<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>1646-9895</journal-id>
<journal-title><![CDATA[RISTI - Revista Ibérica de Sistemas e Tecnologias de Informação]]></journal-title>
<abbrev-journal-title><![CDATA[RISTI]]></abbrev-journal-title>
<issn>1646-9895</issn>
<publisher>
<publisher-name><![CDATA[AISTI - Associação Ibérica de Sistemas e Tecnologias de Informação]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S1646-98952024000100069</article-id>
<article-id pub-id-type="doi">10.17013/risti.53.69-87</article-id>
<title-group>
<article-title xml:lang="es"><![CDATA[Auditoría de riesgos de ciberseguridad: Revisión de Literatura, propuesta y aplicación]]></article-title>
<article-title xml:lang="en"><![CDATA[Cybersecurity Risk Audit: Literature Review, Proposal, and Application]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Sanchez-Garcia]]></surname>
<given-names><![CDATA[I.D.]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Rea-Guaman]]></surname>
<given-names><![CDATA[A.M.]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Feliu]]></surname>
<given-names><![CDATA[T. San]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Calvo-Manzano]]></surname>
<given-names><![CDATA[J.A.]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Universidad Politécnica de Madrid  ]]></institution>
<addr-line><![CDATA[Madrid ]]></addr-line>
<country>Spain</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Universidad de las Fuerzas Armadas Departamento de Ciencias de la Computación Sangolquí ]]></institution>
<addr-line><![CDATA[ ]]></addr-line>
<country>Ecuador</country>
</aff>
<pub-date pub-type="pub">
<day>30</day>
<month>03</month>
<year>2024</year>
</pub-date>
<pub-date pub-type="epub">
<day>30</day>
<month>03</month>
<year>2024</year>
</pub-date>
<numero>53</numero>
<fpage>69</fpage>
<lpage>87</lpage>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://scielo.pt/scielo.php?script=sci_arttext&amp;pid=S1646-98952024000100069&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.pt/scielo.php?script=sci_abstract&amp;pid=S1646-98952024000100069&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://scielo.pt/scielo.php?script=sci_pdf&amp;pid=S1646-98952024000100069&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen Una de las etapas de la gestión de riesgos de ciberseguridad es el monitoreo y la revisión. Esta etapa forma parte del proceso de mejora continua de un sistema de gestión de riesgos de ciberseguridad. Este artículo tiene como objetivo llevar a cabo una exploración de una guía de auditoría de riesgos de ciberseguridad tomando como referencia objetivos comunes y guías de la auditoría de riesgos de ciberseguridad. Para ello se tomó como partida una Revisión Sistemática de Literatura (SLR) considerando los estudios de los últimos diez años (2012-2022), a partir de los cuales se identificaron 23 estudios que mencionaban objetivos y guías de auditoría de riesgos de ciberseguridad. Además, se propusieron atributos que deben ser considerados para la creación de un guía de riesgos de ciberseguridad. Posteriormente en el presente trabajo se define una guía de auditoría de riesgos de ciberseguridad (CRAG). Finalmente, se expone la aplicación de CRAG por medio de un caso de estudio considerando los parámetros identificados en los estudios previamente mencionados.]]></p></abstract>
<abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract One of the stages of cybersecurity risk management is monitoring and review. This stage is part of the continuous improvement process of a cybersecurity risk management system. This article aims to conduct an exploration of a cybersecurity risk audit guide by referencing common objectives and guidelines of cybersecurity risk auditing. To do so, a Systematic Literature Review (SLR) was conducted considering studies from the last ten years (2012-2022), from which 23 studies mentioning cybersecurity risk audit objectives and guidelines were identified. Additionally, attributes to be considered for the creation of a cybersecurity risk guide were proposed. Finally, an application and validation of the identified parameters in the previously mentioned studies are presented.]]></p></abstract>
<kwd-group>
