Estudio sobre seguridad de la información y continuidad de negocio en las empresas españolas

download Estudio sobre seguridad de la información y continuidad de negocio en las empresas españolas

of 126

Transcript of Estudio sobre seguridad de la información y continuidad de negocio en las empresas españolas

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    1/126

    Cw}smal wlbrc wcisramnm mc fn

    aojlrengao q glo}aosamnm mc ocilgal

    co fnw ce{rcwnw cw{nlfnw

    AOW]A]S]L ONGALONF MC ]CGOLFLINW MC FN GLESOAGNGAO

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    2/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 2 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Cmagao8 Wc{}acebrc 2;>2

    Cf Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw

    cw{nlfnw `n waml cfnblrnml {lr cf Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    (AO]CGL!8

    [nbfl [rcx Wno%Hlw (marcggao!

    Graw}aon Is}arrcx Blric (gllrmaongao!

    Cmsnrml fznrcx Nflowl

    Fnsrn Inrgn [rcx

    Wswnon mc fn Jsco}c Rlmriscx

    AO]CGL ~sacrc wcnfnr cf n{lql }goagl co fn rcnfaxngao mc fn aozcw}aingao mc8

    Fn {rcwco}c {sbfagngao {cr}cocgc nf Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao (AO]CGL! q cw} bnhl sonfagcogan Rcglolgaeaco}l%Ol glecrganf 7/; Cw{nn mc Grcn}azc Gleelow& q {lr cffl cw} {crea}aml gl{anr& maw}rabsar qglesoagnr {bfagneco}c cw}n lbrn bnhl fnw glomagalocw waisaco}cw8

    Rcglolgaeaco}l8 Cf glo}coaml mc cw}c aojlrec wc {scmc rc{rlmsgar }l}nf l {nrganfeco}c {lr }crgcrlw& ga}noml ws{rlgcmcogan q `ngacoml rcjcrcogan cp{rcwn }no}l n AO]CGL glel n ws wa}al ycb8 yyy/ao}cgl/cw/ Mag`lrcglolgaeaco}l ol {lmr co oaoio gnwl wsicrar ~sc AO]CGL {rcw}n n{lql n mag`l }crgcrl l n{lqn cf swl ~sc `ngcmc ws lbrn/

    Swl Ol Glecrganf8 Cf en}cranf lraiaonf q flw }rnbnhlw mcraznmlw {scmco wcr maw}rabsamlw& gl{anmlw q cp`abamlweaco}rnw ws swl ol }coin jaocw glecrganfcw/

    Nf rcs}afaxnr l maw}rabsar fn lbrn& }acoc ~sc mchnr baco gfnrl flw }reaolw mc fn fagcogan mc cw}n lbrn/ Nfison mc cw}nwglomagalocw {scmc ol n{fagnrwc wa wc lb}acoc cf {creawl mc AO]CGL glel }a}sfnr mc flw mcrcg`lw mc ns}lr/ Onmn co cw}nfagcogan ecolwgnbn l rcw}raoic flw mcrcg`lw elrnfcw mc AO]CGL/`}}{8,,grcn}azcgleelow/lri,fagcowcw,bq%og,7/;,cw,

    Cf {rcwco}c mlgseco}l gse{fc glo fnw glomagalocw mc nggcwabafamnm mcf jlren}l [MJ ([lr}nbfc Mlgseco} Jlren}!/ Nw& wc}rn}n mc so mlgseco}l cw}rsg}srnml q c}a~sc}nml& {rlzaw}l mc nf}cron}aznw n }lml cfceco}l ol }cp}snf& enrgnml mc amalen qlrmco mc fcg}srn nmcgsnml/

    [nrn lb}cocr ew aojlrengao wlbrc fn glow}rsggao mc mlgseco}lw nggcwabfcw co jlren}l [MJ {scmc glowsf}nr fn isnmaw{loabfc co fn wcggao Nggcwabafamnm ? Majswao ? Enosnfcw q Isnw& mcfn {iaon ycb mc AO]CGLyyy/ao}cgl/cw

    http://creativecommons.org/licenses/by-nc/3.0/es/http://creativecommons.org/licenses/by-nc/3.0/es/http://creativecommons.org/licenses/by-nc/3.0/es/http://www.inteco.es/http://www.inteco.es/http://www.inteco.es/http://www.inteco.es/http://creativecommons.org/licenses/by-nc/3.0/es/
  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    3/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 7 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    OMAGC

    [SO]LW GFNZC //////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// 3A [rl}cggao mc fn ce{rcwn cw{nlfn /////////////////////////////////////////////////////////////////////////////////// 3AA Aogamco}cw mc wcisramnm co fn ce{rcwn cw{nlfn ////////////////////////////////////////////////////////////// 9AAA C%glojanoxn ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// 0AZ Rcglecomngalocw ////////////////////////////////////////////////////////////////////////////////////////////////////////////// 0

    > AO]RLMSGGAO Q LBHC]AZLW ///////////////////////////////////////////////////////////////////////////////////////////// >;>/> [rcwco}ngao ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////// >;>/2 Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnwcw{nlfnw ///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// >2

    2 EC]LMLFLIN /////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// >=2/> Jnwc >8 nofawaw mlgseco}nf ///////////////////////////////////////////////////////////////////////////////////////////// >=2/2 Jnwc 28 cogscw}n n ce{rcwnw ////////////////////////////////////////////////////////////////////////////////////////// >=2/7 Jnwc 78 co}rczaw}nw co {rljsomamnm ////////////////////////////////////////////////////////////////////////////////// 2;2/=

    Jnwc =8 irs{l mc }rnbnhl jaonf glo cp{cr}lw gsnfajagnmlw ///////////////////////////////////////////////// 22

    7 @CRRNEACO]NW ]GOAGNW Q [CRWLONF MC WCISRAMNM ///////////////////////////////////////////// 2=

    7/> @crrneaco}nw mc wcisramnm co fn ce{rcwn cw{nlfn8 ae{fno}ngao q el}azngao /////////// 237/2 Wcisramnm co maw{lwa}azlw ezafcw q glesoagngalocw aonfebragnw //////////////////////////////// 217/7 [crwlonf mcmagnml n fn wcisramnm mc fn aojlrengao /////////////////////////////////////////////////////// 777/= Cw}rn}cian glr{lrn}azn co wcisramnm c ae{fagngao mc fn marcggao ////////////////////////////////// 7:

    = BSCONW [RG]AGNW MC WCISRAMNM //////////////////////////////////////////////////////////////////////////////// 70=/> Gl{anw mc wcisramnm///////////////////////////////////////////////////////////////////////////////////////////////////////// 70=/2 Ng}snfaxngao mc {rlirnenw q waw}cenw /////////////////////////////////////////////////////////////////////////// =7=/7 Ecmamnw mc glo}rlf mc nggcwl n c~sa{lw q mlgseco}lw ///////////////////////////////////////////////// ===/= Bsconw {rg}agnw co maw{lwa}azlw ezafcw //////////////////////////////////////////////////////////////////////// =3=/3 Bsconw {rg}agnw {nrn flw ce{fcnmlw ///////////////////////////////////////////////////////////////////////////// =:

    3 [FNOCW Q [LF]AGNW MC WCISRAMNM /////////////////////////////////////////////////////////////////////////////// 3;3/> [crgc{gao mc fn ce{rcwn wlbrc {fnocw q {lf}agnw mc wcisramnm /////////////////////////////////// 3;3/2 Nofawaw mcf glolgaeaco}l wlbrc ecmamnw l [fnocw mc Glo}aosamnm mc Ocilgal //////////// 32

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    4/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon = mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    3/7 Wa}sngao mc wcisramnm mc fn ce{rcwn cw{nlfn mcwmc cf {so}l mc zaw}n mc fn glo}aosamnmmc ocilgal //////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// 3=

    : AOGAMCO]CW MC WCISRAMNM CO FN CE[RCWN8 AOGAMCOGAN& AE[NG]L Q RCW[SCW]N /////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// ::

    :/> [crgc{gao mc fnw ce{rcwnw wlbrc fn czlfsgao icocrnf mc flw aogamco}cw mc fn wcisramnm////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// ::

    :/2 [crgc{gao mc fnw ce{rcwnw wlbrc wsw aogamco}cw mc wcisramnm //////////////////////////////////// :9:/7 Ae{ng}l q glowcgscoganw mc flw aogamco}cw ///////////////////////////////////////////////////////////////////// 9=:/= Rcw{scw}n mc fnw ce{rcwnw jrco}c n flw aogamco}cw mc wcisramnm /////////////////////////////////// 99

    9 C%GLOJANOXN MC FN [C^SCN Q ECMANON CE[RCWN CW[NLFN /////////////////////////////// 0>9/> C%glojanoxn co fn Wlgacmnm mc fn Aojlrengao ///////////////////////////////////////////////////////////////// 039/2 Jrcolw nf mcwnrrlffl mc fn Wlgacmnm mc fn Aojlrengao //////////////////////////////////////////////////// 1=

    0 [CRJAFCW MC WCISRAMNM Q GLO]AOSAMNM MC OCILGAL CO FN CE[RCWN //////////////// 1:0/> [crjafcw rcfngalonmlw glo fn wcisramnm mc fn aojlrengao q c%glojanoxn ///////////////////////// 1:0/2 [crjafcw rcfngalonmlw glo fn glo}aosamnm mc ocilgal ///////////////////////////////////////////////////// >;>

    1 GLOGFSWALOCW /////////////////////////////////////////////////////////////////////////////////////////////////////////////////// >;:1/> [so}lw mbafcw //////////////////////////////////////////////////////////////////////////////////////////////////////////////// >;:1/2 [so}lw jscr}cw //////////////////////////////////////////////////////////////////////////////////////////////////////////////// >;91/7 Neconxnw /////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// >;01/= L{lr}soamnmcw //////////////////////////////////////////////////////////////////////////////////////////////////////////////// >;1

    >; RCGLECOMNGALOCW MC NG]SNGAO ////////////////////////////////////////////////////////////////////////// >>>>;/> Rcglecomngalocw {nrn fn eagrl& {c~scn q ecmanon ce{rcwn /////////////////////////////////// >>>>;/2 Rcglecomngalocw maraiamnw n fn aomsw}ran mc wcisramnm //////////////////////////////////////////////// >>=>;/7 Rcglecomngalocw maraiamnw n fn Nmeaoaw}rngao [bfagn /////////////////////////////////////////////// >>:

    OMAGC MC IRJAGLW ///////////////////////////////////////////////////////////////////////////////////////////////////////////////// >>0OMAGC MC ]NBFNW ////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// >22NOCPL A8 BABFALIRNJN ////////////////////////////////////////////////////////////////////////////////////////////////////////////// >27

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    5/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 3 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    [SO]LW GFNZC

    Cf Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw

    rcnfaxn so maniow}agl mc fn {crgc{gao wlbrc cf oazcf mc {rc{nrngao no}c flw racwilw mc wcisramnm

    q fn nml{gao mc cw}rn}cianw mc glo}aosamnm mc ocilgal {lr {nr}c mc fnw {c~scnw q ecmanonw

    ce{rcwnw cw{nlfnw ~sc s}afaxno Ao}croc} glel {nr}c mc ws ocilgal co 2;>2/

    [nrn ffcznr n gnbl fn aozcw}aingao& wc `n mcwnrrlffnml son ec}lmlflin ~sc gle{rcomc8

    cogscw}nw n son escw}rn rc{rcwco}n}azn mc ce{rcwnw cw{nlfnw mc ecolw mc 23; ce{fcnmlw

    rc{nr}amnw {lr }lml cf }crra}lral ongalonf q co}rczaw}nw co {rljsomamnm n rcw{lownbfcw co wcisramnm

    mc fn aojlrengao mc fnw ce{rcwnw/ Nwaeawel& Flw rcwsf}nmlw mc fn cogscw}n `no waml wlec}amlw n

    fn glowamcrngao mc so irs{l mc cp{cr}lw& gsqnw n{lr}ngalocw `no waml cwcoganfcw {nrn fn

    gle{rcowao mc fn wa}sngao mc fn ce{rcwn cw{nlfn/

    N glo}aosngao wc cp{loco flw {so}lw gfnzc mcf cw}smal/

    A [RL]CGGAO MC FN CE[RCWN CW[NLFN

    Co icocrnf& cf glfcg}azl mc {c~scnw q ecmanonw ce{rcwnw cw{nlfnw mcgfnrno so ol}nbfc

    irnml mc ae{fno}ngao mc fnw `crrneaco}nw mc wcisramnm bwagnw& olrenfeco}c aogfsamnw co

    wlfsgalocw {n~sc}axnmnw/ Nso~sc cw}nw {crgabco ~sc fn wcisramnm `n echlrnml co cf f}ael

    nl& cpaw}c so enrico mc echlrn co gsno}l n fn aoglr{lrngao mc ecmamnw ew nff mc fnw

    }rnmagalonfcw& ~sc nbnr~sco ol wfl cf gle{loco}c }goagl& waol }nebao cf lrinoaxn}azl q

    cw}rn}iagl/

    No}azarsw q glr}njscilw wlo `crrneaco}nw ~sc {rcwco}no son ne{fan {coc}rngao co fnw

    lrinoaxngalocw (so 1:&># q so 93&=#& rcw{cg}azneco}c!/ [lr mc}rw mc cw}nw wc wa}no

    ecmamnw ~sc ae{fagno fn {nr}aga{ngao mcf swsnral l {rl{lrgalono jsogalonfamnmcw

    cw{cgjagnw/

    Flw maw{lwa}azlw ezafcw& gnmn zcx glo ew {cwl co fnw ce{rcwnw& cw}o ecolw

    {rl}ciamlw ~sc flw c~sa{lw aojlre}aglw/ Nw& so 1:&># mc flw lrmconmlrcw maw{loc mc

    no}azarsw& {lrgco}nhc ~sc mcwgacomc nf 2>&0# co }creaonfcw ezafcw/

    Rcw{cg}l n fn {rl}cggao mc fn rcm aonfebragn yaja& cw ocgcwnral cp}comcr fn aoglr{lrngaomc flw cw}omnrcw Y[N,Y[N2/ Co cf {rcwco}c aojlrec& Y[N,Y[N2 q YC[ (cw}omnr

    aowcisrl! wlo mcgfnrnmlw co fn eawen {rl{lrgao (so 29&=#!/

    So 3:&7# mc fnw ce{rcwnw cw{nlfnw njareno maw{locr mc rcgsrwlw `senolw mcw}aonmlw

    n fn wcisramnm mc fn aojlrengao (so 2>&; # ecmano}c {crwlonf ao}crol q so 73&7# n }rnzw

    mc son ce{rcwn cp}cron!/

    Mc jlren icocrnf& fnw ce{rcwnw l{aono ~sc fn wcisramnm mc fn aojlrengao `n

    czlfsgalonml jnzlrnbfceco}c co cf f}ael nl (so 9;&2# aomagno ~sc cw}n cw aisnf l

    ws{cralr n fn mc 2;>>!/ So jng}lr ~sc aojfsqc co fn czlfsgao cw cf ne{fal gle{rleawl mc fnmarcggao {lr fn {rl}cggao mc fn aojlrengao (so 92&7# fl glowamcrno esq l bnw}no}c

    ae{lr}no}c!/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    6/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon : mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Hso}l glo fnw `crrneaco}nw& fnw lrinoaxngalocw nml{}no co irno ecmamn `ba}lw mc

