▲ Back to Top
STRATEGIC MACROPROCESS INTEGRATED SYSTEMS MANAGEMENT ISMS
INTEGRATED SYSTEMS MANAGEMENT PROCESS
CHARACTERIZATION
Management System Manager

Maria Del Pilar Delgado Rodríguez
Information Security Management System Coordinator
-
- Continuously improve process performance through the implementation of institutional best practices and the application of the mechanisms established by the University of Cundinamarca, with the goal of creating a smart university organization with heart and soul.
-
- Promote and ensure austerity commitments in the efficient use of materials and energy consumed by the strategic, mission-support, follow-up, measurement, analysis, and evaluation processes proper to U CUNDINAMARCA.
-
- Inform and educate the community of the University of Cundinamarca and its stakeholders, both at its main campus and its regional branches and extensions, regarding the guidelines of this Institutional Environmental Policy.
-
- Identify the hazards, evaluate, assess, and intervene in the risks present in the processes developed by the University Community and other stakeholders, establishing the respective controls, with the purpose of avoiding and minimizing incidents, work-related accidents, and occupational illnesses that may arise as a result thereof.
-
- To promote the comprehensive protection of the physical and mental health of officials and contractors who contribute to the fulfillment of the institutional mission, through the prevention and control of occupational hazards.
STAGES
1. PLAN
2. DO
3. VERIFY
4. ACT
OBJECTIVE
Establish, implement, maintain, and continually improve conditions and requirements by establishing guidelines, documented and systematic procedures for the planning, execution, verification, continuous improvement, and best practices of Information Security – IS, Cybersecurity, and the Comprehensive Personal Data Protection Program – PIGDP, with the purpose of protecting the institution's essential information assets from internal and external threats, minimizing risks due to loss of Confidentiality, Integrity, and Availability of physical and digital information, ensuring the implementation of physical and digital security controls, in compliance with the conditions and requirements of ISO standards 27001:2022, 27032:2023, and the Personal Data Protection Law, seeking to strengthen cybersecurity and institutional resilience.
SCOPE
The implementation of the Information Security Management System – ISMS, Cybersecurity, and the Comprehensive Personal Data Management Program – PIGDP covers the institutional level, including the Main Campus, Regional Branches, Extensions, Bogotá Office, Academic Sports Center – CAD, and Agro-environmental units, encompassing all processes of the Digital Operation Model, within the framework of continuous improvement.
PROCESS OPERATION POLICY
| The University of Cundinamarca understands the importance of guaranteeing the confidentiality, integrity, and availability of information as an essential asset for the provision of its services in the processes of admissions and registrar, university welfare, science, technology, and innovation, engaging with the world, training and learning, graduates, and university social interaction. Therefore, the implementation of an Information Security Management System (ISMS) is a priority as a tool to enable the management of information assets, risk management, incident management, compliance management, change and culture management, and the institution's business continuity management, while maintaining continuous improvement in accordance with the needs and expectations of the various identified stakeholder groups. The Information Security Management System – ISMS, following the guidelines and directives of the Institutional Planning Directorate, in accordance with the institution's strategic documents and in coordination with the Systems and Technology Directorate, will be the areas that will establish, manage, and promote mechanisms for the protection and safeguarding of information as the primary asset of the University of Cundinamarca, in accordance with applicable legal regulations and in line with the institution's mission and vision. Likewise, the other guidelines generated as a product of the implementation of the ISMS shall be appropriate and mandatory for all stakeholders, taking into account the guidelines established in the Manual. ESG-SSI-M001. |
| ENTRIES | PROCEDURES | EXITS |
| – Information asset inventory - Information asset classification - Information Asset Labeling |
ESG-SSI-P01 – Information Asset Management | – Information asset inventory of the University of Cundinamarca classified, labeled, and published – Information Asset Consolidates with restricted public classification, pursuant to Articles 13 and 20 of Law 1712 of 2014 |
| - Law 1581 of 2012 – Decree No. 1377 of 2013 – Regulatory Decree 1074 of 2015 – Data Protection Guidelines for Data Subjects at the University of Cundinamarca – Request for the Collection of Data on Data Subjects from the University of Cundinamarca |
ESG-SSI-P03 – Collection and Storage of Personal Data | – Data collected from students at the University of Cundinamarca |
