Future Internet (Jul 2016)

The Importance of the Security Culture in SMEs as Regards the Correct Management of the Security of Their Assets

  • Antonio Santos-Olmo,
  • Luis Enrique Sánchez,
  • Ismael Caballero,
  • Sara Camacho,
  • Eduardo Fernandez-Medina

DOI
https://doi.org/10.3390/fi8030030
Journal volume & issue
Vol. 8, no. 3
p. 30

Abstract

Read online

The information society is increasingly more dependent on Information Security Management Systems (ISMSs), and the availability of these kinds of systems is now vital for the development of Small and Medium-Sized Enterprises (SMEs). However, these companies require ISMSs that have been adapted to their special features, and which are optimized as regards the resources needed to deploy and maintain them. This article shows how important the security culture within ISMSs is for SMEs, and how the concept of security culture has been introduced into a security management methodology (MARISMA is a Methodology for “Information Security Management System in SMEs” developed by the Sicaman Nuevas Tecnologías Company, Research Group GSyA and Alarcos of the University of Castilla-La Mancha.) for SMEs. This model is currently being directly applied to real cases, thus allowing a steady improvement to be made to its implementation.

Keywords