Modelo estadístico para evaluar la efectividad de políticas de ciberseguridad empresarial

Cargando...
Miniatura

Título de la revista

ISSN de la revista

Título del volumen

Editor

Universidad Peruana Unión

DOI

Resumen

Organizations increasingly adopt frameworks such as ISO/IEC 27001 and the NIST Cybersecurity Framework 2.0, yet the performance of the resulting cybersecurity policies is still assessed mainly through compliance checklists and qualitative judgment. Incident records, which most organizations already collect, are rarely exploited as quantitative evidence of policy performance. This study proposes a reproducible statistical framework, grounded in the Knowledge Discovery in Databases (KDD) process, that converts cybersecurity incident records into quantitative evidence to support policy-performance assessment. The framework integrates exploratory data analysis (EDA), principal component analysis (PCA), K-Means clustering, and dispersion-aware generalized linear modeling (GLM) of incident counts, and is implemented as an interactive R Shiny decision-support application. Its behavior was demonstrated on a public synthetic dataset of 100,000 cybersecurity incidents. The first four principal components explained 84.48% of the total variance; PC1 (28.75%) captured incident containment (resilience, attack duration, and response time) and PC2 (27.14%) incident volume and economic impact. K-Means yielded three exploratory technical profiles, although the mean silhouette coefficient (0.185) indicated weak cluster separation. The Poisson reference model was markedly underdispersed (Pearson dispersion ratio = 0.353); therefore, inference was based on a quasi-Poisson model with a log link. Log-transformed economic impact was positively associated with expected incident frequency (β=0.747; IRR ≈2.11; p<0.001), whereas mean severity was negatively associated with it (β=-0.139; IRR ≈0.870; p<0.001). Cross-site scripting differed statistically from the reference attack category, but with a negligible effect size (IRR = 0.981; p=0.011). Because the synthetic incidents are close to uniformly distributed, the built-in diagnostics correctly signaled weak structure instead of producing spurious risk categories, illustrating the value of explicit interpretive safeguards. The main contribution is methodological: an end-to-end, transparent, and reproducible workflow that organizations can apply to their own incident logs to monitor policy performance over time. Validation with real organizational incident records is the necessary next step.

Descripción

Citación

Aprobación

Revisión

Complementado por

Referenciado por

Licencia Creative Commons

Excepto donde se indique lo contrario, la licencia de este ítem se describe como info:eu-repo/semantics/embargoedAccess