    {rl}cggao glel fnw gl{anw mc wcisramnm l fn ng}snfaxngao mcf waw}cen l{crn}azl q

    {rlirnenw/ Cf cwjscrxl mcbc maraiarwc n fn glogacogangao q jlrengao co fn nmcgsnmn

    s}afaxngao mc fnw eawenw/

    Co bnwc n fnw mcgfnrngalocw mc fnw ce{rcwnw& cw rcwcnbfc fn nml{gao enqlra}nran mc

    {rg}agnw glel fn rcnfaxngao mc gl{anw mc wcisramnm (so 00&2#!& fn ng}snfaxngao mcf

    waw}cen l{crn}azl q flw {rlirnenw (0>&1#! q fnw ecmamnw mc glo}rlf mc nggcwl n c~sa{lw q

    mlgseco}lw (:1&>#!/

    Cw}nw {rg}agnw mcbco ngle{nnrwc mc fnw ng}sngalocw ocgcwnranw ~sc inrno}agco fn

    maw{loabafamnm& ao}ciramnm q glojamcoganfamnm mc fn aojlrengao/ [lr chce{fl& cw}nbfcgacoml

    nmcgsnmneco}c fn jrcgscogan mc rcnfaxngao& cf {rlgcmaeaco}l& fn sbagngao& c}g/

    [lr cf glo}rnral& fnw {qecw mcescw}rno cw}nr ecolw glogacoganmnw {lr fn {rl}cggao mc

    fnw }cgolflinw ezafcw q wfl so >>&9# maw{loc mc {lf}agnw mc swl wcisrl {nrn flw

    swsnralw mc mag`lw maw{lwa}azlw/

    Nwaeawel& flw `ba}lw {rsmco}cw maraiamlw n flw ce{fcnmlw wlo ew eaolra}nralw& glel fn

    faea}ngao mc nggcwl n Ao}croc} (2>&7#!& fn aow}nfngao mc {rlirnenw n }rnzw mc so

    rcw{lownbfc (=3&7#! l fn jlrengao co wcisramnm {nrn flw }rnbnhnmlrcw (29&7#!/

    Fn nml{gao mc {fnocw q {lf}agnw mc wcisramnm ~sc {crea}no nwcisrnr fn maw{loabafamnm&

    ao}ciramnm q glojamcoganfamnm mc fn aojlrengao cw }lmnzn son nwaion}srn {comaco}c {nrn

    son irno {nr}c mc fn ce{rcwn cw{nlfn/ ]no}l {lr cf mcwglolgaeaco}l mc fl ~sc gloffczn

    maw{locr mc son cw}rn}cian mc glo}aosamnm mc ocilgal& glel mc fn jnf}n mc glowamcrngao mc

    cw}nw cw}rn}cianw glel aozcrwalocw ~sc {crea}no fn glo}aosamnm mc fnw l{crngalocw co gnwl

    mc mcwnw}rc/

    Fnw {c~scnw q ecmanonw ce{rcwnw grcco rcnfaxnr nsma}lrnw mc wcisramnm q maw{locr mc

    gcr}ajagngalocw co Waw}cenw mc Icw}ao mc fn Wcisramnm mc fn Aojlrengao (WIWA! co enqlr

    ecmamn ~sc fl ~sc njareno flw mn}lw ljaganfcw/ Neblw jng}lrcw wlo aomagnmlrcw mc fn

    n{scw}n mc fn ce{rcwn {lr son wcisramnm {fnoajagnmn& {lr fl ~sc cw ocgcwnral so enqlr

    cwjscrxl mc wcowabafaxngao {nrn wnfznr cwc wnf}l co fn {crgc{gao/

    ]nebao wc lbwcrzn son l{lr}soamnm mc echlrn rcw{cg}l n flw [fnocw mc Glo}aosamnm mc

    Ocilgal/ Gsn}rl mc gnmn macx ce{rcwnw cogscw}nmnw glolgc cf waioajagnml mc cw}lw

    {fnocw& nso~sc cw}n {rl{lrgao cw aojcralr co gsno}l n fn maw{lwagao mc nfison cw}rn}cian

    l {rlgcmaeaco}l co gnwl mc wa}sngalocw mc grawaw l mcwnw}rc& baco rcjaraomlwc n so

    cw}rn}cian iflbnf (>3&7#!& baco rcfn}azl n ecgnoawelw {nrn fn rcgs{crngao

    cpgfswazneco}c mcf co}lrol }cgolfiagl ~sc wl{lr}n fnw l{crngalocw mc ocilgal (>3&3#!/

    [lr f}ael& cf [fno mc Glo}aosamnm mc Ocilgal cpaic cf wcisaeaco}l q echlrn glo}aosn mc

    flw {rlgcwlw/ So 7>&1# mc fnw ce{rcwnw glo [GO `nbafa}n ecgnoawelw {nrn gle{rlbnr

    ws cjagngan& co}rc flw mcw}ngn fn rcnfaxngao mc {rscbnw {cramagnw (=2&7#!/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    7/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 9 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    AA AOGAMCO]CW MC WCISRAMNM CO FN CE[RCWN CW[NLFN

    N hsagal mc fnw ce{rcwnw& flw aogamco}cw mc wcisramnm ew jrcgsco}cw waisco wacoml cf

    enfynrc q cf w{ne co cf gnwl mc flw lrmconmlrcw& eaco}rnw ~sc co flw maw{lwa}azlw ezafcw

    wlo cf rlbl q fn {rmamn mc flw eawelw/ Flw wsgcwlw glo ew {rlbnbafamnm mc {locr co

    racwil fn glo}aosamnm mcf ocilgal wlo n~scfflw rcfn}azlw nf jsogaloneaco}l aoglrrcg}l mc fn

    aojrncw}rsg}srn aojlre}agn/

    So 97&1# mc fnw ce{rcwnw njaren ol `nbcr wsjraml so aogamco}c mc wcisramnm co cf f}ael

    nl& jrco}c n so 2:&># ~sc w wlo glowgaco}cw mc cw}n gargsow}nogan/ Maw{locr mc {crwlonf

    ao}crol mc wcisramnm }acoc son rcfngao marcg}n glo fn enqlr {crgc{gao mc aogamcoganw8 cf

    {lrgco}nhc mc zg}aenw nseco}n `nw}n cf =:&=# co}rc fnw ~sc gsco}no glo cw}lw

    {rljcwalonfcw/

    Fn aojcggao {lr enfynrc (>=&9#! q fn rcgc{gao mc glrrcl cfcg}roagl ol mcwcnml l w{ne(>>&1#! wlo fnw aogamcoganw mcgfnrnmnw co enqlr ecmamn/

    Co cf gnwl mc flw maw{lwa}azlw ezafcw& cf 99&;# wcnfno ol `nbcr }coaml oaoio {crgnogc

    mc wcisramnm co wsw }creaonfcw msrno}c cf f}ael nl/ Fn wsw}rnggao q fn {rmamn mcf

    }creaonf (9&2# q 9&># rcw{cg}azneco}c! wlo flw wsgcwlw ew jrcgsco}cw/

    Flw aogamco}cw {scmco& co lgnwalocw& {rlzlgnr fn ao}crrs{gao mc fnw l{crngalocw mc

    ocilgal/ Nw& co cf f}ael nl cf {raoga{nf {crgnogc mcgfnrnml cw fn gnmn l nzcrn mc flw

    waw}cenw mc wl{lr}c (so >3&2#!& wcisaml mc fn gnmn mc flw waw}cenw l n{fagngalocw

    aojlre}agnw (>>&7#! q fn jnf}n mc wcrzagal l wseaoaw}rl {lr {nr}c mc flw {rlzccmlrcw(>>&2#!/

    ]rnw so aogamco}c& fnw ce{rcwnw amco}ajagno fnw glowcgscoganw ew zawabfcw& {crl wlo

    ecolw glowgaco}cw mc fnw glowcgscoganw mc gnrg}cr }goagl/ Jrco}c n cw}lw wsgcwlw& fnw

    rcnggalocw }lmnzn wlo }eamnw& gco}rnmnw co fn aoglr{lrngao mc oscznw `crrneaco}nw q

    ecmamnw mc wcisramnm/

    Co}rc fnw ce{rcwnw ~sc mcgfnrno `nbcr wsjraml ae{ng}lw ocin}azlw co ws l{crn}azn&

    aenico l cglolen n glowcgscogan mc so aogamco}c mc wcisramnm& flw wcnfnmlw co enqlr

    ecmamn wlo flw ~sc njcg}no nf }ace{l q fn {rlmsg}azamnm q flw ~sc ae{fagno son {nrnmn mcfnw l{crngalocw/

    So 3=&=# mc fnw lrinoaxngalocw ol rcnfaxn oaoison elmajagngao mcw{sw mcf {crgnogc&

    eaco}rnw ~sc so 70&3# nml{}n son ng}a}sm {rlng}azn aoglr{lrnoml `crrneaco}nw l ecmamnw

    mc wcisramnm/ Wao cebnril& ol cpaw}c son n{scw}n gfnrn {lr ng}sngalocw n oazcf

    lrinoaxn}azl l cw}rn}iagl/

    Flw cognrinmlw mc rcwlfzcr flw aogamco}cw wlo flw }goaglw ao}crolw mc fnw ce{rcwnw

    (wcio mcgfnrn so =0&3#!& nso~sc mcw}ngn fn {rl{lrgao mc lrinoaxngalocw ~sc magco

    n{lqnrwc co so wcrzagal cp}crol& baco {nrn nwcwlrnr nf {crwlonf mc fn ce{rcwn (so 9&=#!&

    baco {nrn rcwlfzcr marcg}neco}c cf aogamco}c (so 77&3#!/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    8/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 0 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    AAA C%GLOJANOXN

    Wcrzagalw glel fn bnogn cfcg}roagn& fn c%Nmeaoaw}rngao l cf ocilgal cfcg}roagl (jaren q

    jng}srn cfcg}roagn! glo}rabsqco nf nznogc mc fn c%glojanoxn co fn Wlgacmnm mc fn

    Aojlrengao/

    Bnogn cfcg}roagn q ecmalw mc {nil lofaoc (:1&0#!& {iaon ycb ce{rcwnranf (33&3#! q c%

    Nmeaoaw}rngao (3>&1#! wlo flw wcrzagalw mc Ao}croc} ew cp}comamlw co cf glfcg}azl

    ce{rcwnranf cw{nlfn/ Cw ocgcwnral rcnfaxnr so cwjscrxl {lr {rlelzcr fn s}afaxngao mc

    n~scfflw ecolw {rcwco}cw& glel rcmcw wlganfcw (2:&0##!& jng}srn cfcg}roagn (2;&7#!&

    c%glo}rn}ngao (>9&9#! q zco}n lofaoc (>=&3#!/

    N {cwnr mc fnw majcrcoganw co cf swl& mcw}ngn cf nf}l oazcf mc glojanoxn ~sc& wcio fnw

    ce{rcwnw& fcw }rnowea}co fn enqlrn mc flw wcrzagalw/ Nw lgsrrc glo fn c%Nmeaoaw}rngao

    (09&;#!& fn s}afaxngao mc fn bnogn cfcg}roagn q flw ecmalw mc {nil lofaoc (0:&>#! l cfocilgal cfcg}roagl (07&1#!/ Fnw rcmcw wlganfcw wlo fnw ~sc ecolw glojanoxn icocrno

    (=3&1#!/

    Fn jnf}n mc ocgcwamnm q fn jnf}n mc ao}crw wlo flw el}azlw ew nfcinmlw {nrn fn ol

    aoglr{lrngao mc osczlw wcrzagalw/

    AZ RCGLECOMNGALOCW

    Fnw rcglecomngalocw ~sc wc cp{loco co cf aojlrec cw}o maraiamnw n fnw ce{rcwnw& n fn aomsw}ran

    mc wcisramnm mc fn aojlrengao q n fn Nmeaoaw}rngao [bfagn/

    Rcglecomngalocw {nrn fnw {qecw

    Nznoxnr co fn wcowabafaxngao mc fnw ce{rcwnw wlbrc flw racwilw mc wcisramnm mc fn

    aojlrengao& aogamacoml co fn jlrengao q cf rcgagfnhc ao}crolw/

    Ngsmar n {rljcwalonfcw cp}crolw ~sc wlfzco}co fn jnf}n mc rcgsrwlw ao}crolw wao rcosoganr n

    fn wcisramnm/

    S}afaxnr glrrcg}neco}c fnw `crrneaco}nw q ecmamnw mc wcisramnm/ Esg`nw ce{rcwnw ol

    maw{loco mc flw glolgaeaco}lw wsjagaco}cw {nrn nmn{}nr glrrcg}neco}c fnw wlfsgalocw n wsgnwl glogrc}l/

    Jleco}nr fn aoglr{lrngao mc bsconw {rg}agnw {nrn flw eacebrlw mc fn lrinoaxngao/

    Nml{}nr cw}rn}cianw mc glo}aosamnm mc ocilgal {nrn nwcisrnr fn rcwaw}cogan mc fn

    lrinoaxngao no}c gsnf~sacr wsgcwl ~sc {scmn {locr co {cfairl ws ws{crzazcogan/

    Cw}nbfcgcr gra}cralw mc wcisramnm co fnw rcfngalocw glo flw {rlzccmlrcw/

    Eno}cocrwc ng}snfaxnmlw mc fnw olzcmnmcw co en}cran mc racwilw mc wcisramnm q ecmamnw

    mc {rl}cggao/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    9/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 1 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Rcglecomngalocw {nrn fn aomsw}ran mc wcisramnm

    Nmcgsnr fn ljcr}n mc {rlmsg}lw q wlfsgalocw mc wcisramnm n fn rcnfamnm mc fn ce{rcwncw{nlfn/