<kwd lng="es"><![CDATA[Auditoría de ciberseguridad]]></kwd>
<kwd lng="es"><![CDATA[Guía de auditoría]]></kwd>
<kwd lng="es"><![CDATA[Aseguramiento]]></kwd>
<kwd lng="es"><![CDATA[Cumplimiento, Mejora de la ciberseguridad, Monitoreo]]></kwd>
<kwd lng="es"><![CDATA[Revisión sistemática de literatura]]></kwd>
<kwd lng="es"><![CDATA[Aplicación]]></kwd>
<kwd lng="en"><![CDATA[Cybersecurity Audit]]></kwd>
<kwd lng="en"><![CDATA[Audit Guide]]></kwd>
<kwd lng="en"><![CDATA[Assurance]]></kwd>
<kwd lng="en"><![CDATA[Compliance]]></kwd>
<kwd lng="en"><![CDATA[Cybersecurity Enhancement, Monitoring]]></kwd>
<kwd lng="en"><![CDATA[Systematic Literature Review]]></kwd>
<kwd lng="en"><![CDATA[Implementation]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Congram]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[Epelman]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[How to describe your service]]></article-title>
<source><![CDATA[International Journal of Service Industry Management]]></source>
<year>1995</year>
<volume>6</volume>
<numero>2</numero>
<issue>2</issue>
<page-range>6-23</page-range></nlm-citation>
</ref>
<ref id="B2">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Duncan]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
<name>
<surname><![CDATA[Whittington]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Compliance with standards, assurance and audit: Does this equal security?]]></article-title>
<source><![CDATA[ACM International Conference Proceeding Series, 2014-September]]></source>
<year>2014</year>
<page-range>77-84</page-range></nlm-citation>
</ref>
<ref id="B3">
<nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Dyba]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Dingsoyr]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Hanssen]]></surname>
<given-names><![CDATA[G. K.]]></given-names>
</name>
</person-group>
<source><![CDATA[Applying Systematic Reviews to Diverse Study Types: An Experience Report]]></source>
<year>2007</year>
<conf-name><![CDATA[ First International Symposium on Empirical Software Engineering and Measurement (ESEM 2007)]]></conf-name>
<conf-loc> </conf-loc>
<page-range>225-34</page-range></nlm-citation>
</ref>
<ref id="B4">
<nlm-citation citation-type="">
<collab>European Confederation of Institutes of Internal Auditors</collab>
<source><![CDATA[Risk in focus 2021. Hot topics for internal auditors]]></source>
<year>2020</year>
</nlm-citation>
</ref>
<ref id="B5">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ezzamouri]]></surname>
<given-names><![CDATA[N.]]></given-names>
</name>
<name>
<surname><![CDATA[Hulstijn]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Continuous monitoring and auditing in municipalities]]></article-title>
<source><![CDATA[Proceedings of the 19th Annual International Conference on Digital Government Research: Governance in the Data Age]]></source>
<year>2018</year>
<page-range>1-10</page-range></nlm-citation>
</ref>
<ref id="B6">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Fernandez]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Black]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Jones]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Wilson]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
<name>
<surname><![CDATA[Salvador-Carulla]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
<name>
<surname><![CDATA[Astell-Burt]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Black]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Flooding and mental health: A systematic mapping review]]></article-title>
<source><![CDATA[PLoS ONE]]></source>
<year>2015</year>
<volume>10</volume>
<numero>4</numero>
<issue>4</issue>
</nlm-citation>
</ref>
<ref id="B7">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gale]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Bongiovanni]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Slapnicar]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead]]></article-title>
<source><![CDATA[Computers &amp; Security]]></source>
<year>2022</year>
<volume>121</volume>
</nlm-citation>
</ref>
<ref id="B8">
<nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Galligan]]></surname>
<given-names><![CDATA[M. E.]]></given-names>
