Adapting cybersecurity maturity models for resource-constrained settings: A case study of Peru

  • Lee, GangSeok
  • Kim, SuHyun
  • Lee, ImYoung
  • Brown, Suzana
  • Carbajal, Yuri Aldoradin
Citations

WEB OF SCIENCE

5
Citations

SCOPUS

8

초록

Developing countries are rapidly embracing digitalization, but this exposes them to heightened cybersecurity risks. They often look to standard established cybersecurity models from developed countries to build their national defenses. However, significant developmental, political, social, and economic differences can render these models unsuitable for developing countries. This study addresses this gap by proposing a new framework that would be more useful in a developing country context. We first examine existing cybersecurity maturity models (CMMs) and metrics. Through a case study of Peru's national computer security incident response team (CSIRT), we assess the applicability of the security incident management maturity model (SIM3) and the security operation center CMM (SOC-CMM) frameworks. By applying these frameworks to the Peruvian context, we identify limitations in standard maturity models for developing countries. In response, we propose a novel framework that allows developing countries like Peru to leverage existing models by tailoring them to their specific environment. This tailored approach can be a powerful tool for developing countries to improve and build their cybersecurity on a national level.

키워드

CSIRTcase studycybersecuritydigital developmentPeruSECURITY
제목
Adapting cybersecurity maturity models for resource-constrained settings: A case study of Peru
저자
Lee, GangSeokKim, SuHyunLee, ImYoungBrown, SuzanaCarbajal, Yuri Aldoradin
DOI
10.1002/isd2.12350
발행일
2025-01
유형
Article
저널명
Electronic Journal of Information Systems in Developing Countries
91
1