    Mcw{fcinr ng}sngalocw ~sc nqsmco n gle{fceco}nr fn wcisramnm co fn ce{rcwn mcwmc fn

    glogacogangao q fn jlrengao/

    [rlelzcr fn {rljcwalonfaxngao mc fnw ce{rcwnw mcf gnonf mc maw}rabsgao mc wlfsgalocw mc

    wcisramnm/

    Glfnblrnr cw}rcg`neco}c glo fnw Nmeaoaw}rngalocw [bfagnw/

    Rcglecomngalocw {nrn fnw Nmeaoaw}rngalocw [bfagnw

    Nwcwlrnr nf ce{rcwnral {nrn ~sc aoglr{lrc gle{c}coganw mc wcisramnm mc fn aojlrengao/

    Mcw{fcinr nggalocw mc wcowabafaxngao bnwnmlw co flw bcocjagalw mcf swl mc wcrzagalw ]AG

    q fn wcisramnm {rlng}azn/

    [rlelzcr cf mcwnrrlffl mc cw}rn}cianw ce{rcwnranfcw bnwnmnw co cw}omnrcw/

    Mcw{fcinr nggalocw aojlren}aznw q jlren}aznw {nrn cf {crwlonf mc fnw ce{rcwnw/

    Cw}smanr cf cw}nml mc fn wcisramnm mc fn aojlrengao q fn glo}aosamnm mc ocilgal co fnw

    ce{rcwnw cw{nlfnw/

    Rcnfaxnr nggalocw cw{cgjagnw {nrn fnw ce{rcwnw mc wcrzagalw mc }cgolflinw mc fn

    aojlrengao (]A!/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    10/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >; mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    > AO]RLMSGGAO Q LBHC]AZLW

    >/> [RCWCO]NGAO

    Cf Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao& W/N/ (AO]CGL!& cw son wlgacmnm cw}n}nf

    nmwgra}n nf Eaoaw}cral mc Aomsw}ran& Cocrin q ]srawel n }rnzw mc fn Wcgrc}nrn mc Cw}nml mc

    ]cfcglesoagngalocw q {nrn fn Wlgacmnm mc fn Aojlrengao/

    AO]CGL cw so gco}rl mc mcwnrrlffl mc gnrg}cr aoolznmlr q mc ao}crw {bfagl mc eba}l ongalonf

    ~sc wc lraco}n n fn n{lr}ngao mc znflr& n fn aomsw}ran q n flw swsnralw& q n fn majswao mc fnw oscznw

    }cgolflinw mc fn aojlrengao q fn glesoagngao (]AG! co Cw{nn& co gfnrn wao}lon glo Csrl{n/

    Ws lbhc}azl jsomneco}nf cw wcrzar glel aow}rseco}l {nrn mcwnrrlffnr fn Wlgacmnm mc fn

    Aojlrengao& glo ng}azamnmcw {rl{anw co cf eba}l mc fn aoolzngao q cf mcwnrrlffl mc {rlqcg}lwnwlganmlw n fnw ]AG& bnwomlwc co }rcw {afnrcw jsomneco}nfcw8 fn aozcw}aingao n{fagnmn& fn

    {rcw}ngao mc wcrzagalw q fn jlrengao/

    Fn eawao mc AO]CGL cw n{lr}nr znflr c aoolzngao n flw gasmnmnolw& n fnw {qecw& n fnw

    nmeaoaw}rngalocw {bfagnw q nf wcg}lr mc fnw }cgolflinw mc fn aojlrengao& n }rnzw mcf mcwnrrlffl

    mc {rlqcg}lw ~sc glo}rabsqno n rcjlrxnr fn glojanoxn co flw wcrzagalw mc fn Wlgacmnm mc fn

    Aojlrengao co oscw}rl {nw& {rlelzacoml nmcew son focn mc {nr}aga{ngao ao}crongalonf/

    [nrn cffl& AO]CGL mcwnrrlffn ng}sngalocw co fnw waisaco}cw focnw8

    Wcisramnm }cgolfiagn8 AO]CGL cw} gle{rlec}aml glo fn {rlelgao mc wcrzagalw mc fnWlgacmnm mc fn Aojlrengao gnmn zcx ew wcisrlw& ~sc {rl}chno flw mn}lw {crwlonfcw mc

    flw ao}crcwnmlw& ws ao}aeamnm& fn ao}ciramnm mc ws aojlrengao q cza}co n}n~scw ~sc {loino

    co racwil flw wcrzagalw {rcw}nmlw/ Q& {lr ws{scw}l& ~sc inrno}agco so gse{faeaco}l cw}rag}l

    mc fn olren}azn fcinf co en}cran mc ]AG/ [nrn cffl gllrmaon maw}ao}nw aoagan}aznw {bfagnw co

    }lrol n fn wcisramnm mc fnw ]AG& ~sc wc en}cranfaxno co fn {rcw}ngao mc wcrzagalw {lr {nr}c

    mcf Lbwcrzn}lral mc fn Wcisramnm mc fn Aojlrengao& cf Gco}rl mc Rcw{scw}n n Aogamco}cw

    mc Wcisramnm co ]cgolflinw mc fn Aojlrengao (AO]CGL%GCR]!& glo ws Gn}flil mc

    Ce{rcwnw q Wlfsgalocw mc Wcisramnm ]AG& q fn Ljagaon mc Wcisramnm mcf Ao}crons}n (LWA!&

    mc flw ~sc wc bcocjagano gasmnmnolw& {qecw& nmeaoaw}rngalocw {bfagnw q cf wcg}lr

    }cgolfiagl/

    Nggcwabafamnm8 AO]CGL {rlesczc wcrzagalw mc fn Wlgacmnm mc fn Aojlrengao ew

    nggcwabfcw& ~sc ws{raeno fnw bnrrcrnw mc cpgfswao& gsnf~sacrn ~sc wcn fn majagsf}nm l

    gnrcogan }goagn& jlren}azn& c}g/& aogfswl mawgn{ngamnm& ~sc }coino wsw swsnralw/ Q ~sc

    jngafa}co fn ao}cirngao {rlircwazn mc }lmlw flw glfcg}azlw mc swsnralw& mc elml ~sc }lmlw

    cfflw {scmno bcocjaganrwc mc fnw l{lr}soamnmcw ~sc ljrcgc fn Wlgacmnm mc fn Aojlrengao/

    Co {nr}agsfnr& AO]CGL maw{loc mc ne{fan cp{cracogan co cf mcwnrrlffl mc {rlqcg}lw co cf

    eba}l mc fn nggcwabafamnm {nrn fn }cfczawao maia}nf& nw glel mc n~scfflw lraco}nmlw n

    inrno}axnr flw mcrcg`lw mc flw gasmnmnolw n rcfngalonrwc glo fnw nmeaoaw}rngalocw

    {bfagnw {lr ecmalw cfcg}roaglw& rcglolgamlw co fn Fcq >>,2;;9& mc 22 mc hsoal& mcnggcwl cfcg}roagl mc flw gasmnmnolw n flw Wcrzagalw [bfaglw

    http://cert.inteco.es/cert/INTECOCERT/?postAction=getCertHomehttp://cert.inteco.es/cert/INTECOCERT/?postAction=getCertHome
  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    11/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >> mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Gnfamnm ]AG8 AO]CGL {rlesczc solw wcrzagalw mc fn Wlgacmnm mc fn Aojlrengao ~sc

    gnmn zcx wcno mc enqlr gnfamnm& ~sc inrno}agco solw nmcgsnmlw oazcfcw mc wcrzagal& fl

    gsnf wc }rnmsgc co son enqlr rlbsw}cx mc n{fagngalocw q waw}cenw& so gle{rleawl co fn

    maw{loabafamnm q flw }ace{lw mc rcw{scw}n& so nmcgsnml wl{lr}c {nrn flw swsnralw& sonaojlrengao {rcgawn q gfnrn wlbrc fn czlfsgao mc fnw jsogalonfamnmcw mc flw wcrzagalw& q co

    rcwseco& wcrzagalw gnmn zcx echlrcw/ Co cw}n focn ae{sfwn fn gle{c}a}azamnm mc fn

    aomsw}ran mcf Wlj}ynrc n }rnzw mc fn {rlelgao mc fn echlrn mc fn gnfamnm q fn gcr}ajagngao

    mc fnw ce{rcwnw q {rljcwalonfcw mc fn aoicoacrn mcf wlj}ynrc& n }rnzw mcf Fnblrn}lral

    Ongalonf mc Gnfamnm mcf Wlj}ynrc/

    Jlrengao8 fn jlrengao cw so jng}lr mc}creaono}c {nrn fn n}rnggao mc }nfco}l q {nrn fn

    echlrn mc fn gle{c}a}azamnm mc fnw ce{rcwnw/ [lr cffl& AO]CGL ae{sfwn fn jlrengao mc

    soazcrwa}nralw q {rljcwalonfcw co fnw }cgolflinw ew mcenomnmnw {lr fn aomsw}ran/

    Cw sol mc flw lbhc}azlw mcf Aow}a}s}l mcwgrabar mc enocrn mc}nffnmn q waw}ce}agn cf oazcf mc

    wcisramnm& {razngamnm q glojanoxn co fn Wlgacmnm mc fn Aojlrengao q mc icocrnr glolgaeaco}l

    cw{cganfaxnml co fn en}cran/ Mc cw}c elml& wc cogsco}rn nf wcrzagal mc flw gasmnmnolw& fnw

    ce{rcwnw q fnw nmeaoaw}rngalocw {bfagnw cw{nlfnw {nrn mcwgrabar& nonfaxnr& nwcwlrnr q majsomar fn

    gsf}srn mc fn wcisramnm mc fn aojlrengao& fn {razngamnm q fn c%glojanoxn/

    AO]CGL `n mawcnml so [fno mc Ng}azamnmcw q Cw}smalw glo cf lbhc}l mc {rlmsgar glolgaeaco}l

    cw{cganfaxnml q }af co en}cran mc wcisramnm q {razngamnm& nw glel mc cfnblrnr rcglecomngalocw

    q {rl{scw}nw ~sc mcjaono }comcoganw zfamnw {nrn fn }len mc mcgawalocw js}srnw {lr {nr}c mc flw

    {lmcrcw {bfaglw/

    Mco}rl mc cw}c {fno mc nggao wc rcnfaxno fnblrcw mc aozcw}aingao& nofawaw& cw}smal&

    nwcwlrneaco}l q mazsfingao ~sc n}comcro& co}rc l}rnw& n fnw waisaco}cw cw}rn}cianw8

    Cfnblrngao mc cw}smalw c aojlrecw {rl{alw co en}cran mc wcisramnm mc fnw ]cgolflinw

    mc fn Aojlrengao q fn Glesoagngao& glo cw{cganf ojnwaw co fn Wcisramnm q {razngamnm co

    Ao}croc}/

    Wcisaeaco}l mc flw {raoga{nfcw aomagnmlrcw q {lf}agnw {bfagnw rcfngalonmnw glo fn

    wcisramnm mc fn aojlrengao q fn glojanoxn co cf eba}l ongalonf c ao}crongalonf/

    Icocrngao mc son bnwc mc mn}lw ~sc {crea}n cf nofawaw q cznfsngao mc fn wcisramnm q

    fn glojanoxn glo son {crw{cg}azn }ce{lrnf/

    Ae{sfwl mc {rlqcg}lw mc aozcw}aingao co en}cran mc wcisramnm ]AG/

    Majswao mc cw}smalw c aojlrecw {sbfagnmlw {lr l}rnw co}amnmcw q lrinoawelw ongalonfcw c

    ao}crongalonfcw& nw glel mc aojlrengao wlbrc fn ng}snfamnm ongalonf q csrl{cn co

    en}cran mc fn wcisramnm q glojanoxn co fn Wlgacmnm mc fn Aojlrengao/

    Nwcwlrneaco}l n fnw Nmeaoaw}rngalocw [bfagnw co en}cran mc wcisramnm mc fn aojlrengaoq glojanoxn& nw glel cf n{lql n fn cfnblrngao& wcisaeaco}l q cznfsngao mc {lf}agnw

    {bfagnw co cw}c eba}l/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    12/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >2 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    >/2 CW]SMAL WLBRC WCISRAMNM MC FN AOJLRENGAO Q GLO]AOSAMNM MC OCILGAL

    CO FNW CE[RCWNW CW[NLFNW

    >/2/> Glo}cp}l q l{lr}soamnm mcf cw}smalFnw eagrlce{rcwnw q fnw {c~scnw q ecmanonw ce{rcwnw wlo cf el}lr mc fn cglolen csrl{cn/

    Glow}a}sqco son jsco}c jsomneco}nf mc {scw}lw mc }rnbnhl& icocrno cw{ra}s ce{rcwnranf c

    aoolzngao co fn SC q& {lr cffl& wlo za}nfcw {nrn {rlelzcr fn gle{c}a}azamnm q cf ce{fcl/ Cw}c

    glfcg}azl cw} glow}a}saml {lr lrinoaxngalocw ~sc lgs{no n ecolw mc 23; {crwlonw q gsql

    zlfseco mc ocilgalw nosnf ol cpgcmc mc 3; eafflocw mc csrlw l gsql bnfnogc icocrnf nosnf ol

    cpgcmc mc =7 eafflocw mc csrlw/

    Flw mn}lw mcf Aow}a}s}l Ongalonf mc Cw}nmw}agn (AOC!> mabshno so en{n mc 7/2:9/32> ce{rcwnw co

    Cw{nn& mc fnw gsnfcw 7/2=3/391 }acoco ecolw mc >11 nwnfnranmlw/ Ew mcf 11# mcf }chaml

    ce{rcwnranf cw{nlf cw} glow}a}saml {lr lrinoaxngalocw ~sc cognhno co fn mcjaoagao mceagrlce{rcwnw& {c~scnw q ecmanonw ce{rcwnw& mc ngscrml glo fl maw{scw}l {lr fn Gleawao

    Csrl{cn2/

    Co Cw{nn& cw}c glfcg}azl }acoc son ae{lr}nogan cw}rn}iagn co cf enrgl mcf mcwnrrlffl cgloeagl

    mcf {nw& {scw}l ~sc cf }chaml ce{rcwnranf cw{nlf cw} glow}a}saml co ew mc so 11# {lr

    {c~scnw ce{rcwnw q ew mc so 13# }acoco ecolw mc >; nwnfnranmlw/

    Fnw ]cgolflinw mc fn Aojlrengao q fnw Glesoagngalocw (]AG! mcwce{cno so {n{cf maoneaxnmlr

    mc fn gle{c}a}azamnm mc fn cglolen n oazcf iflbnf c ae{sfwno fn aoolzngao& fn grcn}azamnm q fn

    cjagacogan co fnw lrinoaxngalocw/

    Cffl hsw}ajagn fn ocgcwamnm mc maw{locr mc so maniow}agl rcnf q raisrlwl mc fn wa}sngao mc

    wcisramnm ]AG co fn {c~scn q ecmanon ce{rcwn cw{nlfn& glel {nwl {rczal n fn ae{fceco}ngao

    mc {lf}agnw mc jleco}l mc fn wcgsraxngao {nrn fnw ce{rcwnw/ Fn zlgngao mc AO]CGL `ngan cw}c

    glfcg}azl fc `n ffcznml n rcnfaxnr co cf {nwnml& n }rnzw mc ws Lbwcrzn}lral mc fn Wcisramnm mc fn