</name>
<name>
<surname><![CDATA[Rau]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
</person-group>
<source><![CDATA[COSO in the cyber age]]></source>
<year>2015</year>
</nlm-citation>
</ref>
<ref id="B9">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gauthier]]></surname>
<given-names><![CDATA[M. P.]]></given-names>
</name>
<name>
<surname><![CDATA[Brender]]></surname>
<given-names><![CDATA[N.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[How do the current auditing standards fit the emergent use of blockchain?]]></article-title>
<source><![CDATA[Managerial Auditing Journal]]></source>
<year>2021</year>
<volume>36</volume>
<numero>3</numero>
<issue>3</issue>
<page-range>365-85</page-range></nlm-citation>
</ref>
<ref id="B10">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Ibrahim]]></surname>
<given-names><![CDATA[A.]]></given-names>
</name>
<name>
<surname><![CDATA[Valli]]></surname>
<given-names><![CDATA[C.]]></given-names>
</name>
<name>
<surname><![CDATA[McAteer]]></surname>
<given-names><![CDATA[I.]]></given-names>
</name>
<name>
<surname><![CDATA[Chaudhry]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A security review of local government using NIST CSF: a case study]]></article-title>
<source><![CDATA[Journal of Supercomputing]]></source>
<year>2018</year>
<volume>74</volume>
<numero>10</numero>
<issue>10</issue>
<page-range>5171-86</page-range></nlm-citation>
</ref>
<ref id="B11">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Islam]]></surname>
<given-names><![CDATA[Md. S.]]></given-names>
</name>
<name>
<surname><![CDATA[Farah]]></surname>
<given-names><![CDATA[N.]]></given-names>
</name>
<name>
<surname><![CDATA[Stafford]]></surname>
<given-names><![CDATA[T. F.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Factors associated with security/cybersecurity audit by internal audit function]]></article-title>
<source><![CDATA[Managerial Auditing Journal]]></source>
<year>2018</year>
<volume>33</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>377-409</page-range></nlm-citation>
</ref>
<ref id="B12">
<nlm-citation citation-type="">
<collab>Information Systems Audit and Control Association</collab>
<source><![CDATA[COBIT 2019]]></source>
<year>2018</year>
</nlm-citation>
</ref>
<ref id="B13">
<nlm-citation citation-type="">
<collab>International Organization for Standardization</collab>
<source><![CDATA[ISO IEC 27000 2018 Information technology - Information security Management systems - Overview and vocabulary]]></source>
<year>2018</year>
<page-range>1-26</page-range></nlm-citation>
</ref>
<ref id="B14">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kitchenham]]></surname>
<given-names><![CDATA[B.]]></given-names>
</name>
<name>
<surname><![CDATA[Pearl Brereton]]></surname>
<given-names><![CDATA[O.]]></given-names>
</name>
<name>
<surname><![CDATA[Budgen]]></surname>
<given-names><![CDATA[D.]]></given-names>
</name>
<name>
<surname><![CDATA[Turner]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Bailey]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Linkman]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Systematic literature reviews in software engineering - A systematic literature review]]></article-title>
<source><![CDATA[Information and Software Technology]]></source>
<year>2009</year>
<page-range>7-15</page-range><publisher-name><![CDATA[Elsevier B.V.]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B15">
<nlm-citation citation-type="">
<collab>National Institute of Standards and Technology</collab>
<article-title xml:lang=""><![CDATA[NIST cybersecurity framework]]></article-title>
<source><![CDATA[Proceedings of the Annual ISA Analysis Division Symposium]]></source>
<year>2018</year>
<volume>535</volume>
<page-range>9-25</page-range></nlm-citation>
</ref>
<ref id="B16">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Petersen]]></surname>
<given-names><![CDATA[K.]]></given-names>
</name>
<name>
<surname><![CDATA[Vakkalanka]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Kuzniarz]]></surname>
<given-names><![CDATA[L.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Guidelines for conducting systematic mapping studies in software engineering: An update]]></article-title>
