Application of MAGERIT to reduce risks in Web services in an academic context in Ecuador.

Main Article Content

Diego Jácome Segovia
Jessica Castillo Fiallos
Carmita Mantilla Cabrera
Byron Ernesto Vaca Barahona

Abstract

This study presents an adaptation of the MAGERIT methodology that allows us to manage the IT security risks of a company's web services. For this purpose, the first step was to determine the company’s information assets along with possible threats, and in the event of materialization the impact of these threats was then measured to identify the safeguards of these assets. After this, a web services vulnerability detection test was performed using a free software tool called VEGA. Finally, the level of risk was determined so that IT staff will be better able to make future decisions. In the analysis of the vulnerability of web services, the most common vulnerabilities found were: SQL Injection, PHP Error Detected and Directory Listing Detected, among others. With the implementation of this model, high risk vulnerabilities were reduced to 87.87% and 12.13% of all vulnerabilities were eliminated. 

Downloads

Download data is not yet available.

Article Details

How to Cite
Jácome Segovia, D., Castillo Fiallos, J., Mantilla Cabrera, C., & Vaca Barahona, B. E. (2021). Application of MAGERIT to reduce risks in Web services in an academic context in Ecuador. AlfaPublicaciones, 3(2.2), 66–82. https://doi.org/10.33262/ap.v3i2.2.60
Section
Artículos

Similar Articles

You may also start an advanced similarity search for this article.

Most read articles by the same author(s)