    Aojlrengao& {rlqcg}lw mc aozcw}aingao waeafnrcw co fnw en}cranw {fno}cnmnw (wcisramnm mc fn

    aojlrengao q glo}aosamnm mc ocilgal!/ Nw& co 2;>; wc {sbfag cf Cw}smal wlbrc fn wcisramnm q c%

    glojanoxn co fnw {c~scnw q eagrlce{rcwnw cw{nlfnw7 q cf Cw}smal wlbrc cf cw}nml mc fn {qec

    cw{nlfn no}c flw racwilw q fn ae{fno}ngao mc [fnocw mc Glo}aosamnm mc Ocilgal=& jrs}l mc wsw

    rcwsf}nmlw& co 2;;1 wc cma} fn Isn {rg}agn {nrn [QECW8 gel ae{fno}nr so [fno mc

    Glo}aosamnm mc Ocilgal3/

    > Marcg}lral Gco}rnf mc Ce{rcwnw (MARGC!& mn}lw mc > mc cocrl mc 2;>>/ Glowsf}n mcf marcg}lral maw{loabfc co8

    `}}{8,,yyy/aoc/cw,hnpa,ecos/ml,*jafc5aocbnwc/2 Gleawao Csrl{cn (2;;:! Fn osczn mcjaoagao mc [QEC/ [sbfagngalocw mc ce{rcwn c aomsw}ran/ Maw{loabfc co8

    `}}{8,,cg/csrl{n/cs,co}cr{rawc,{lfagacw,wec,jafcw,wec\mcjaoa}alo,wec\swcr\isamc\cw/{mj7 AO]CGL (2;>;!/ Cw}smal wlbrc fn wcisramnm q c%glojanoxn co fnw {c~scnw q eagrlce{rcwnw cw{nlfnw/ Maw{loabfc co8

    `}}{8,,yyy/ao}cgl/cw,Wcisramnm,Lbwcrzn}lral,Cw}smalw,Cw}smal\wcisramnm\eagrlce{rcwnw= AO]CGL (2;>;!/ Cw}smal wlbrc cf cw}nml mc fn {qec cw{nlfn no}c flw racwilw q fn ae{fno}ngao mc [fnocw mc Glo}aosamnm

    mc Ocilgal/ Maw{loabfc co8`}}{8,,yyy/ao}cgl/cw,Wcisramnm,Lbwcrzn}lral,Cw}smalw,Cw}smal\{qecw\glo}aosamnm\ocilgal3 AO]CGL (2;>;!/ Isn {rg}agn {nrn [QECW8 gel ae{fno}nr so [fno mc Glo}aosamnm mc Ocilgal/ Maw{loabfc co8

    `}}{8,,yyy/ao}cgl/cw,Wcisramnm,Lbwcrzn}lral,isanw,isan\glo}aosamnm

    http://www.ine.es/jaxi/menu.do?type=pcaxis&path=/t37/p201/&file=inebasehttp://www.ine.es/jaxi/menu.do?type=pcaxis&path=/t37/p201/&file=inebasehttp://ec.europa.eu/enterprise/policies/sme/files/sme_definition/sme_user_guide_es.pdfhttp://ec.europa.eu/enterprise/policies/sme/files/sme_definition/sme_user_guide_es.pdfhttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_seguridad_microempresashttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_seguridad_microempresashttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_pymes_continuidad_negociohttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_pymes_continuidad_negociohttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_pymes_continuidad_negociohttp://www.inteco.es/Seguridad/Observatorio/guias/guia_continuidadhttp://www.inteco.es/Seguridad/Observatorio/guias/guia_continuidadhttp://www.inteco.es/Seguridad/Observatorio/guias/guia_continuidadhttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_pymes_continuidad_negociohttp://www.inteco.es/Seguridad/Observatorio/Estudios/Estudio_seguridad_microempresashttp://ec.europa.eu/enterprise/policies/sme/files/sme_definition/sme_user_guide_es.pdfhttp://www.ine.es/jaxi/menu.do?type=pcaxis&path=/t37/p201/&file=inebase
  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    13/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >7 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    [lr cffl& cf Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw

    ce{rcwnw cw{nlfnw inrno}axn fn glo}aosamnm mc cw}lw cw}smalw no}cralrcw& rcgliacoml fn

    wa}sngao ng}snf co cw}lw eba}lw/ [lr l}rl fnml& {nrn n{rlzcg`nr cf {l}coganf {rg}agl q l{crn}azl

    mc fn aojlrengao rcgliamn& cf mcwnrrlffl mc cw}n aozcw}aingao mcbc icocrnr son wcrac mcaomagnmlrcw glo zlgngao mc {crenocogan q glo}aosamnm ew nff mcf enrgl }ce{lrnf mcf {rlqcg}l/

    >/2/2 Lbhc}azl icocrnf

    Cf lbhc}azl icocrnf mcf {rlqcg}l cw fn lb}cogao mc so maniow}agl raisrlwl wlbrc cf oazcf mc

    {rc{nrngao no}c flw racwilw mc wcisramnm q fn nml{gao mc cw}rn}cianw mc glo}aosamnm mc ocilgal

    co fnw {c~scnw q ecmanonw ce{rcwnw cw{nlfnw ~sc s}afaxno Ao}croc} glel {nr}c mc ws ocilgal/

    >/2/7 Lbhc}azlw cw{cgjaglw

    Cf lbhc}azl icocrnf n{so}nml wc mcwiflwn& n ws zcx& co son wcrac mc lbhc}azlw cw{cgjaglw8

    Maw{locr mc aomagnmlrcw ~sc {crea}no glolgcr gsf cw fn wa}sngao ng}snf co en}cran mc

    wcisramnm q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw/

    Amco}ajagnr flw {raoga{nfcw aogamco}cw ~sc njcg}no n flw waw}cenw mc aojlrengao c aogfswl&

    {rlzlgnr fn {nrnfaxngao mc fnw ng}azamnmcw mc ocilgal& cw}smanoml fnw {raoga{nfcw

    glowcgscoganw mcraznmnw q fnw rcnggalocw nml{}nmnw mcwmc fnw lrinoaxngalocw/

    Amco}ajagnr {n}rlocw l {crjafcw mc gle{lr}neaco}l co fnw ce{rcwnw co gsno}l n

    ae{fceco}ngao mc fn gsf}srn mc wcisramnm q glo}aosamnm mc ocilgal/

    Nonfaxnr cf oazcf mc swl q glojanoxn co flw majcrco}cw wcrzagalw mc fn Wlgacmnm mc fn

    Aojlrengao {rcwco}cw co fnw {c~scnw q ecmanonw ce{rcwnw& {rljsomaxnoml co flw

    el}azlw ~sc ae{fagno son ecolr l osfn s}afaxngao mc flw eawelw/

    N{lr}nr son wcrac mc glogfswalocw co bnwc n flw {raoga{nfcw rcwsf}nmlw lb}coamlw/ Cw}nw

    glogfswalocw {crea}co& n ws zcx& {rl{lrgalonr majcrco}cw rcglecomngalocw n flw {lmcrcw

    {bfaglw& n fn aomsw}ran {rlzccmlrn mc bacocw q wcrzagalw mc wcisramnm& q n fnw {rl{anw

    ce{rcwnw co cf wco}aml mc glogacoganr wlbrc fn ae{lr}nogan mc cfcznr cf oazcf mc wcisramnm

    q glo}aosamnm mc ocilgal co fn cw}rn}cian ce{rcwnranf cw{nlfn/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    14/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >= mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    2 EC]LMLFLIN

    [nrn fn rcnfaxngao mc cw}c cw}smal wc `n s}afaxnml son glebaongao mc }goagnw mc nofawaw

    gsnfa}n}azl q gsno}a}n}azl& cw}rsg}srnoml cf {rlqcg}l co znranw jnwcw8

    Jnwc >8 Bw~scmn q nofawaw mlgseco}nf (jsco}cw {raenranw q wcgsomnranw!/

    Jnwc 28 Cogscw}n n rcw{lownbfcw co wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal

    co fnw {qecw/

    Jnwc 78 Co}rczaw}nw co {rljsomamnm n rcw{lownbfcw mc wcisramnm mc fn aojlrengao q

    glo}aosamnm mc ocilgal co fnw ce{rcwnw& wcfcggalonmlw co jsogao mc fn gnrng}craxngao

    mc fnw {qecw co majcrco}cw {crjafcw mc gle{lr}neaco}l/

    Jnwc =8 Irs{l mc cp{cr}lw co wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal

    {cr}cocgaco}cw n majcrco}cw eba}lw/

    2/> JNWC >8 NOFAWAW MLGSECO]NF

    Cf lbhc}azl mc cw}n {raecrn jnwc `n waml rcglicr aojlrengao wlbrc fn wa}sngao ng}snf q czlfsgao

    mcf irnml mc wcgsraxngao mc fn {c~scn q ecmanon ce{rcwn cw{nlfn q fn {lwagao rcw{cg}l n fn

    nml{gao mc {fnocw mc glo}aosamnm mc ocilgal/

    Glel jsco}cw mlgseco}nfcw wc `no s}afaxnml flw majcrco}cw aojlrecw rcnfaxnmlw {lr AO]CGL co fnw

    en}cranw lbhc}l mcf {rcwco}c cw}smal/ Nwaeawel& wc `no }coaml co gsco}n aojlrecw& y`a}c {n{crw&cw}smalw q ol}nw mc {rcown mc ef}a{fcw jsco}cw ongalonfcw c ao}crongalonfcw glel `crrneaco}nw

    {nrn ffcznr n gnbl fn aozcw}aingao mlgseco}nf/ Fn {rlgcmcogan mc cw}nw jsco}cw nbnrgn

    lrinoawelw ljaganfcw (Csrlw}n}& AOC& LOW]A& c}g/!& ce{rcwnw rcfngalonmnw glo fnw }cgolflinw mc fn

    aojlrengao q fnw glesoagngalocw (Czcraw& Mcfla}}c& [ragcyn}cr`lswcGll{crw! c aomsw}ran mc fn

    wcisramnm mc fn aojlrengao ([nomn Wcgsra}q l Dnw{crwdq!& co}rc l}rnw/

    Co cf NOCPL A8 BABFALIRNJN wc {scmco coglo}rnr fnw jsco}cw mc flw mlgseco}lw gfnzc

    s}afaxnmlw/ Mc fn eawen enocrn& wc ga}no glel {ac mc irjaglw q }nbfnw fnw jsco}cw s}afaxnmnw {nrn

    fn escw}rn mc flw mn}lw co gnmn gnwl/

    2/2 JNWC 28 COGSCW]N N CE[RCWNW

    [nrn nonfaxnr fn {crgc{gao mc fn wa}sngao co fnw {c~scnw q ecmanonw ce{rcwn cw{nlfn co

    gsno}l n fn wcisramnm q glo}aosamnm mc ocilgal wc `n rcnfaxnml son jnwc mc cogscw}n/ Fn

    gle{fchamnm mc mag`n cogscw}n `n {rl{aganml fn mazawao mcf gscw}alonral co mlw {nr}cw& n wnbcr8

    [nr}c N8 wcisramnm mc fn aojlrengao q c%glojanoxn/

    [nr}c B8 glo}aosamnm mc ocilgal/

    Co }l}nf `no {nr}aga{nml >/=2= ce{rcwnw& mc fnw gsnfcw >/>== `no rcw{lomaml n fn {nr}c N mc fncogscw}n (wcisramnm q c%glojanoxn! q >/>;1 `no rcw{lomaml n fn {nr}c B (glo}aosamnm mc ocilgal!/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    15/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >3 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    2/2/> Soazcrwl mcf cw}smal q wshc}l mc l{aoao

    Cf soazcrwl lbhc}l mc cw}smal wc gle{loc mc fnw {c~scnw q ecmanonw ce{rcwnw cw{nlfnw glo

    nf ecolw so lrmconmlr glocg}nml n Ao}croc}& cw}rn}ajagnml co bnwc nf oecrl mc ce{fcnmlw q

    wcg}lr mc ng}azamnm/

    Glel {raecrn n{rlpaengao& fn {c~scn q ecmanon ce{rcwn cw{nlfn nifs}aon n irno {nr}c mcf

    }chaml ce{rcwnranf cw{nlf (11#!& glo}rabsqcoml co irno ecmamn n fn icocrngao mc ra~scxn

    cgloeagn/ Nw& co cf waisaco}c irjagl wc escw}rn fn maw}rabsgao mc fn enwn fnblrnf co Cw{nn& co

    bnwc n flw mn}lw mc fn Cogscw}n mc Glqso}srn Fnblrnf mcf AOC :/ Cf glfcg}azl nonfaxnml lgs{n so

    fsinr mcw}ngnml co fn maw}rabsgao mc fn enwn fnblrnf8 cf 92&=# mc flw }rnbnhnmlrcw {cr}cocgco n

    eagrl& {c~scnw q ecmanonw ce{rcwnw& eaco}nw ~sc fnw ce{rcwnw mc enqlr }nenl ce{fcno nf

    29&:# mc cw}c glfcg}azl/

    Irjagl >8 Maw}rabsgao mc fn enwn fnblrnf mc ce{fcnmlw co Cw{nn (#!