<source><![CDATA[Information and Software Technology]]></source>
<year>2015</year>
<volume>64</volume>
<page-range>1-18</page-range></nlm-citation>
</ref>
<ref id="B17">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Sabillon]]></surname>
<given-names><![CDATA[R.]]></given-names>
</name>
<name>
<surname><![CDATA[Serra-Ruiz]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
<name>
<surname><![CDATA[Cavaller]]></surname>
<given-names><![CDATA[V.]]></given-names>
</name>
<name>
<surname><![CDATA[Cano]]></surname>
<given-names><![CDATA[J.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A comprehensive cybersecurity audit model to improve cybersecurity assurance: The cybersecurity audit model (CSAM)]]></article-title>
<source><![CDATA[Proceedings - 2017 International Conference on Information Systems and Computer Science, INCISCOS 2017]]></source>
<year>2018</year>
<page-range>253-9</page-range><publisher-name><![CDATA[Institute of Electrical and Electronics Engineers Inc]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B18">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Slapni&#269;ar]]></surname>
<given-names><![CDATA[S.]]></given-names>
</name>
<name>
<surname><![CDATA[Vuko]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[&#268;ular]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
<name>
<surname><![CDATA[Dra&#353;&#269;ek]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Effectiveness of cybersecurity audit]]></article-title>
<source><![CDATA[International Journal of Accounting Information Systems]]></source>
<year>2022</year>
<volume>44</volume>
</nlm-citation>
</ref>
<ref id="B19">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Stafford]]></surname>
<given-names><![CDATA[T.]]></given-names>
</name>
<name>
<surname><![CDATA[Deitz]]></surname>
<given-names><![CDATA[G.]]></given-names>
</name>
<name>
<surname><![CDATA[Li]]></surname>
<given-names><![CDATA[Y.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[The role of internal audit and user training in information security policy compliance]]></article-title>
<source><![CDATA[Managerial Auditing Journal]]></source>
<year>2018</year>
<volume>33</volume>
<numero>4</numero>
<issue>4</issue>
<page-range>410-24</page-range></nlm-citation>
</ref>
<ref id="B20">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Steinbart]]></surname>
<given-names><![CDATA[P. J.]]></given-names>
</name>
<name>
<surname><![CDATA[Raschke]]></surname>
<given-names><![CDATA[R. L.]]></given-names>
</name>
<name>
<surname><![CDATA[Gal]]></surname>
<given-names><![CDATA[G.]]></given-names>
</name>
<name>
<surname><![CDATA[Dilla]]></surname>
<given-names><![CDATA[W. N.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[The relationship between internal audit and information security: An exploratory investigation]]></article-title>
<source><![CDATA[International Journal of Accounting Information Systems]]></source>
<year>2012</year>
<volume>13</volume>
<numero>3</numero>
<issue>3</issue>
<page-range>228-43</page-range></nlm-citation>
</ref>
<ref id="B21">
<nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Steinbart]]></surname>
<given-names><![CDATA[P. J.]]></given-names>
</name>
<name>
<surname><![CDATA[Raschke]]></surname>
<given-names><![CDATA[R. L.]]></given-names>
</name>
<name>
<surname><![CDATA[Gal]]></surname>
<given-names><![CDATA[G.]]></given-names>
</name>
<name>
<surname><![CDATA[Dilla]]></surname>
<given-names><![CDATA[W. N.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[SECURQUAL: An Instrument for Evaluating the Effectiveness of Enterprise Information Security Programs]]></article-title>
<source><![CDATA[Journal of Information Systems]]></source>
<year>2016</year>
<volume>30</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>71-92</page-range></nlm-citation>
</ref>
<ref id="B22">
<nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Yin]]></surname>
<given-names><![CDATA[R. K.]]></given-names>
</name>
</person-group>
<source><![CDATA[Case Study Research and Applications]]></source>
<year>2018</year>
<edition>Sixth Edition</edition>
<publisher-name><![CDATA[SAGE Publications India Pvt. Ltd]]></publisher-name>
</nlm-citation>
</ref>
</ref-list>
</back>
</article>
