Security policies in the technological infrastructure of health institutions through a fortinet 80e appliance: Jipijapa Basic hospital case study

Authors

DOI:

https://doi.org/10.62305/biosana.v4i1.102

Keywords:

security politics; Technological infrastructure; Fortinet 80e appliance

Abstract

The objective of this research is the implementation of computer security policies to protect technological assets and reduce risks in the technological infrastructure of the Jipijapa Basic Hospital in the province of Manabí, through the identification of the state of the art on computer security policies in technological assets, determining existing vulnerabilities and designing computer security policies to protect technological assets in public organizations. The methodology used was framed from the interpretive paradigm, with a qualitative approach, type of case study research, the methods chosen were: bibliographic, inductive, analysis and synthesis, descriptive in scope, the technique was the interview through a structured questionnaire to use technological tools to scan the data network over time periods. The results reveal the need to implement security policies through the Fortinet 80e appliance technology in the technological infrastructure of the Jipijapa Basic Hospital and adhere to security policies proposed in this research. This model can be used in other environments by other hospitals and medical organizations to improve their cybersecurity strategies and protect confidential patient information, this work contributes to the Institutional research project: “Factors that determine the acceptance of smart city technologies applied to students with a high level of education and to the research group: Intelligent and Cyberphysical Systems Research Group – UNESUM.”

Downloads

Download data is not yet available.

References

Palou Oliver M. Pla de sistemes informàtics per a l'Ajuntament de Marratxí. 2020.

Siponen M, Willison R. Information security management standards: Problems and solutions. Information & management. 2009;46(5):267-70.

Susanto12 H, Almunawar MN, Tuan YC. Information security management system standards: A comparative study of the big five. International Journal of Electrical Computer Sciences IJECSIJENS. 2011;11(5):23-9.

Gollmann D. Computer security. Wiley Interdisciplinary Reviews: Computational Statistics. 2010;2(5):544-54.

Ponce FBP, Caicedo RWA, Parrales KGM, Plúa CRC. Asistente virtual como componente para el desarrollo de una universidad inteligente en procesos de vinculación de la Universidad Estatal del Sur de Manabí. RECIAMUC. 2022;6(4):191-9.

Muñoz WWQ, Plúa CRC. Modelo de sistema de movilidad inteligente para la planificación de servicios urbanos desde la percepción de estudiantes de la Universidad Estatal del Sur de Manabí. Revista Científica Arbitrada Multidisciplinaria PENTACIENCIAS. 2023;5(5):315-28.

López RA. Sistemas de gestión de la seguridad informática. Bogotá: AREANDINA. Fundación Universitaria del Área Andina; 2017.

Disterer G. ISO/IEC 27000, 27001 and 27002 for information security management. Journal of Information Security. 2013;4(2).

Plúa CRC, Pincay IHP, CAICEDO FJ. Modelo de entorno web para el fortalecimiento de productos agrícolas en Pymes. Revista Espacios Vol. 2018;39.

Dey M, editor Information security management-a practical approach. AFRICON 2007; 2007: IEEE.

Alvarez A, Chilán S, Figueroa M, Marcillo M, Parrales J, Caicedo C. Sustainable management model to improve competitiveness in coffee crops title in English. Espacios. 2019;40:16.

Artavia León JA, Soto Sotelo MG. Evaluación del sistema de gestión de resiliencia y de ciberseguridad en un proveedor de internet, utilizando el" Marco para la mejora de la seguridad del instituto nacional de estándares y tecnologías NIST 1.1": Universidad Cenfotec; 2023.

Plúa CRC, Fernández FOA. Revisión sistemática de la literatura sobre ciudades inteligentes y tecnologías de servicios urbanos 2012–2021. Revista Científica Arbitrada Multidisciplinaria PENTACIENCIAS. 2022;4(3):215-35.

Faizan M, Hcgdc S, Yaligar NV. Comparison between Cisco ASA and Fortinet FortiGate. IOSR J Comput Eng. 2019;21(3):34-6.

Plúa CRC, Gonzalez ADCR, Caicedo RWA, Vásquez JPA. Aplicativo móvil como estrategia de marketing para el impulso de la matriz productiva en el área turística. 3c Tecnología: glosas de innovación aplicadas a la pyme. 2016;5(1):41-53.