| - Law 1581 of 2012 – Decree No. 1377 of 2013 – Regulatory Decree 1074 of 2015 – Data Protection Guidelines for Data Subjects at the University of Cundinamarca – Stored data on individuals affiliated with the University of Cundinamarca |
ESG-SSI-P05 – Use and Sharing of Personal Data | – Guidelines for the Use and Sharing of Personal Data |
| – Request to delete personal data. | ESG-SSI-P06 – Suppression of Personal Data | – Response to a Request to Delete Personal Data |
| – Requirements for the International Transfer and/or Transmission of Personal Data | ESG-SSI-P07 – International Transfer and Transmission of Personal Data | – Response to the Transfer and/or Disclosure of Personal Data |
| – The Need to Implement an Information Security Management System | ESG-SSI-P08 – Implementation of the Information Security Management System | – Continuous improvement of the Information Security Management System |
| – Information Security Incident Events | ESG-SSI-P09 – Information Security Event and/or Incident Management | – Analysis and Resolution of the Documented Incident |
| – Information Security Events and/or Incidents Involving the Processing of Personal Data. | ESG-SSI-P10 – Management of Security Events and/or Incidents in the Processing of Personal Data | – Analysis and Resolution of the Documented Event and/or Incident |
| – Risks, vulnerabilities, and threats related to information assets | ESG-SSI-P12 – Information Security Risk Management |
– Identification, assessment, and mitigation of information security risks |
| – Schedule of Activities – Requirement for the registration of institutional databases – Regulatory Changes |
ESG-SSI-P13 – National Database Registry at the SIC | -Execution of the schedule of activities - Consolidated institutional databases -Procedure implemented |
| - Personal Data Protection Schedule – Resolution 091 Guideline – Data subject requests – Current legal regulations – Schedule of the National Registry of Personal Data Bases |
ESG-SSI-P15 – Personal Data Management | - Schedule Execution – Reports to the Superintendency of Industry and Commerce – Management Reports – Compliance Reports – Report on Processed Requests |
| - Risks, threats, and consequences related to databases containing personal information | ESG-SSI-P16 – Personal Data Protection Risk Management | – Identification, assessment, and management of personal data protection risks |
| – ESG-SSI-P01 – Information Asset Management – ESG-SSI-F034 – Information Asset Inventory Consolidated Report | ESG-SSI-P17 – Information Asset Labeling | – ADOr006 – Institutional Information Asset Labeling Results Report |
| – Data Processing Guidelines of the University of Cundinamarca – Information Security Guideline of the University of Cundinamarca. – ESG-SSI-M001 – Information Security and Privacy Guidelines Manual |
ESG-SSI-P18 – Information Security and Privacy Watchdogs | – ESG-SSI-F035 – Verification Report for Information Security Officers |
| – Transfer of information assets by the immediate supervisor to the relevant employee | ESG-SSI-P19 – Delivery and return of information assets | – Return of information assets by the employee in accordance with ESG-SSI-I005. |
| – Law No. 1581 of 2012 – Decree No. 1377 of 2013 – Regulatory Decree No. 1074 of 2015 – Resolution 091 of 2023 -Request for the destruction of physical documents containing personal data. |
ESG-SSI-P20 – Procedure for the Destruction of Physical Documents Containing Personal Data | -Certificate of Document Destruction in accordance with ESG-SSI-F053 |
| -Guidelines for planning and conducting controlled social engineering exercises at the University of Cundinamarca. | ESG-SSI-P21 – Social Engineering Exercises | -ADOr006 – Report on the consolidated results of the social engineering exercise conducted at the institutional level. |
| -Institutional prerequisites (organizational chart, digital operating model, academic calendar, IT inventory, and applicable regulations) – Institutional process map and results of process prioritization (triage) – Inventory of Information Assets |
ESG-SSI-P22 – Continuity Management in the Provision of Institutional Services | -Strategic context and scope of the documented Continuity Plan – Approved Business Impact Analysis (BIA) on the Provision of Institutional Services, with RTO, RPO and MTD per critical process – Application Impact Analysis (AIA) approved, with RTO and RPO per critical system – Recovery strategies and approved Continuity Plan for the Provision of Institutional Services – Directory of contacts, test and drill results, and post-incident review reports |
| ENTRIES | PLANES | EXITS |
| – Information Security and Privacy Model – Data Processing Guidelines of the University of Cundinamarca – Information Security Guidelines of the University of Cundinamarca |
ESG-SSI-PL01 – Institutional Plan for Awareness and Training in Information Security and Privacy | – Talks, workshops and events for Awareness and Training in information security and privacy |
| -ESG-SSI-P08 Implementation of the Information Security Management System -ESG-SSI-P15 Personal Data Management |