    Jsco}c8 Cogscw}n mc Glqso}srn Fnblrnf % ]crgcr }raecw}rc 2;>>

    Mc gnrn n fn mcfaea}ngao mcf soazcrwl mcf cw}smal& wc `no }coaml co gsco}n flw waisaco}cw nw{cg}lw8

    Wc aogfsqc bnhl fn mcoleaongao mc {c~scn q ecmanon ce{rcwn n {rljcwalonfcw fabcrnfcw

    q ce{rcwnw mc `nw}n 23; }rnbnhnmlrcw& co bnwc n fn gfnwajagngao cw}nbfcgamn {lr fn

    Glesoamnm Csrl{cn/

    Fn mcfaea}ngao {lr wcg}lr mc ng}azamnm wc `n rcnfaxnml s}afaxnoml fn gfnwajagngao ongalonf

    mc ng}azamnmcw ce{rcwnranfcw (GONC! co ws zcrwao mc 2;;1& glo : gn}cilrnw rcwsf}no}cw/

    Wc `n rcnfaxnml son wcieco}ngao {rl{an nirs{noml fnw glesoamnmcw ns}olenw {lr

    xlonw iclirjagnw& lb}coacoml : mazawalocw/

    : Jsco}c8 AOC (2;>2! Cogscw}n mc Glqso}srn Fnblrnf % ]crgcr }raecw}rc 2;>>/ Maw{loabfc co8

    `}}{8,,yyy/fnralhn/lri,s{flnm,mlgseco}w,:1191;\CGF\7]>>/{mj

    2:&;#

    2=&9#2>&0#

    29&:#

    Eagrlce{rcwnw [c~scn ce{rcwn Ecmanon ce{rcwn Irno ce{rcwn

    http://www.larioja.org/upload/documents/699790_ECL_3T11.pdfhttp://www.larioja.org/upload/documents/699790_ECL_3T11.pdfhttp://www.larioja.org/upload/documents/699790_ECL_3T11.pdf
  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    16/126

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    17/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >9 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Cf cw}smal {rljsomaxn co fn ecmamn mc fl {lwabfc& co flw mn}lw wcieco}nmlw {lr }nenl mc

    ce{rcwn q {lr eba}l wcg}lranf/

    Fn soamnm aojlreno}c mc fn cogscw}n `n waml fn {crwlon rcw{lownbfc mc fn wcisramnm mc fnaojlrengao mc fn ce{rcwn l& co ws mcjcg}l& cf rcw{lownbfc mc aojlre}agn/ Co gnwl mc nswcogan

    mc fnw mlw jaisrnw no}cralrcw& cf wshc}l mc l{aoao `n waml cf rcw{lownbfc mc fn ce{rcwn/

    2/2/2 ]nenl q maw}rabsgao escw}rnf

    Cf }nenl escw}rnf mc fn {nr}c mc wcisramnm q c%glojanoxn mc fn cogscw}n cw mc >/>== ce{rcwnw q

    mc fn {nr}c mc glo}aosamnm mc ocilgal cw mc >/>;1& rc{nr}amnw {lr }lml cf }crra}lral ongalonf/

    Mag`n escw}rn wc `n maw}rabsaml {lr cw}rn}lw s}afaxnoml son wlfsgao mc gle{rleawl co}rc njahngao

    soajlrec q {rl{lrgalonf& wcio flw mn}lw mc ce{rcwnw rcgliamlw co cf Marcg}lral Gco}rnf mc

    Ce{rcwnw& mcf Aow}a}s}l Ongalonf mc Cw}nmw}agn rcjcramlw n 2;>>/

    [nrn rcnfaxnr cf escw}rcl wc `no }coaml co gsco}n }rcw znranbfcw mc cw}rn}ajagngao8 }nenl mc fn

    ce{rcwn (oecrl mc ce{fcnmlw!& wcg}lr mc ng}azamnm q xlon iclirjagn/

    Co cf waisaco}c irjagl wc escw}rn fn maw}rabsgao {lr }nenl mc fn {lbfngao lbhc}l mc cw}smal

    {nrn gnmn son mc fnw mlw {nr}cw mc fn cogscw}n/

    Irjagl 28 Maw}rabsgao mc fnw escw}rnw {lr }nenl mc fn ce{rcwn (#!

    Bnwc8 Wcisramnm q c%glojanoxn (o5>/>==!4 Glo}aosamnm mc ocilgal (o5>/>;1! Jsco}c8 AO]CGL

    Co neblw gnwlw& cw}n maw}rabsgao {rcwco}n majcrcoganw cw}rsg}srnfcw rcw{cg}l n fn {lbfngao rcnf/

    Cw}l cw nw {lr~sc fn njahngao mc fn escw}rn {lr cw}rn}lw wc rcnfax mc enocrn ol {rl{lrgalonf&

    glo cf lbhc}l mc nwcisrnr fn rc{rcwco}n}azamnm mc mc}creaonmlw cw}rn}lw/

    70&3#

    7=&3#

    29&;#

    Wcisramnm q c%glojanoxn

    Eagrlce{rcwn [c~scn ce{rcwn

    =3&2#

    7;&1#

    27&1#

    Glo}aosamnm mc ocilgal

    Ecmanon ce{rcwn

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    18/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >0 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    }

    a

    }

    a

    o

    o

    O

    O

    [lr }no}l& cw ocgcwnral n{fagnr so jng}lr mc {lomcrngao ~sc {crea}n isnrmnr fn {rl{lrgalonfamnm

    mc gnmn sol mc flw cw}rn}lw mc fn escw}rn rcw{cg}l mc fn {lbfngao rcnf lbhc}l mc cw}smal/ Cw

    mcgar& cf jng}lr mc {lomcrngao gneban flw {cwlw mc flw maw}ao}lw cw}rn}lw escw}rnfcw {nrn ~sc

    w}lw wc nhsw}co n flw {lbfngalonfcw/

    Co cw}c gnwl& fn n{fagngao mcf jng}lr mc {lomcrngao `n ws{scw}l nwaionr ew {cwl n fnw

    rcw{scw}nw n{lr}nmnw {lr fnw eagrlce{rcwnw& q ecolw n fnw {c~scnw q ecmanonw ce{rcwnw& qn

    ~sc mco}rl mcf glohso}l {lbfngalonf cpaw}c cw}n majcrcogan co}rc cf oecrl mc lrinoaxngalocw mc

    gnmn }a{l/ Aisnfeco}c wc `n aogrceco}nml cf {cwl mc fnw lrinoaxngalocw {cr}cocgaco}cw n fnw

    ng}azamnmcw q mc fnw xlonw iclirjagnw gsqn rc{rcwco}n}azamnm cjcg}azn co cf glohso}l mc fn

    {lbfngao cw enqlr ~sc fn cpaw}co}c co fn escw}rn/

    [lr }no}l& cw}n {lomcrngao wc `n ffcznml n gnbl co jsogao mc fnw waisaco}cw znranbfcw8 }nenl mc

    fn ce{rcwn (oecrl mc ce{fcnmlw! q wcg}lr mc ng}azamnm q xlon iclirjagn/

    Afsw}rngao >8 Jng}lr mc {lomcrngao

    Oa5 oecrl mc ce{rcwnw ~sc `nq co gnmn cw}rn}l

    O}5 oecrl mc ce{rcwnw ~sc `nq co fn {lbfngao mc rcjcrcogan

    oa5 oecrl mc ce{rcwnw ~sc `nq co gnmn cw}rn}l mc fn escw}rn

    o}5 oecrl }l}nf mc ce{rcwnw ~sc gle{loco fn escw}rn

    Jsco}c8 LO]WA>>

    Flw mn}lw {lbfngalonfcw {nrn fn cfnblrngao mc cw}c {lomcrnmlr `no waml lb}coamlw n {nr}ar mc fn

    aojlrengao {sbfagnmn {lr cf Aow}a}s}l Ongalonf mc Cw}nmw}agn (AOC! n }rnzw mcf Marcg}lral Gco}rnf

    mc Ce{rcwnw (MARGC!/

    N fl fnril mcf cw}smal& wc mcwgrabc nf {ac mc gnmn irjagl fn bnwc mc gfgsfl/ N{rgacwc ~sc& co

    cw}lw gnwlw& wc rcglico flw mn}lw rcnfcw mc fn escw}rn& wao n{fagnr oaoio jng}lr mc {lomcrngao&

    glo lbhc}l mc {rl{lrgalonr son zawao ew rcnfaw}n mcf nofawaw/

    2/2/7 Crrlr escw}rnf

    Cf crrlr {nrn fn escw}rn ~sc `n rcw{lomaml n fn {nr}c mc wcisramnm q c%glojanoxn (o5>/>==! q co fn

    {nr}c mc glo}aosamnm mc ocilgal (o5>/>;1! cw co neblw gnwlw mc 2&1#& gnfgsfnml {nrn so oazcf

    mc glojanoxn mcf 13&3#& q wacoml {5~5;&3;/

    N {cwnr mc ~sc cf crrlr escw}rnf cw cf aomagnml& cf majcrco}c {cwl mc fnw ce{rcwnw co jsogao mc ws

    }nenl lbfain n mc}nffnr flw crrlrcw escw}rnfcw {nrn gnmn sol mc cw}lw irs{lw& glel wc aomagn co

    fn waisaco}c }nbfn8

    >>

    Cf Lbwcrzn}lral Ongalonf mc fnw ]cfcglesoagngalocw q mc fn Wlgacmnm mc fn Aojlrengao (LO]WA! cw so rinol nmwgra}l nRcm/cw gsql {raoga{nf lbhc}azl cw cf cw}smal q nofawaw mc fn Wlgacmnm mc fn Aojlrengao co Cw{nn/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    19/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon >1 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    ]nbfn 28 Crrlr escw}rnf>2

    Oecrl mc ce{fcnmlw Wcisramnm q c%glojanoxn Glo}aosamnm mc OcilgalEscw}rn Crrlr (#! Escw}rn Crrlr (#!

    Eagrlce{rcwn ==; =&9# 3;> =&=#

    [c~scn ce{rcwn 713 =&1# 7=7 3&7#

    Ecmanon ce{rcwn 7;1 3&3# 2:3 :&;#

    ]l}nf >/>== 2&1# >/>;1 2&1#

    Wcg}lr mc ng}azamnmWcisramnm q c%glojanoxn Glo}aosamnm mc Ocilgal

    Escw}rn Crrlr (#! Escw}rn Crrlr (#!

    Aomsw}ran q glow}rsggao 2>3 :&9# 2;1 :&0#

    Glecrgal q `lw}cfcrn >0: 9&2# >92 9&3#

    ]rnow{lr}c >9; 9&3# >=9 0&>#Oscznw ]cgolflinw >:; 9&9# >37 9&1#

    Wcrzagalw ce{rcwnranfcw 2;2 :&1# 2;2 :&1#

    L}rlw wcrzagalw 2>> :&9# 22: :&3#

    ]l}nf >/>== 2&1# >/>;1 2&1#

    Xlon iclirjagnWcisramnm q c%glojanoxn Glo}aosamnm mc Ocilgal

    Escw}rn Crrlr (#! Escw}rn Crrlr (#!

    Xlon Wsr >0; 9&7# >0= 9&2#Xlon Gco}rl >91 9&7# >92 9&3#Gn}nfsn 2;0 :&0# >00 9&>#

    Xlon Cw}c 2;: :&0# >00 9&>#Xlon Olr}c >17 9&># 2;> :&1#Glesoamnm mc Enmram >90 9&7# >9: 9&=#

    ]l}nf >/>== 2&1# >/>;1 2&1#

    Jsco}c8 AO]CGL

    Cw}lw rcmsgamlw ericocw mc crrlr n{lr}no janbafamnm n fn `lrn mc cp}rncr glogfswalocw rcw{cg}l nf

    glohso}l mcf }chaml ce{rcwnranf cw{nlf/

    2/2/= Rcnfaxngao mcf }rnbnhl mc gne{l

    Cf }rnbnhl mc gne{l wc `n rcnfaxnml co mlw eleco}lw majcrco}cw8 fn {nr}c N (wcisramnm mc fn

    aojlrengao q c%glojanoxn! wc `n rcnfaxnml co}rc cf >2 mc magacebrc mc 2;>> q cf >7 mc cocrl mc

    2;>2 q fn {nr}c B (glo}aosamnm mc ocilgal! co}rc cf 27 mc cocrl mc 2;>2 q cf >; mc jcbrcrl mc

    2;>2/

    Mc jlren icocrnf& wc `n ce{fcnml fn }goagn GN]A (Gle{s}cr Nwwaw}cm ]cfc{`loc Ao}crzacyaoi!&

    gle{fceco}nmn {lr GNYA (Gle{s}cr Namcm Ycb Ao}crzacyaoi!/

    >2 Co cf gfgsfl mcf crrlr cw}nmw}agl wc n glowamcrnml so soazcrwl aojaoa}l/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    20/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 2; mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    2/2/3 ]rn}neaco}l q nofawaw cw}nmw}agl mc flw mn}lw

    N {nr}ar mc fn aojlrengao rcgliamn co fn cogscw}n& wc `n n{fagnml so {fno mc cp{fl}ngao

    cw}nmw}agn ~sc `n {crea}aml mnr rcw{scw}n n flw lbhc}azlw mcjaoamlw/

    Cf {raecr {nwl {nrn cf nofawaw glowaw}c co fn }nbsfngao bwagn& ~sc ljrcgc aojlrengao icocrnf mc

    fn cogscw}n q {crea}c ecmar fn gnfamnm mc flw mn}lw/ ]rnw nonfaxnr flw faw}nmlw mc jrcgscoganw& wc `n

    {rlgcmaml nf mawcl mcf {rl}lglfl mc cp{fl}ngao mc flw mn}lw q {fno mc }nbfnw cw}nmw}agnw q

    irjaglw n lb}cocr/ Cw}c {rlgcwl wc `n ffcznml n gnbl glo cf {rlirnen W[WW& n {nr}ar mcf

    {rl}lglfl mc cp{fl}ngao/ Wc `no n{fagnml fnw waisaco}cw }goagnw cw}nmw}agnw q mc nofawaw8

    ]goagnw cw}nmw}agnw mcwgra{}aznw l maw}rabsgao mc jrcgscoganw rcfn}aznw mc }lmnw fnw

    znranbfcw gn}ciragnw mcf gscw}alonral q lb}cogao mc ecmanw {nrn fnw znranbfcw oseragnw/

    ]cw} mc aojcrcogan cw}nmw}agn l }cw} cw}nmw}aglw mc waioajagngao {nrn glolgcr wacpaw}co majcrcoganw cw}nmw}agneco}c waioajagn}aznw co}rc fnw maw}ao}nw gn}cilrnw mc son

    znranbfc/

    Nofawaw esf}aznrano}cw ~sc {crea}co son ao}cr{rc}ngao ew {rljsomn mc flw mn}lw q

    n{lr}no znflr nnmaml nf cw}smal/ Co cw}c wco}aml& wc `no rcnfaxnml mlw nofawaw gfw}cr&

    ~sc glowaw}co co gfnwajagnr son {lbfngao ne{fan& gle{scw}n {lr cf }l}nf mc {lbfngao

    cw}smanmn ({qecw! co so {c~scl oecrl mc irs{lw& es}sneco}c cpgfsqco}cw q

    cp`nsw}azlw& bnwomlwc co fnw wcechnoxnw mc {crjafcw cpaw}co}cw co}rc flw majcrco}cw

    cfceco}lw gle{loco}cw mc mag`n {lbfngao rcw{cg}l n so nw{cg}l glogrc}l& co cw}c gnwl

    fn wcisramnm mc fn aojlrengao ({raecr nofawaw! q fn glo}aosamnm mc ocilgal (wcisoml!/

