information Security and Cybersecurity Management A Case Study with SMEs in Portugal.pdf
Tamanho:
1.26 MB
Formato:
Adobe Portable Document Format
Descrição:
Information security plays a key role in enterprises management, as it deals with the confidentiality, privacy, integrity, and availability of one of their most valuable resources: data and information. Small and Medium-sized enterprises (SME) are seen as a blind spot in information security and cybersecurity management, which is mainly due to their size, regional and familiar scope, and financial resources. This paper presents an information security and cybersecurity management project, in which a methodology based on the well-known ISO-27001:2013 standard was designed and implemented in fifty SMEs that were located in the center region of Portugal. The project was conducted by a business association located at the center of Portugal and mainly participated by SMEs. The Polytechnic of Leiria and an IT auditing/consulting team were the other two entities that participated on the project. The characterisation of the participating enterprises, the ISO-27001:2013 based methodology developed and implemented in SMEs, as well as the results obtained in this case study, are depicted and analysed in the paper. The attained results show a clear benefit to the audited and intervened SMEs, being mainly attested by the increasing of their information security management robustness and collaborators’ cyberawareness.
Licença
A mostrar 1 - 1 de 1
Miniatura indisponível
Nome:
license.txt
Tamanho:
1.32 KB
Formato:
Item-specific license agreed upon to submission
Descrição: