▲ Back to Top
MACROPROCESO DE APOYO GESTIÓN SISTEMAS Y TECNOLOGÍA
PROCESO GESTIÓN SISTEMAS Y TECNOLOGÍA
CHARACTERIZATION
PROCESS OWNER

Ana Lucía Hurtado Mesa
Director of Systems and Technology
- Continuously improve process performance through the implementation of institutional best practices and the application of the mechanisms established by the University of Cundinamarca, with the goal of creating a smart university organization with heart and soul.
- Ensure an institutional environmental culture within the framework of its commitment to life-forming education, democratic values, civility, and freedom.
- Consolidate and make visible the University of Cundinamarca as a Green University Institution, consistent with its responsibility to society and nature, within the framework of the international standard.
- Promote and ensure austerity commitments in the efficient use of materials and energy consumed by the strategic, core, support, monitoring, measurement, analysis, and evaluation processes of UCUNDINAMARCA.
- Inform and educate the community of the University of Cundinamarca and its stakeholders, both at its main campus and its regional branches and extensions, regarding the guidelines of this Institutional Environmental Policy.
- To promote the comprehensive protection of the physical and mental health of officials and contractors who contribute to the fulfillment of the institutional mission, through the prevention and control of occupational hazards.
- Comply with current legal regulations regarding occupational hazards and other applicable requirements.
- Assignment of responsibilities at all hierarchical levels, from senior management to the operational levels of the University, generating an individual and collective commitment to self-care and comprehensive health protection.
- Identify the hazards, evaluate, assess, and intervene in the risks present in the processes developed by the University Community and other stakeholders, establishing the respective controls, with the purpose of avoiding and minimizing incidents, work-related accidents, and occupational illnesses that may arise as a result thereof.
- Establish and maintain the roles and responsibilities of the Information Security Management System – ISMS, taking into account the different hierarchical levels within the institution, starting with Top Management by allocating the necessary and sufficient resources for the implementation, maintenance, and continuous improvement of the ISMS.
- Manage risks with each process of the institution based on the confidentiality, integrity, and availability criteria of the Information Security Management System – ISMS information, starting from Information Asset Management, associated in Annex A of the ISO 27001 standard, for their treatment and mitigation, according to the prioritization of the criticality of the identified information assets.
- Implement and maintain the ESG-SSI-PL01 – Institutional Security and Information Privacy Awareness and Training Plan for the academic community in general, and for administrative staff and teachers in particular, for the appropriation and strengthening regarding policies, procedures, manuals, instructions, and guides on information security and privacy.
- Define and implement incident management involving the activities of prevention, identification, and management of events and/or incidents that threaten the confidentiality, integrity, and availability of information assets, in accordance with the resources provided by the institution, promoting the continuous improvement of the ISMS.
- Comply with the legal and regulatory requirements regarding information security and privacy that bind the activities of the Information Security Management System – ISMS.
STAGES
1. PLAN
2. DO
3. VERIFY
4. ACT
OBJECTIVES
General Objective:
Manage and administer the architecture, operation, technological services, support, and security of IT resources, through the support of best practices, technology projects, application development, and the implementation of information systems and technological solutions to achieve institutional objectives.
Specific Objectives:
- Streamline process systematization by implementing requests for the use and appropriation of information systems.
- Ensure the proper functioning of technological resources and connectivity through the execution of the preventive maintenance schedule.
- Ensure the timely processing of requests registered in IT services through the one-click service desk.
- Ensure the delivery of needs and requirements identified in the design and development process of information systems, guaranteeing that all expectations and demands are effectively met during system implementation.
SCOPE
Starts from the strategic planning of the institution's technological services and resources, which are aligned with the different processes to generate value and effectively meet the goals of the strategic plan of the University of Cundinamarca and the strategic front of Social Organization of Knowledge and Living Learning. It concludes with the provision of quality services to the university community.
PROCESS OPERATION POLICY
The Systems and Technology Directorate is responsible for establishing the guidelines for the incorporation, use, and appropriation of information technologies through the development of technological projects aimed at fulfilling institutional objectives. Likewise, it is responsible for comprehensively managing information technologies, providing services that align with the entity's needs, and contributing to the development and achievement of mission, strategic, and support goals.
Compliance with the information technology process operation policy is mandatory, and it is the commitment of every user to abide by the guidelines established for the performance of their duties, in accordance with the guidelines set forth in the process procedures.
| ENTRIES | PROCEDURES | EXITS |
| – Service requirements – Software Requirements – Software News – Information systems innovation – Regulatory Changes. |
ASIP16 – Information Systems Development |
- Information Systems Implementation – Response to software needs – Implemented System Documentation. |
| – Schedule of Activities - Activity Planning - Service Requirement. |
ASIP18 – Support, Maintenance, and Monitoring of Network Infrastructure and Technological Resources |
– Technical Assistance Report and responses – Schedule Execution – Execution of Planned Activities. |
| – Computer resource requests – Activity planning – Procurement advisory request. |
ASIP19 – IT Project Management |
– Filed projects – Purchase request for goods or services – Response to acquisition advisory services. |
| – Service Requirement – Academic Calendar – Staff contract dates. |
ASIP20 – Management of Access to Information Systems, Resources, and Technological Services |
– Access and withdrawal to the computer service. – Institutional Platform, Email, and Domain. |
| – Need to Back Up Information Assets. | ASIP25 – Data Backup |
– Backups executed. |
| - Request through the One-Click Service Desk application in any of its categories. | ASIP33 – Service Desk One Click |
– Response through the One-Click Service Desk application in any of its categories. |
| – Planning of Preventive Maintenance for Information Systems. | ASIP34 – Preventive Maintenance for Information Systems |
– Execution of preventive maintenance for the Information Systems managed by the Directorate of Systems and Technology. |
| - Requirement for construction or modification of Dashboard. -Express needs of the requesting department. |
ASIP35 – Data Analysis |
-Response to needs. – Dashboard implementation. -Documentation. |
| – Identification of vulnerabilities. -Administration and development of methodologies for management. |
ASIP36 – Vulnerability Management |
-Definition of necessary actions for vulnerability management. -Results evaluation -Documentation of actions taken. |
| -Need to encrypt IT devices, digital information, or IT services. | ASIP37 – Cryptographic Controls |
-Encryption process -Access PIN |
| -identification of the IT resource. | ASIP38 – Log Management |
-Logging to Syslog |

1. Monitoring and Oversight of Technology Investment Projects
2. Follow-up on the action plan and management indicators
3. Self-assessment and process monitoring
4. Users' perceptions of the services offered
5. Response time to user requests
Implement monitoring and review procedures to:
– Advise and supervise IT projects, both for the Directorate and for other administrative departments of the University of Cundinamarca.
– Conduct scheduled periodic reviews to assess residual risks and determine acceptable levels, taking into account potential changes in the institution, technology, objectives, and processes. In addition, the identified threats and the effectiveness of the controls in place should be analyzed, and the external environment—including legal requirements and contractual obligations, among other factors—should be evaluated.
– Run periodic self-assessments with the aim of understanding the status of the Management and determining whether the activities carried out by people and technological elements are being performed correctly in relation to what was planned.
- Successfully detect errors in a timely manner within the results generated by information processing.
– Comprehensive review of requests through the One-Click Service Desk to understand the nature of the requirement and provide solutions.
Advance actions for the continuous improvement of process performance, through:
- Corrective actions
- Improvement Plans
- Controls Arising from the Use of Information Systems
ASI Process Documents
There are no documents for this filter.
Digital Operating Model
Digital Operating Model
Digital Operating Model
Digital Operating Model