    2/7 JNWC 78 CO]RCZAW]NW CO [RLJSOMAMNM

    Cf {rl{wa}l mc cw}n jnwc amco}ajagnr cp{cracoganw {nr}agsfnrcw co fn wcgsraxngao q cf

    cw}nbfcgaeaco}l mc cw}rn}cianw mc glo}aosamnm mc ocilgal co fnw ce{rcwnw& cp}rncr {n}rlocw mc

    gle{lr}neaco}l q ocgcwamnmcw mc ng}sngao {nrn fn echlrn q cf mcwnrrlffl mc fnw en}cranw lbhc}l

    mc fn aozcw}aingao co fn ce{rcwn cw{nlfn/ [nrn cffl& wc `no rcnfaxnml macx co}rczaw}nw co

    {rljsomamnm n rcw{lownbfcw mc wcisramnm {cr}cocgaco}cw n lrinoaxngalocw {nr}aga{no}cw co fn

    cogscw}n& gaogl rcfn}aznw n wcisramnm mc fn aojlrengao co fn ce{rcwn& q gaogl wlbrc glo}aosamnm

    mc ocilgal/ Fnw co}rczaw}nw `no }coaml fsinr co}rc flw ecwcw mc jcbrcrl q enrxl mc 2;>2/

    Fn amco}ajagngao mc gnmn sol mc flw {nr}aga{no}cw co fn jnwc mc co}rczaw}nw co {rljsomamnm wc `n

    `cg`l glo cf lbhc}azl mc gsbrar fn `c}crliocn rcnfamnm mcf }chaml ce{rcwnranf/ Flw gra}cralw }coamlw

    co gsco}n {nrn rcnfaxnr fn wcfcggao wc `no bnwnml co fnw gnrng}crw}agnw ~sc mcjaoco flw {crjafcw

    mc}cg}nmlw n {nr}ar mc flw nofawaw gfw}cr& ~sc wlo nonfaxnmlw co mc}nffc co cf gn{}sfl 0/

    Wcisramnm mc fn Aojlrengao8 ce{rcwnw {rl}ciamnw& {rcgnzamnw& mcw{rclgs{nmnw c

    ae{rsmco}cw/

    Glo}aosamnm mc Ocilgal8 ce{rcwnw & {rc{nrnmnw& mcw{rczcoamnw& aomajcrco}cw q

    }cecrnranw/

    Flw macx {crjafcw wcfcggalonmlw {nrn fn rcnfaxngao mc co}rczaw}nw co {rljsomamnm wc escw}rno co fn

    Afsw}rngao 2/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    21/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 2> mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Afsw}rngao 28 [crjafcw mc ce{rcwnw {nr}aga{no}cw co fn jnwc mc co}rczaw}nw co {rljsomamnm

    WCISRAMNM MC FN AOJLRENGAO

    Ce{rcwn >

    Oecrl mc ce{fcnmlw8 :3

    Ng}azamnm8 Wcrzagalw mc aoicoacrn q}cfcglesoagngalocw/

    Maw{loc mc nf ecolw gaogl lrmconmlrcw&c~sa{lw {lr}}afcw q wenr}{`locw/

    Ol gsco}n glo {crwlonf mcmagnml co cpgfswaznn fn wcisramnm mc fn aojlrengao/

    @n }coaml nfio aogamco}c mc wcisramnm q `n}lenml ecmamnw }rnw f/

    Ce{rcwn 2

    Oecrl mc ce{fcnmlw8 ecolw mc >;

    Ng}azamnm8 Wcrzagalw mc {sbfagamnm q enrdc}aoi/

    Maw{loc mc nf ecolw mlw lrmconmlrcw

    Gsco}n glo {crwlonf mcmagnml cpgfswazneco}cn fn wcisramnm mc fn aojlrengao/

    @n }coaml nfio aogamco}c mc wcisramnm q `n}lenml ecmamnw }rnw f/

    Ce{rcwn 7

    Oecrl mc ce{fcnmlw8 12

    Ng}azamnm8 Wcrzagalw ce{rcwnranfcw

    Maw{loc mc nf ecolw mlw lrmconmlrcw

    Maw{loc mc ce{rcwn cp}cron ~sc icw}alon flwnw{cg}lw mc wcisramnm mc fn aojlrengao/

    @n }coaml nfio aogamco}c mc wcisramnm q `n}lenml ecmamnw }rnw f/

    Ce{rcwn =

    Oecrl mc ce{fcnmlw8 7

    Ng}azamnm8 Glecrgal

    Maw{loc mc so lrmconmlr/

    Ol maw{loc mc {crwlonf mcmagnml nwcisramnm mc fn aojlrengao/

    Ol `n }coaml aogamco}cw mc wcisramnm/

    Ce{rcwn 3

    Oecrl mc ce{fcnmlw8 23

    Ng}azamnm8 Glecrgal q maw}rabsgao/

    Maw{loc mc ew mc 3 lrmconmlrcw& c~sa{lw{lr}}afcw q wenr}{`locw/

    @n }coaml nfio aogamco}c mc wcisramnm q `n

    }lenml ecmamnw }rnw f/

    GLO]AOSAMNM MC OCILGAL

    Ce{rcwn :

    Oecrl mc ce{fcnmlw8 >3;

    Ng}azamnm8 Maw}rabsgao mc wlj}ynrc/

    Maw{loc mc son cw}rn}cian mc glo}aosamnmmc ocilgal/

    Ce{rcwn 9

    Oecrl mc ce{fcnmlw8 3;/

    Ng}azamnm8 Wcrzagalw n }rnbnhnmlrcw/

    Fnw ng}azamnmcw gr}agnw mcf ocilgal cw}o

    amco}ajagnmnw/ @n wsjraml co cf f}ael nl so aogamco}c mc

    glo}aosamnm mc ocilgal/

    Ol maw{loc mc son cw}rn}cian mcglo}aosamnm mc ocilgal/

    Ce{rcwn 0

    Oecrl mc ce{fcnmlw8 >/

    Ng}azamnm8 L}rlw wcrzagalw/

    Fnw ng}azamnmcw gr}agnw mcf ocilgal cw}oamco}ajagnmnw/

    Ol maw{loc mc son cw}rn}cian mcglo}aosamnm mc ocilgal/

    Ce{rcwn 1

    Oecrl mc ce{fcnmlw8 3/

    Ng}azamnm8 Wcrzagalw mc aojlre}agn/

    Fnw ng}azamnmcw gr}agnw mcf ocilgal cw}oamco}ajagnmnw/

    Maw{loc mc son cw}rn}cian mc glo}aosamnmmc ocilgal/

    Glo cp{cracoganw {rczanw mc aogamco}cw gloae{ng}l co fn glo}aosamnm mc fnwl{crngalocw mc ocilgal/

    Ce{rcwn >;

    Oecrl mc ce{fcnmlw8 >;;/

    Ng}azamnm8 ]rnow{lr}c/

    Fnw ng}azamnmcw gr}agnw mcf ocilgal cw}oamco}ajagnmnw/

    Glo cp{cracoganw {rczanw mc aogamco}cw gloae{ng}l co fn glo}aosamnm mc fnwl{crngalocw mc ocilgal/

    Maw{loc mc son cw}rn}cian mc glo}aosamnm

    mc ocilgal/Jsco}c8 AO]CGL

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    22/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 22 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    2/= JNWC =8 IRS[L MC ]RNBNHL JAONF GLO CP[CR]LW GSNFAJAGNMLW

    [lr f}ael& wc `no ffcznml n gnbl fn grcngao mc so irs{l mc }rnbnhl glo cp{cr}lw mc majcrco}cw

    eba}lw/ [nrn fn cfcggao mc fn rcfngao mc cp{cr}lw ~sc jlrenrlo cf irs{l wc `n }coaml co gsco}n{raoga{nfeco}c ws cp{cracogan {rljcwalonf& nw glel cf gnril ~sc lgs{no mco}rl mc fn ce{rcwn

    (gnrilw glo rcw{lownbafamnm q glolgaeaco}lw wlbrc fn wcisramnm mc fn aojlrengao!/

    [lr l}rn {nr}c }nebao wc glowamcr fn mazcrwamnm mc {crjafcw (maw}ao}lw }a{lw mc ce{rcwnw q

    co}amnmcw& nwlgangalocw ce{rcwnranfcw! q ws rc{s}ngao mco}rl mcf wcg}lr/ Nw& cw}nbno

    rc{rcwco}nmnw fn aomsw}ran mc fn wcisramnm mc fn aojlrengao& nwlgangalocw mc ce{rcwnw mcf wcg}lr

    ]AG& irnomcw ce{rcwnw glowseamlrnw q ~sc ae{raeco so cjcg}l }rng}lr co fn nml{gao mc

    wlfsgalocw mc wcisramnm& lrinoawelw mc gcr}ajagngao& ns}lramnmcw mc glo}rlf co cf eba}l mc fn

    {rl}cggao mc mn}lw {crwlonfcw& ce{rcwnw {rlzccmlrnw mc wcrzagalw fcinfcw q wcrzagalw mc

    glowsf}lrn q n{lql rcfngalonmlw glo fn {rl}cggao mc mn}lw {crwlonfcw co fn ce{rcwn/

    Fn rcfngao mc cp{cr}lw {nr}aga{no}cw co cf {rcwco}c cw}smal cw fn waisaco}c8

    Ceafal Ngcm (Nicogan mc [rl}cggao mc Mn}lw mc fn Glesoamnm mc Enmram!/

    Nmrao Nisml (Aomrn Waw}cenw!/

    Gwnr Nflowl (NSMAWCG Wcisramnm mc fn Aojlrengao!/

    No}loal Gaelrrn (Nwlgangao Esf}awcg}lranf mc Ce{rcwnw mc fn Cfcg}roagn& fnw ]cgolflinw

    mc fn Aojlrengao q Glesoagngao& mc fnw }cfcglesoagngalocw q mc flw glo}coamlw maia}nfcw% NEC]AG!/

    Fsaw Jscr}cw (Wqeno}cg Abragn!/

    Ragnrm Enr}ocx (Nwlgangao [rljcwalonf Cw{nlfn mc [razngamnm % N[C[!!/

    Lwgnr [nw}lr (Aoicoacrn mc Waw}cenw {nrn fn Mcjcown mc Cw{nn % AWMCJC!/

    [nbfl [rcx (Lbwcrzn}lral mc fn Wcisramnm mc fn Aojlrengao& mcf Aow}a}s}l Ongalonf mc

    ]cgolflinw mc fn Glesoagngao% AO]CGL!

    Hlw oicf Znfmcrrnen (Nwlgangao Cw{nlfn mc Olrenfaxngao q Gcr}ajagngao % NCOLR!/

    Wc ffcz n gnbl son wcwao mc mcbn}c& gcfcbrnmn cf mn 20 mc enrxl mc 2;>2 n fnw >:87; `lrnw&

    glo son msrngao mc 2&3 `lrnw/ Cf lbhc}azl mc cw}c irs{l jaonf `n waml {rljsomaxnr co flw rcwsf}nmlw

    lb}coamlw co cf nofawaw no}cralr& nw glel rcgnbnr fn l{aoao mc cw}lw cp{cr}lw {rljcwalonfcw q

    cp{cr}lw fainmlw nf eba}l mc fn wcisramnm ]AG q fn glo}aosamnm mc ocilgal co rcfngao n fnw

    {raoga{nfcw aogamcoganw& }no}l n oazcf }goagl glel fcinf {rlmsgamnw co fnw ce{rcwnw& nw glel fn

    {lwabfc amco}ajagngao mc fnw {raoga{nfcw rcglecomngalocw {nrn ea}ainr cw}nw aogamcoganw/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    23/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 27 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    [nrn fn glowcgsgao mcf lbhc}azl& fn ec}lmlflin mc }rnbnhl msrno}c fn wcwao `n glowaw}aml co fn

    {rcwco}ngao mc flw rcwsf}nmlw {rcfaeaonrcw mc fn cogscw}n q fn n{cr}srn mc so }srol mc mcbn}c

    msrno}c cf ~sc flw cp{cr}lw `no n{lr}nml wsw l{aoalocw l glowamcrngalocw/ ]lml cffl `n waml

    ffcznml n gnbl glo cf glo}rlf mc so elmcrnmlr/

    Glo {lw}cralramnm n fn gcfcbrngao mc fn wcwao& cf nofawaw wc `n bnwnml co cf cw}smal mc fn

    }rnowgra{gao fa}crnf mc fnw mcfabcrngalocw& ~sc `no waml cpneaonmnw& jaf}rnmnw c ao}cirnmnw co cf

    {rcwco}c cw}smal/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    24/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 2= mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    7 @CRRNEACO]NW ]GOAGNW Q [CRWLONF MC

    WCISRAMNM

    Co cf {rcwco}c cw}smal& fnw ce{rcwnw {nr}aga{no}cw escw}rno so ol}nbfc swl mc fnw ]AG/ Cf

    lrmconmlr mc wlbrcecwn cw son `crrneaco}n ae{rcwgaomabfc co fn ng}azamnm ce{rcwnranf& glo so

    12&7# mc {coc}rngao/ Cf lrmconmlr {lr}}af cw} {rcwco}c co so =9&2# mc fnw ce{rcwnw q

    maw{lwa}azlw ezafcw glel flw wenr}{`locw& }nbfc}nw q [MNw& co so 29&>#/ Fnw ce{rcwnw wcnfno

    cf rcgnebal }cgolfiagl (mcbaml n fn n{nragao mc osczlw {rlmsg}lw l }nebao {lr aogamco}cw mc

    wcisramnm! glel so jng}lr ~sc aojfsqc co wsw ocilgalw/

    L}rl aomagnmlr mcf oazcf mc fn ae{lr}nogan mc fnw ]AG co fn {c~scn q ecmanon ce{rcwn cw{nlfn

    cw fn ao}crglocpao mc wsw c~sa{lw/ Mlw mc gnmn }rcw lrinoaxngalocw magco }cocr ao}crglocg}nmlw

    wsw c~sa{lw n }rnzw mc son rcm yaja& eaco}rnw ~sc fn {coc}rngao mc fnw rcmcw mc rcn flgnf (FNO!wc wa}n co cf 31&0#/ Jaonfeco}c& so =>&7# s}afaxn glocpao n }rnzw mc nggcwl rcel}l/

    Irjagl 78 Maw}rabsgao mcf swl mc }cgolflinw ]AG (#!

