Ingeniería en Sistemas, Electrónica e Industrial
Permanent URI for this communityhttp://repositorio.uta.edu.ec/handle/123456789/1
Browse
5 results
Search Results
Item Sistema de gestión de seguridad de la información (SGSI) basado en la Norma ISO 27001 para el control de la seguridad informática de la empresa Epc-Compu de la ciudad de Ambato(Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas, Electrónica e Industrial. Carrera de Tecnologías de la Información, 2023-09) Sailema Fiallos, Soraya Cristina; Balarezo, Julio EnriqueActually, data has become a valuable resource for organizations and its control demands a thorough analysis in order to protect them from possible risks to which they are exposed. In this manner, it seeks to ensure the integrity, confidentiality and accessibility of information. The present research proyect aims to implement an information security management system (ISMS) based on the ISO 27001 standard for the control of computer security of the company EPCCOMPU in Ambato city. First, a study of ISO 27001 was carried out to create a manual based on the ISO 27001:2013 standard, which contains the necessary points that must be followed to correctly implement an Information Security Management System, then an analysis of the current state of computer security through the collection of information from interviews and an observation sheet that allowed obtaining a starting point for the design of the ISMS, an analysis of the critical processes of the company EPC-COMPU to perform risk assessment in order to identify and analyze the vulnerabilities and threats involved in the management of information security for this analysis, the necessary controls of the ISO 27001 standard were selected, then risk management was carried out identifying prevention, detection and correction by consequence detailed in the contingency plan. Finally, monitoring and control processes were developed to define the activities with their respective managersItem Plan de mantenimiento para la maquinaria de la línea de producción de la empresa lácteos La Victoria(Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas, Electrónica e Industrial. Carrera de Ingeniería Industrial, 2023-08) Lema Chicaiza, Marlon René; Urrutia Urrutia, FernandoThe objective of this research project was the management of a maintenance plan for the machinery of the production line within the dairy company “La Victoria”, with the purpose of the organization can preserve and maintain the equipment with suitable conditions for the development of daily free activities of events that are not scheduled within its facilities. With the processed data of the machinery operation of the production line, the current state of maintenance was analyzed by calculating the maintenance indicators such as operating time, average time between failures, average time to repair, failure rate, reliability and availability to obtain the status of each of the machines. For a visual analysis, it was used the graph of the bathtub curve, which allows to identify in which stage of useful life the equipment is. To identify the components that are most prone to failure within the production line, the AMFE matrix that is certified by NTP 679 was used. Each of the components were evaluated with the standard criteria such as detectability, severity and frequency that the product of the 3 results in the risk priority index, wich according to the standard, if it exceeds a value of 100, it is considered a critical component. For the maintenance plan proposal, a maintenance log was prepared with prospects of high, medium and low criticality for each of the necessary activities to preserve and extend the useful life of the machinery. The log has the schedule of activities to carry out maintenance, whether daily, weekly or monthly, which it is stipulated for a duration of a normal year of work, so that the company can maintain or improve the availability and current status of the production lineItem Plan de mantenimiento preventivo para la maquinaria pesada y vehículos livianos del gobierno autónomo descentralizado municipal del cantón San Cristóbal de Patate(Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas, Electrónica e Industrial. Carrera de Industrial, 2023-03) Centeno Guevara, Darío Javier; Urrutia, FernandoThe present research work has been developed taking into consideration the needs of the public institution GADM Patate, focusing on heavy machinery and light vehicles of the automotive park of the institution, in order to provide a practical tool for the performance of maintenance activities within the mechanical workshop that allows to improve the availability of equipment for the development of field work of both heavy machinery and light vehicles and therefore also extend the useful life of the same. As a starting point of the research project, once the data processing of the history of the mechanical workshop of each machinery and light vehicle has been carried out, the calculation of maintenance indicators such as the average time between failures, average repair time, failure rate, stop rate and availability has been carried out, which as a starting point allows to know the current status of each