Modelo estadístico para evaluar la efectividad de políticas de ciberseguridad empresarial

dc.contributor.advisorLópez Gonzales, Javier Linkolk
dc.contributor.authorDelgado Paucar, Katherine
dc.date.accessioned2026-10-05T16:04:53Z
dc.date.embargoEnd2028-09-28
dc.date.issued2026-09-28
dc.description.abstractOrganizations increasingly adopt frameworks such as ISO/IEC 27001 and the NIST Cybersecurity Framework 2.0, yet the performance of the resulting cybersecurity policies is still assessed mainly through compliance checklists and qualitative judgment. Incident records, which most organizations already collect, are rarely exploited as quantitative evidence of policy performance. This study proposes a reproducible statistical framework, grounded in the Knowledge Discovery in Databases (KDD) process, that converts cybersecurity incident records into quantitative evidence to support policy-performance assessment. The framework integrates exploratory data analysis (EDA), principal component analysis (PCA), K-Means clustering, and dispersion-aware generalized linear modeling (GLM) of incident counts, and is implemented as an interactive R Shiny decision-support application. Its behavior was demonstrated on a public synthetic dataset of 100,000 cybersecurity incidents. The first four principal components explained 84.48% of the total variance; PC1 (28.75%) captured incident containment (resilience, attack duration, and response time) and PC2 (27.14%) incident volume and economic impact. K-Means yielded three exploratory technical profiles, although the mean silhouette coefficient (0.185) indicated weak cluster separation. The Poisson reference model was markedly underdispersed (Pearson dispersion ratio = 0.353); therefore, inference was based on a quasi-Poisson model with a log link. Log-transformed economic impact was positively associated with expected incident frequency (β=0.747; IRR ≈2.11; p<0.001), whereas mean severity was negatively associated with it (β=-0.139; IRR ≈0.870; p<0.001). Cross-site scripting differed statistically from the reference attack category, but with a negligible effect size (IRR = 0.981; p=0.011). Because the synthetic incidents are close to uniformly distributed, the built-in diagnostics correctly signaled weak structure instead of producing spurious risk categories, illustrating the value of explicit interpretive safeguards. The main contribution is methodological: an end-to-end, transparent, and reproducible workflow that organizations can apply to their own incident logs to monitor policy performance over time. Validation with real organizational incident records is the necessary next step.
dc.description.escuelaEscuela de Posgrado
dc.description.lineadeinvestigacionModelos estadísticos
dc.description.sedeLima
dc.formatapplication/pdf
dc.identifier.urihttps://hdl.handle.net/20.500.12840/10766
dc.language.isospa
dc.publisherUniversidad Peruana Unión
dc.publisher.countryPE
dc.rightsinfo:eu-repo/semantics/embargoedAccess
dc.rights.urihttps://creativecommons.org/licenses/by-nc/4.0/
dc.subjectCybersecurity policy assessment
dc.subjectKnowledge discovery in databases
dc.subjectIncident analytics
dc.subject.ocdehttps://purl.org/pe-repo/ocde/ford#1.01.03
dc.titleModelo estadístico para evaluar la efectividad de políticas de ciberseguridad empresarial
dc.typeinfo:eu-repo/semantics/bachelorThesis
renati.advisor.dni46071566
renati.advisor.orcidhttps://orcid.org/0000-0003-0847-0552
renati.author.dni70884007
renati.discipline54202992
renati.jurorHuanca Lopez, Lizeth Geanina
renati.jurorGonzales Garay, Jhon Harol
renati.jurorTocto Cano, Esteban
renati.jurorOrrego Granados, David Leandro
renati.levelhttps://purl.org/pe-repo/renati/level#tituloSegundaEspecialidad
renati.typehttps://purl.org/pe-repo/renati/type#tesis
thesis.degree.disciplineSEGUNDA ESPECIALIDAD EN ESTADÍSTICA APLICADA PARA INVESTIGACIÓN
thesis.degree.grantorUniversidad Peruana Unión. Unidad de Posgrado de Ingeniería y Arquitectura
thesis.degree.nameSegunda Especialidad Profesional de Ingeniería: Estadística Aplicada para Investigación

Archivos

Bloque original

Mostrando 1 - 3 de 3
Cargando...
Miniatura
Nombre:
Katherine_Tesis_Especialidad_2026.pdf
Tamaño:
181,46 KB
Formato:
Adobe Portable Document Format
Cargando...
Miniatura
Nombre:
Autorización.pdf
Tamaño:
243,84 KB
Formato:
Adobe Portable Document Format
Cargando...
Miniatura
Nombre:
Reporte de similitud.pdf
Tamaño:
5,54 MB
Formato:
Adobe Portable Document Format