    Bnwc8 ]l}nf ce{rcwnw ~sc rcw{lomco nf gscw}alonral mc wcisramnm (o5>/>==! Jsco}c8 AO]CGL

    Mnml cf swl ~sc rcnfaxno cw}nw ce{rcwnw mc fnw oscznw }cgolflinw& co cf {rcwco}c n{nr}nml wc

    cw}sman fn {crgc{gao mcf glfcg}azl {nr}aga{no}c co cf cw}smal co gsno}l n ws irnml mc {rl}cggao

    co en}cran mc wcisramnm mc fn aojlrengao/

    [lr cffl& wc cw}smano flw rcgsrwlw }goaglw q `senolw mcmagnmlw n fn wcisramnm mc fn aojlrengao&

    cf irnml mc ae{fno}ngao mc fnw `crrneaco}nw co fn ce{rcwn& fn wcisramnm co flw maw{lwa}azlw

    ezafcw q co fnw rcmcw aonfebragnw& cf {crwlonf mcmagnml n fn wcisramnm& q fn czlfsgao mc fn

    aozcrwao co wcisramnm/

    29&>#

    =>&7#

    =9&2#

    31&0#

    ::&2#

    12&7#

    ;# >;# 2;# 7;# =;# 3;# :;# 9;# 0;# 1;# >;;#

    Maw{lwa}azlw ezafcw ([MN& Wenr}{`loc& ]nbfc}n!

    Nggcwl rcel}l

    Lrmconmlrcw {lr}}afcw

    Rcm mc rcn flgnf (FNO!

    Rcmcw aonfebragnw (Yaja!

    Lrmconmlrcw mc wlbrcecwn

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    25/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 23 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Co flw gn{}sflw {lw}cralrcw& wc gle{fceco}n cw}c maniow}agl glo cf nofawaw mc fnw bsconw

    {rg}agnw {nrn fn {rl}cggao q wc cpneaon fn {crgc{gao wlbrc cf glolgaeaco}l c ae{fceco}ngao

    mc {fnocw q {lf}agnw mc wcisramnm q glo}aosamnm mc ocilgal/

    Cf nofawaw {nr}c mc fn l{aoao mc flw rcw{lownbfcw mc wcisramnm q glo}aosamnm mc fnw ce{rcwnw

    wlbrc flw {rlgcmaeaco}lw q `crrneaco}nw ~sc {crea}co inrno}axnr fn ao}ciramnm& maw{loabafamnm q

    glojamcoganfamnm mc fn aojlrengao/ Flw rcwsf}nmlw wc gle{fceco}no glo so nofawaw wcieco}nml

    {lr }nenl l wcg}lr cgloeagl glo cf lbhc}l mc n{lr}nr enqlr ra~scxn nf cw}smal/

    Fn aojlrengao lb}coamn co cf }rnbnhl mc gne{l gsno}a}n}azl wc cp{fagn& co flw gnwlw co ~sc cw

    {lwabfc& glo fnw n{lr}ngalocw mc flw cp{cr}lw q rcw{lownbfcw mc wcisramnm ~sc `no {nr}aga{nml co

    cf cw}smal/

    [lr f}ael& wcnfnr ~sc co flw gnwlw co ~sc fn aojlrengao rcgnbnmn fl {crea}c& wc rcnfaxn so

    nofawaw floia}smaonf& s}afaxnoml {nrn cffl flw rcwsf}nmlw lb}coamlw co cw}smalw {rczalw mc AO]CGL&

    nw glel mc l}rnw jsco}cw mlgseco}nfcw>7/

    7/> @CRRNEACO]NW MC WCISRAMNM CO FN CE[RCWN CW[NLFN8 AE[FNO]NGAO Q

    EL]AZNGAO

    Glel wc mcw{rcomc mcf nofawaw& fnw ce{rcwnw njareno maw{locr mc mazcrwnw `crrneaco}nw mc

    wcisramnm {nrn {rl}cicr wsw c~sa{lw& glo so ol}nbfc oazcf mc nml{gao co focnw icocrnfcw/

    Cw}c cw cf gnwl mc fnw wlfsgalocw nwlganmnw n fn wcisramnm co fn onzcingao& cognbcxnmnw {lr flw

    no}azarsw q,l no}acw{nw (1:&>#!& wcisamlw mc flw glr}njscilw (93&=#!& flw {rlirnenw no}aw{ne

    (93&7#! q fnw `crrneaco}nw mc bfl~scl mc zco}nonw cecrico}cw (9>&3#!/

    [lr mc}rw mc cw}nw wc wa}no `crrneaco}nw l ecmamnw ~sc ae{fagno fn {nr}aga{ngao mcf swsnral&

    glel fn cfaeaongao mc nrg`azlw }ce{lrnfcw q glldacw (:9&=#! q n~scffnw ~sc n{lr}no

    jsogalonfamnmcw nmagalonfcw n fnw }rnmagalonfcw ~sc ljrcgc son wlfsgao no}aenfynrc& glel flw

    waw}cenw mc glo}rlf mc ao}rswao (32&1#!& flw {fsiaow l gle{fceco}lw mc wcisramnm {nrn cf

    onzcinmlr (3>&=#! q cf gajrnml mc mn}lw (7=&>#!/ ]no wlfl cf 2&=# mc fnw lrinoaxngalocw

    glowsf}nmnw wcnf ol glo}nr glo oaoison mc fnw aomagnmnw/

    Fn {crgc{gao mc fnw ce{rcwnw cogscw}nmnw wlbrc fn aoglr{lrngao mc wlfsgalocw mc wcisramnm wc

    nhsw}n co focnw icocrnfcw n fn rcnfamnm& wcio flw cp{cr}lw glowsf}nmlw co cf enrgl mcf cw}smal/Co cw}c wco}aml& fnw lrinoaxngalocw wscfco nm~sarar wlfsgalocw {n~sc}axnmnw& ~sc gsco}no glo son

    wcrac mc jsogalonfamnmcw/ Nfisonw wlo {crgabamnw {lr~sc wlo glolgamnw ne{faneco}c (no}azarsw ,

    no}acw{nw& glr}njscilw>=!& l}rnw wlo mcgfnrnmnw co ecolr ecmamn nso~sc cw}o co cwlw {n~sc}cw

    (no}aw{ne& cfaeaongao mc nrg`azlw }ce{lrnfcw q glldacw!/ oagneco}c co cf gnwl mcf gajrnml mc

    mn}lw wc {rcwsec son ecolr {coc}rngao mc fn lb}coamn co fn cogscw}n/

    >7 Zcr n{nr}nml NOCPL A/

    >= Wcio cf cw}smal Fnw ]cgolflinw mc fn Aojlrengao q fnw Glesoagngalocw co fn ce{rcwn cw{nlfn& mc NC]AG%Czcraw

    (2;>>!& cf 1:&7# mc fnw ce{rcwnw cw{nlfnw maw{loc mc so {rlirnen no}azarsw q cf 0>&2# mc waw}cenw mc glr}njscilw/Maw{loabfc co8`}}{8,,yyy/czcraw/gle,w{nao,YGRc{lwa}lrqJafcw,Cw}smal\czcraw\NEC]AG/{mj

    http://www.everis.com/spain/WCRepositoryFiles/Estudio_everis_AMETIC.pdfhttp://www.everis.com/spain/WCRepositoryFiles/Estudio_everis_AMETIC.pdfhttp://www.everis.com/spain/WCRepositoryFiles/Estudio_everis_AMETIC.pdfhttp://www.everis.com/spain/WCRepositoryFiles/Estudio_everis_AMETIC.pdf
  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    26/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 2: mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Co cw}c wco}aml& fnw ce{rcwnw {nr}aga{no}cw co fn co}rczaw}n co {rljsomamnm wcnfno ~sc cf gajrnml

    mc mn}lw cw ao`crco}c n fn s}afaxngao mc wcrzagalw ]AG glel fn bnogn cfcg}roagn& fl ~sc {scmc

    aojfsar co fn cfcznmn {rl{lrgao mc ce{rcwnw ~sc glowamcrn ~sc s}afaxn cw}n `crrneaco}n/

    Cw}c glfcg}azl {crgabc fn cpaw}cogan mc racwilw ~sc ol wlfsgalono fnw `crrneaco}nw ng}snfcw& glel

    {lr chce{fl cf `ngdaoi l cf w{ne/ Nmcew& mcenomno fn ao}cirngao mc fn wlfsgao q glojaisrngao

    mc wcisramnm co fn wsbglo}rn}ngao mc wlfsgalocw }cgolfiagnw& {lr chce{fl& nf `nbfnr mc wcrzagalw

    mc gflsm gle{s}aoi/

    Irjagl =8 Oazcf mc ae{fno}ngao mcgfnrnml mc wlfsgalocw mc wcisramnm co fn ce{rcwn (#!

    Bnwc8 ]l}nf ce{rcwnw ~sc rcw{lomco nf gscw}alonral mc wcisramnm (o5>/>==! Jsco}c8 AO]CGL

    Fn czlfsgao co cf oazcf mc {coc}rngao mc fnw {raoga{nfcw wlfsgalocw mcwmc 2;;1 >3n fn ng}snfamnm

    cw {lwa}azn/ Fnw wlfsgalocw ew glesocw& glel flw glr}njscilw l flw no}azarsw,no}acw{n escw}rno

    znflrcw waeafnrcw co neblw {cralmlw/ Wao cebnril& nfisonw `crrneaco}nw mcgfnrnmnw co ecolr

    ecmamn co 2;;1 cp{craeco}no so nwgcowl co ws ae{fno}ngao& glel cf no}aw{ne (~sc {nwn mc so

    :># co 2;;1 n so 93&7# co 2;>2! l cf bfl~scl mc zco}nonw cecrico}cw (mc so 3=&=# n so9>&3#!/

    Cw ae{lr}no}c }cocr co gsco}n fn aoglr{lrngao mc ce{rcwnw mc enqlr maecowao co {rcwco}c

    cw}smal& qn ~sc cf soazcrwl glowamcrnml znrn rcw{cg}l nf mcf no}cralr/ Co cf nl 2;;1 cw}nbn

    glow}a}saml {lr ce{rcwnw mc `nw}n 3; ce{fcnmlw& eaco}rnw ~sc co fn cmagao ng}snf cw}

    glojlrenml {lr ce{rcwnw mc `nw}n 23; ce{fcnmlw/

    >3 Jsco}c8 Zcr ol}n nf {ac 7/

    7=&>#

    3>&=#

    32&1#

    :9&=#

    9>&3#

    93&7#

    93&=#

    1:&>#

    ;# 2;# =;# :;# 0;# >;;#

    Gajrnml mc mn}lw

    [fsiaow l gle{fceco}lw {nrn cfonzcinmlr

    Waw}cenw mc glo}rlf mc ao}rswao

    Cfaeaongao mc nrg`azlw }ce{lrnfcw qglldacw

    Bfl~scl mc zco}nonw cecrico}cw

    No}aw{ne

    Glr}njscilw

    No}azarsw,No}acw{n

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    27/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 29 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Irjagl 38 Oazcf mc ae{fno}ngao mcgfnrnml mc fnw {raoga{nfcw wlfsgalocw mc wcisramnm

    Czlfsgao 2;;1%2;>2 (#!

    Bnwc 2;>28 }l}nf ce{rcwnw (o5>/>==! Jsco}c8 AO]CGL

    Bnwc 2;;18 }l}nf ce{rcwnw (o52/2;:!

    Fn {rcjcrcogan {lr fnw maw}ao}nw `crrneaco}nw ol znrn co jsogao mcf }nenl (fnw `crrneaco}nw ewmcgfnrnmnw wlo no}azarsw,no}acw{n& glr}njscilw q no}aw{ne!& nso~sc w cf irnml mc s}afaxngao&

    enqlr co fnw ecmanonw ce{rcwnw/

    ]nbfn 78 Maw{loabafamnm mc `crrneaco}nw {nrn {rl}cicr c~sa{lw q waw}cenw

    wcio }nenl mc fnw ce{rcwnw (#!

    Wlfsgalocw Eagrlce{rcwn[c~scnce{rcwn

    Ecmanonce{rcwn

    No}azarsw,No}acw{n 1:&> 19&: 10&2

    Glr}njscilw 9=&1 02&: 1;&=

    No}aw{ne 9=&1 0;&: 17&:Bfl~scl mc zco}nonwcecrico}cw& bnoocrw{sbfaga}nralw

    9>&= 92&9 0;&2

    Cfaeaongao mc nrg`azlw}ce{lrnfcw q glldacw :9&2 :1&7 97&1

    Waw}cenw mc glo}rlf mc ao}rswao 32&3 3:&0 ::&9

    [fsiaow l gle{fceco}lw mcwcisramnm {nrn cf onzcinmlr

    3>&; 39&> :3&7

    Gajrnml mc mn}lw 77&= =3&9 3=&3

    Bnwc8 ]l}nf ce{rcwnw ~sc rcw{lomco nf gscw}alonral mc wcisramnm (o5>/>==! Jsco}c8 AO]CGL

    3=&=#

    :>&;#

    92&=#

    19&0#

    9>&3#

    93&7#

    93&=#

    1:&>#

    ;# >;# 2;# 7;# =;# 3;# :;# 9;# 0;# 1;# >;;#

    Bfl~scl mc zco}nonwcecrico}cw

    No}aw{ne

    Glr}njscilw

    No}azarsw,No}acw{n

    2;>2 2;;1

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    28/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 20 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Fn }nbfn waisaco}c escw}rn gsfcw wlo fnw rnxlocw n{lr}nmnw {lr fnw ce{rcwnw {nrn hsw}ajagnr fn ol

    maw{loabafamnm mc fnw maw}ao}nw `crrneaco}nw mc wcisramnm/ Son {nr}agsfnramnm n }cocr co gsco}n& cw

    ~sc fn bnwc mc gfgsfl wc glow}a}sqc co gnmn gnwl {lr fnw ce{rcwnw ~sc magco ol s}afaxnr gnmn

    wlfsgao& {lr fl ~sc flw mn}lw mcbco }lenrwc ecrneco}c glel lraco}n}azlw/

    Fnw ce{rcwnw ~sc `no aomagnml ol maw{locr mc fnw maw}ao}nw `crrneaco}nw mc wcisramnm nfcino

    majcrco}cw el}azlw {nrn ol ae{fno}nrfnw& {raoga{nfeco}c cf mcwglolgaeaco}l q fn jnf}n mc

    ocgcwamnm>:/ L}rnw glowamcrngalocw& glel cf glw}c& fn wcowngao mc aocjagngan l mc

    co}lr{cgaeaco}l co cf jsogaloneaco}l mcf c~sa{l& n{nrcgco co ecolr ecmamn q mc jlren mcwaisnf

    co jsogao mc fn `crrneaco}n mc ~sc wc }rn}c co gnmn eleco}l/ Nwaeawel& wlr{rcomc cf cfcznml

    {lrgco}nhc mc ce{rcwnw ~sc ol mno son rcw{scw}n/

    Co jsogao mc gnmn `crrneaco}n wc cogsco}rno majcrcoganw ~sc wc cp{loco n glo}aosngao/ Cf

    mcwglolgaeaco}l cw enqlr co fnw ce{rcwnw ~sc ol s}afaxno waw}cenw mc glo}rlf mc ao}rswao&{fsiaow l glr}njscilw& eaco}rnw ~sc fnw ~sc ol maw{loco mc no}azarsw,no}acw{n q no}aw{ne wlo fnw

    ~sc nfcino ol ocgcwa}nr fnw `crrneaco}nw q wlfsgalocw mc wcisramnm/ [lr f}ael mcw}ngn ~sc cf

    co}lr{cgaeaco}l ~sc {rlzlgno fnw `crrneaco}nw cw so el}azl mcw}ngnml co}rc fnw lrinoaxngalocw

    ~sc ol }acoco no}azarsw,no}acw{n/

    ]nbfn =8 El}azlw wcnfnmlw {lr fnw ce{rcwnw {nrn ol s}afaxnr

    fnw `crrneaco}nw q wlfsgalocw mc wcisramnm (#!