unit of heavy machinery and light vehicle of the GADM Patate automotive park. To determine which mechanical components are more likely to suffer failures or damage, the modal analysis of failures and effects (AMFE) has been carried out, endorsed by the NTP 679, which indicates within its content the guidelines for the application of this methodology in equipment. The critical components have been characterized by calculating the risk priority index, the norm mentions that the components assigned with a rating greater than 100 will be considered critical and intervention or prevention actions must be taken. The maintenance plan is made up of a maintenance log where the preventive maintenance activities are detailed considering the critical and main components that make up the heavy machinery and light vehicles, within the maintenance log the machine, systems, components, maintenance activities, frequency in which the activities should be carried out are also detailed. In this way, maintenance tasks have been scheduled for one year of operation, all this in order to improve availability and keep machinery and vehicles in good conditionItem Auditoría informática aplicando la Norma ISO 27001 para optimizar la seguridad de la información en el Departamento de Tic’s del Centro de Investigación y Desarrollo FAE.(Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas, Electrónica e Industrial. Carrera de Ingeniería en Sistemas Computacionales e Informáticos, 2022-06) Chagmana Pomaquero, Remigio Leonel; Mayorga Mayorga, Franklin OswaldoAt present, information is one of the most important assets within any organization, its security and administration require a complete analysis to identify any risk to which it is exposed so that in this way the integrity, confidentiality and availability of the information is guaranteed. information optimally. The purpose of the research project is to minimize risks and provide security to the information that is handled daily in the ICT Department of the FAE Research and Development Center, through the application of information security policies that are based on the standard ISO27001. First, an analysis of the current state of security in the ICT Department was carried out through the application of interviews and surveys, which were applied to the Chief and the employees of the aforementioned department. The methodology used was based on the Deming cycle, which is made up of 4 phases (Plan, Implement, Verify and Act), in which each phase constitutes act ivities that allow planning, determining its scope, making an inventory of information assets and the valuation of assets with the aim of determining and analyzing the risks, threats and vulnerabilities that intervene in the management of information security. Afterwards, an Information Security Plan was prepared in which the Scope, Characterization, Risk Analysis and the Creation of new Information Security Policies will be defined for approval and application in the ICT Department on FAE Research and Development Center, with this it is expected that the Head and employees of the Department comply with the policies established to guarantee adequate control in the areas where there are shortcomings in terms of information security, maintain constant monitoring in the corresponding areas.Item Plan de contingencia informático basado en la norma ISO 24762:2008 para el departamento de tecnologías de la información del Gobierno Autónomo Descentralizado de la Municipalidad de Ambato(Universidad Técnica de Ambato. Facultad de Ingeniería en Sistemas, Electrónica e Industrial. Carrera de Ingeniería en Sistemas Computacionales e Informáticos, 2022-03) Nuñez Santamaría, Adriana Cristina; Balarezo, JulioA computer contingency plan for the IT department (Information Technologies) of the Autonomous Decentralized Government of the Municipality of Ambato aims to identify risks, whether of natural or human origin that may occur and cause damage to the most important assets, for By means of this, the risks may be reduced or mitigated and in this way to be able to protect the information to guarantee its confidentiality, integrity and availability, for the normal functioning of the activities that the institution offers to all citizens. The IT department is in charge of administering and managing in the best way the information and services of the institution, which may be exposed to threats that harm its confidentiality, integrity and availability, partially or totally interrupting the operations of the institution. For this reason, an updated IT contingency plan must be in place to reduce any IT eventualities that may arise, so that the institution continues to operate. This research project proposes the Design of a Computer Contingency Plan based on the ISO 24762: 2008 standard, which describes the guidelines for Information and Communications Technology disasters. The plan will describe what actions to take in the event of a catastrophic event that affects the continuity of the institution's activities, reducing the impact of mitigation measures before, during and after the materialization of threats, and thus prevent the loss of valuable information for the institution. institution.