ESG-SSI-PL02 – Operational Plan for Information Security and Privacy | -ESG-SSI-P08 Implementation of the Information Security Management System -ESG-SSI-P15 Personal Data Management |
| – ISO 27001:2002 Standard – Strategic Plan for Information Security and Privacy – MINTIC – EPIP02 Estimation of income, expenses and definition of general provisions – EPIP05 – Management of the university bank of investment programs and projects of the University of Cundinamarca |
ESG-SSI-PL03 – Strategic Plan for Information Security and Privacy | – Strategic Plan for Information Security and Privacy |
| – ESG-SSI-P12 Information Security Risk Management – Information Security and Privacy Risk Management Plan – MINTIC – Guide for DAFP risk management |
ESG-SSI-PL04 – Information Security and Privacy Risk Treatment Plan | – ESG-SSI-F039 Information Security and Privacy Risk Matrix – ADOF010 Risk Treatment Record |
| – Information asset inventory of the University of Cundinamarca classified, labeled, and published – Vulnerability analysis reports. |
ESG-SSI-PL05 – Vulnerability Management Plan | – Vulnerability classification and management matrix – ADOR006 Vulnerability Management Reports |
| -Results of the triage (15-question form) and process classification (Complete BIA, Summary, Record Only) – Results of the Business Impact Analysis (BIA) on the Provision of Institutional Services by critical process -Inventory of institutional assets. |
ESG-SSI-PL06 – Plan for the Continuity of Institutional Service Delivery | – Prioritization of critical processes with defined RTO, RPO and MTD -Catalog of recovery strategies by process and strategies. -Activation levels and criteria (Level 1, 2, 3) -Response and activation procedure (detection, containment, declaration, contingency operation, return to normal, post-incident review) -Crisis directory and call tree -Continuity system performance indicators (KPIs) |
| ENTRIES | PROGRAMS | EXITS |
| – Data Processing Guidelines of the University of Cundinamarca, requests for consultations, complaints and/or deletion of data – Personal Data Protection Incidents |
ESG-SSI-PG01 – Comprehensive Personal Data Management Program – PIGDP | – Response to Personal Data Protection Incidents |
-
- Monitoring the action plan and indicators of the Information Security Management System.
-
- Self-assessment and control of the Information Security Management System.
-
- Attention to inquiries, complaints or claims related to the processing of data of the data subjects of the University of Cundinamarca.
Implement monitoring and review procedures to:
-
- Identify security and privacy breaches and incidents;
-
- To assist management in determining whether the activities carried out by people and technological devices to ensure information security and the protection of personal data are being carried out in accordance with what was planned;
-
- Detect and prevent information security and privacy events and incidents by identifying risks to meet the proposed indicators;
Regularly review the effectiveness of the ISMS by considering compliance with the ISMS policy and objectives, the results of security audits, incidents, results of effectiveness measurements, suggestions and observations from all parties involved.
Periodically define the Personal Data Databases that are processed and that must be registered with the Superintendency of Industry and Commerce or its equivalent.
Measure the effectiveness of controls to verify compliance with safety requirements.
Review risk assessments, residual risks and their acceptable levels regularly at planned intervals, taking into account any changes that may have occurred in the organization, technology, business objectives and processes, identified threats, the effectiveness of implemented controls and the external environment - legal requirements, contractual obligations, etc.
Conduct periodic internal audits of the ISMS at planned intervals.
Management should periodically review the ISMS to ensure that the defined scope remains appropriate and that improvements to the ISMS process are evident.
Update security plans based on the conclusions and new findings discovered during monitoring and review activities.
The definition of the objective, the scope of the process and its relationship with the institutional strategic direction is carried out with the active participation of the process managers, as well as the procedures for indicators, risks, control points and other actions for the monitoring, evaluation and improvement of the process.
-
- Implement the identified improvements in the ISMS.
-
- Carry out appropriate preventive and corrective actions in relation to clause 8 – Operation of the ISO 27001 standard and the lessons learned from our own and other organizations' experiences.
-
- Communicate the actions and improvements to all stakeholders with the appropriate level of detail and agree, if relevant, on how to proceed.
-
- Ensure that the improvements introduced achieve the intended objectives.
-
- Risk and opportunity management.
Documents
There are no documents for this filter.
Digital Operating Model
Digital Operating Model
Digital Operating Model
Digital Operating Model