Almagro L. MARCO NIST CIBERSEGURIDAD Un abordaje integral de la Ciberseguridad. Internet (https://www oas org/es/sms/cicte/docs/OEA-AWS-Marco-NIST-de-Ciberseguridad-ESP pdf). 2019.

Fouinat F. A comprehensive framework for human security. Security and Development: Routledge; 2013. p. 71-9.

Khonji M, Iraqi Y, Jones A. Phishing detection: a literature survey. IEEE Communications Surveys & Tutorials. 2013;15(4):2091-121.

Lopez V. Papel de la explosión combinacional en ataques de fuerza bruta. Investigacion e Innovación en Ingenierías. 2013;1(1).

Hedström K, Kolkowska E, Karlsson F, Allen JP. Value conflicts for information security management. The Journal of Strategic Information Systems. 2011;20(4):373-84.

Gupta S, Gupta BB. Cross-Site Scripting (XSS) attacks and defense mechanisms: classification and state-of-the-art. International Journal of System Assurance Engineering and Management. 2017;8:512-30.

Keele S. Guidelines for performing systematic literature reviews in software engineering. Technical report, ver. 2.3 ebse technical report. ebse; 2007.

Sampieri R, Fernández C, Baptista P. Metodología de la investigación.(Cuarta Edición). México: Graw-Hill. Interamericana, SA de CV; 2006.

Yang Y, Qu G, Hua L. Research status, hotspots, and evolution trend of decision-making in marine management using VOSviewer and CiteSpace. Mathematical Problems in Engineering. 2022;2022.

Ahmed SN, Syed RM, Kamal R, Khan M, editors. Corporate Information Security Policies Targeting Ransomw are Attack. 2022 Mohammad Ali Jinnah University International Conference on Computing (MAJICC); 2022: IEEE.

Bulut H, Kaçar F. Prevention of Cyberattacks on SCADA Systems Used in the Financial Sector. Electrica. 2022;22(2).

Chiniah A, Ghannoo F. A multi-theory model to evaluate new factors influencing information security compliance. International Journal of Security and Networks. 2023;18(1):19-29.

Nasir A, Arshah RA, Ab Hamid MR, Fahmy S. Information security culture concept towards information security compliance: a comparison between it and non-IT professionals. International Journal of Integrated Engineering. 2022;14(3):157-65.

Hong Y, Xu M. Autonomous motivation and information security policy compliance: role of job satisfaction, responsibility, and deterrence. Journal of Organizational and End User Computing (JOEUC). 2021;33(6):1-17.

Fong N, Bayona-Oré S. Consideraciones para el Cumplimiento de la Política de Seguridad de la Información. Revista Ibérica de Sistemas e Tecnologias de Informação. 2022(E51):528-39.

Gangire Y, Da Veiga A, Herselman M. Assessing information security behaviour: A self-determination theory perspective. Information & Computer Security. 2021;29(4):625-46.

Ording LG, Gao S, Chen W. The influence of inputs in the information security policy development: an institutional perspective. Transforming Government: People, Process and Policy. 2022;16(4):418-35.

Bhagwat-Chitale S. Asian Men Who Have Sex With Men (MSM)’s Perceptions of Risk Behaviour and Attitudes Towards HIV Testing in New Zealand: Auckland University of Technology; 2017.

Tonge AM, Kasture SS, Chaudhari SR. Cyber security: challenges for society-literature review. IOSR Journal of computer Engineering. 2013;2(12):67-75.

Choez Gómez JA. Plataforma virtual Open Source para optimizar recursos en la administración de servidores del Hospital Básico de Jipijapa: Jipijapa-Unesum; 2023.

Franco DA, Perea JL, Puello P. Metodología para la Detección de Vulnerabilidades en Redes de Datos. Información tecnológica. 2012;23(3):113-20.

Molina L, Furfaro A, Malena G, Parise A. Ataques Distribuidos de Denegación de Servicios: modelación y simulación con eventos discretos. XV Jornada Internacional de Seguridad Informática-ACIS. 2015.

Published

2024-03-13

How to Cite

Baque Pinargote , O. S. ., Asanza Chóez , J. A., Chiquito Manrique , C. D., & Caicedo Plúa , C. R. (2024). Security policies in the technological infrastructure of health institutions through a fortinet 80e appliance: Jipijapa Basic hospital case study . BIOSANA Health Scientific Journal. ISSN 2960-8481, 4(1), 115–138. https://doi.org/10.62305/biosana.v4i1.102

Issue

Section

Artículos