    Wlfsgalocw

    #ce{rcwnw~sc ol

    s}afaxno cofn

    ng}snfamnm

    El}azlw

    Olglolgc

    Olocgcwa}n

    [rcgal

    Aocjagngcw

    Co}lr{cgco

    L}rlw

    Olglo}cw}n

    No}azarsw , No}acw{n 7&1 2&7 71&: ;&= 3&> >9&= >=&1 2;&7Glr}njscilw 2=&: 73&: 29&2 7&2 ;&0 2&0 ;&2 7;&2No}aw{ne 2=&9 20&; 70&0 ;&> ;&0 7&0 ;&2 20&7[fsiaow =0&: 79&; 20&= ;&3 ;&3 2&; ;&= 7>&2Bfl~scl mc zco}nonw

    cecrico}cw

    20&3 77&7 21&9 ;&; ;&1 2&1 ;&2 77&;

    Waw}cenw mc glo}rlfmc ao}rswao =9&>

    70&; 2:&; >&= ;&= 2&> ;&2 7>&1

    Gajrnml mc mn}lw :3&1 73&> 73&2 ;&= ;&3 >&: ;&0 2:&=Cfaeaongao mcnrg`azlw }ce{lrnfcwq glldacw

    72&: 21&> 72&3 ;&9 >&> 7&> >&3 72&;

    Bnwc8 ce{rcwnw ~sc ol s}afaxno fnw `crrneaco}nw q wlfsgalocw mc wcisramnm Jsco}c8 AO]CGL

    >: Wcio cf Cw}smal AA Bnrec}rl Ao}crongalonf mc Wcisramnm co fnw [qecw[nomn Wcgsra}q (2;>;! cf {raoga{nf {rlbfcen {nrn

    ol ao}rlmsgar so waw}cen mc wcisramnm co fnw ce{rcwnw cw{nlfnw cw fn jnf}n mc ocgcwamnm/ Maw{loabfc co8`}}{8,,yyy/ao}cgl/cw,w}smqGn}cilrq,Wcisramnm,Lbwcrzn}lral,Babfal}cgn,bnrlec}rl\ao}crongalonf\[QECW\{nomn

    http://www.inteco.es/studyCategory/Seguridad/Observatorio/Biblioteca/barometro_internacional_PYMES_pandahttp://www.inteco.es/studyCategory/Seguridad/Observatorio/Biblioteca/barometro_internacional_PYMES_pandahttp://www.inteco.es/studyCategory/Seguridad/Observatorio/Biblioteca/barometro_internacional_PYMES_panda
  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    29/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 21 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Co }reaolw icocrnfcw& fn {crgc{gao mcf irnml mc ae{fno}ngao mc fnw `crrneaco}nw mc wcisramnm

    cw ol}nbfc& {scw}l ~sc }lmnw fnw ecmamnw& n cpgc{gao mcf gajrnml mc mn}lw& wlo mcgfnrnmnw {lr

    ew mc fn ea}nm mc fnw ce{rcwnw/ Cw cw{cganfeco}c mcw}ngnml cf swl mc `crrneaco}nw maw{loabfcw

    co wlfsgalocw co {n~sc}c& glel no}azarsw q glr}njscilw& ~sc cw}o ew cp}comamnw ~sc cf rcw}l/

    Ol lbw}no}c& fnw ce{rcwnw escw}rno mcwglolgaeaco}l& mcwao}crw q jnf}n mc rcgsrwlw n fn `lrn mc

    n{fagnr `crrneaco}nw ew nff mc fnw }rnmagalonfcw/ Flw cp{cr}lw q flw rcw{lownbfcw mc wcisramnm

    mc fnw ce{rcwnw ~sc `no glfnblrnml co cf cw}smal glowamcrno ~sc wc mcbc }rnbnhnr {nrn ne{fanr cf

    irnml mc ao}cirngao mc fnw `crrneaco}nw& glo ecmamnw glel fn wcowabafaxngao {lr {nr}c mc flw

    lrinoawelw ~sc }rnbnhno marcg}neco}c glo cw}c glfcg}azl/

    7/2 WCISRAMNM CO MAW[LWA]AZLW EZAFCW Q GLESOAGNGALOCW AONFEBRAGNW

    Flw maw{lwa}azlw ezafcw gnmn zcx }acoco ew {rcwcogan co fnw ce{rcwnw/ Wcio EgNjcc >9& co

    2;>; wac}c mc gnmn macx lrinoaxngalocw mc{comno co enqlr ecmamn mc flw ezafcw ~sc >2 ecwcwno}cw/ Fn cp}cowao mcf swl q fn grcgaco}c gle{fchamnm mc cw}c }a{l mc maw{lwa}azlw (glo

    jsogalonfamnmcw glel fn }rnoweawao mc mn}lw& cf nfengconeaco}l mc aojlrengao l fn glocpao n

    Ao}croc}! ae{fagno fn ocgcwamnm mc inrno}axnr ws {rl}cggao/

    Nw& glel escw}rn cf waisaco}c irjagl& fnw ce{rcwnw maw{loco mc mazcrwnw ecmamnw mc wcisramnm

    {nrn wsw maw{lwa}azlw ezafcw/ Co}rc fnw ew ecogalonmnw& mcw}ngn cf nggcwl ecmano}c gmail

    [AO (so 39&0#!& q fnw glo}rnwcnw mc mcwbfl~scl (so =:&>#!/

    Ecolw mc so }crgal mc fnw ce{rcwnw glo cw}lw maw{lwa}azlw ezafcw wcnfno l}rnw ecmamnw glel fn

    rcnfaxngao mc fnw gl{anw mc wcisramnm mc mn}lw wcowabfcw (7>&9#!& Bfsc}ll}` lgsf}l q gloglo}rnwcn (7;&1#!& ng}snfaxngalocw mcf wlj}ynrc ns}le}agnw (20&0#!& q flw {rlirnenw no}azarsw

    (2>&0#!/ Co}rc fnw ecolw s}afaxnmnw wc wa}no cf gajrnml mc mn}lw (wfl cf 9&7# mc fnw ce{rcwnw

    njareno maw{locr mc cw}c waw}cen!& cf blrrnml mc mn}lw co rcel}l (>7&3#! l fn ae{lwabafamnm mc fn

    aow}nfngao mc {rlirnenw l n{fagngalocw (>3&3#!/

    [lr f}ael& wc lbwcrzn ~sc fnw ce{rcwnw mc ecolr }nenl mcgfnrno s}afaxnr {raoga{nfeco}c

    ecmamnw ew majsomamnw& q ~sc `nba}snfeco}c cw}o {rcaow}nfnmnw co flw {rl{alw maw{lwa}azlw q

    ns}len}axnmnw/ Co gnebal& fnw ecmanonw rcgsrrco n l}rnw ew gle{fchnw q escw}rno so enqlr

    irnml mc {rclgs{ngao {lr cf nggcwl n flw maw{lwa}azlw q n flw mn}lw/

    >9 Jsco}c8 EGNJCC (2;>;! Elzafamnm q wcisramnm8 ae{rcwalono}cw l{lr}soamnmcw mcwnjlw {rljsomlw& Co cf cw}smal wc

    rcnfaxnrlo >/3;; cogscw}nw n lrinoaxngalocw mc >= {nwcw co}rc flw ~sc wc aogfsn n Cw{nn/ Fnw cogscw}nw wcrcnfaxnrlo n rcw{lownbfcw mc fnw }cgolflinw mc fn aojlrengao mc ce{rcwnw mc ew mc >;; }rnbnhnmlrcw/

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    30/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 7; mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Irjagl : 8 Ecmamnw mc wcisramnm s}afaxnmnw,aow}nfnmnw co flw maw{lwa}azlw ezafcw (#!

    Bnwc8 Ce{rcwnw ~sc maw{loco mc maw{lwa}azlw ezafcw (o5=31! Jsco}c8 AO]CGL

    Co }reaolw icocrnfcw fnw ce{rcwnw ao}cirno co enqlr ecmamn cfceco}lw mc wcisramnm co flw

    c~sa{lw aojlre}aglw ~sc co flw maw{lwa}azlw ezafcw/

    Cw}c cw cf gnwl mc flw {rlirnenw no}azarsw,no}acw{n& glo son {coc}rngao gnwa }l}nf co

    lrmconmlrcw (so 1:&>#! q ecolr co maw{lwa}azlw ezafcw so (so 2>&0#!/ Fn majcrcogan }nebao cw

    ngswnmn co cf gnwl mc fnw gl{anw mc wcisramnm (so 00&2# mcgfnrn rcnfaxnrfnw co flw lrmconmlrcw&

    jrco}c n so 7>&9# co flw ezafcw!/

    Cf Irjagl 9 escw}rn fn {crgc{gao mc fnw ce{rcwnw nf gle{nrnr cf oazcf mc wcisramnm mc flw

    maw{lwa}azlw ezafcw jrco}c n c~sa{lw jahlw q {lr}}afcw/ N cw}c rcw{cg}l `nq ~sc wcnfnr ~sc cf

    {lrgco}nhc mc ce{rcwnw ~sc `no wsjraml so aogamco}c mc wcisramnm cw esq waeafnr }no}l co cf gnwl

    mc flw maw{lwa}azlw ezafcw glel co cf mc flw lrmconmlrcw/

    [nrn ew mc fn ea}nm mc fnw ce{rcwnw& flw maw{lwa}azlw ezafcw ol ae{fagno ecolr wcisramnm glorcw{cg}l nf rcw}l mc c~sa{lw8 {nrn so =1&1# wlo aisnf mc wcisrlw ~sc so lrmconmlr jahl&

    coglo}rnoml enqlr waeafa}sm glo flw lrmconmlrcw {lr}}afcw (31&=#!/ Ol lbw}no}c& nfil ew mc so

    }crgal glowamcrn ~sc wlo ecolw wcisrlw& cw{cganfeco}c jrco}c nf lrmconmlr mc wlbrcecwn/

    9&7#

    >7&3#

    >3&3#

    >1&=#

    2;&9#

    2>&0#

    20&0#

    7;&1#

    7>&9#

    =:&>#

    39&0#

    ;# 2;# =;# :;#

    Gajrnml mc mn}lw q,l glesoagngalocw

    Blrrnml rcel}l mc mn}lw co gnwl mcwsw}rnggao,cp}rnzl

    Ae{lwabafamnm mc aow}nfngao mc {rlirnenw ln{fagngalocw

    Jlren}cl }rnw so o mc ao}co}lw nf ao}rlmsgarglo}rnwcn

    Rlbsw}cx mc glo}rnwcn

    [rlirnen no}azarsw

    Ng}snfaxngalocw mcf wlj}ynrc ns}le}agnw

    Bfsc}ll}` lgsf}l q glo glo}rnwcn

    Gl{an mc wcisramnm mc mn}lw wcowabfcw

    Glo}rnwcn mc mcwbfl~scl

    Nggcwl ecmano}c gmail [AO (glo}rnwcn!

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    31/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 7> mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Irjagl 98 [crgc{gao mcf oazcf mc wcisramnm mc flw maw{lwa}azlw ezafcw

    jrco}c c~sa{lw jahlw q {lr}}afcw (#!

    Bnwc8 Ce{rcwnw ~sc maw{loco mc lrmconmlrcw mc wlbrcecwn l {lr}}afcw (o5790! Jsco}c8 AO]CGL

    Fn aoglr{lrngao mc flw maw{lwa}azlw ezafcw co fnw ce{rcwnw cw rcfn}azneco}c rcgaco}c& fl ~sc

    {scmc cp{fagnr ~sc cf oazcf mc glogacogangao wlbrc fn ocgcwamnm mc maw{locr mc `crrneaco}nw mc

    {rl}cggao wcn ecolr/

    Wao cebnril& fnw jsogalonfamnmcw ~sc n{lr}no wlo gnmn zcx ew aomaw{cownbfcw q flw n}ngno}cw&

    glowgaco}cw mc cwn ocgcwamnm& {crjcggalono glow}no}ceco}c wsw n}n~scw maraiamlw n flw

    maw{lwa}azlw ezafcw/ Cf ae{ng}l ~sc {nrn fn ce{rcwn {scmc lgnwalonr fn {rmamn l mc}cralrl mc fn

    aojlrengao nfengconmn co flw }creaonfcw icocrn fn ocgcwamnm mc ae{fceco}nr q eno}cocr

    ng}snfaxnmlw fnw `crrneaco}nw mc wcisramnm co cw}lw maw{lwa}azlw/ Hso}l glo cw}n aoglr{lrngao&

    mcbco ffcznrwc n gnbl ecmamnw mc wcowabafaxngao q glogacogangao ~sc ngle{nco n fnw

    no}cralrcw/

    Glel `celw zaw}l& fnw ce{rcwnw gnmn zcx ew rc~sacrco mc }cgolflinw q c~sa{lw ~sc n{lr}coso gle{loco}c mc elzafamnm q nggcwabafamnm n ws ng}azamnm mc ocilgal/ Nmcew mc flw maw{lwa}azlw

    ezafcw& fnw glesoagngalocw n }rnzw mc rcmcw aonfebragnw>0 glo}rabsqco n cw}c {rl{wa}l& {lr fl

    ~sc gnmn zcx cw}o ew cp}comamnw co}rc fnw {c~scnw q ecmanonw ce{rcwnw/

    Nw& mlw mc gnmn }rcw ocilgalw enoajacw}no maw{locr mc son glocpao yaja (so >7# nbacr}n q so

    37&2# mc nggcwl rcw}raoiaml!& glel wc n{rcgan co cf Irjagl 0/ Fn {coc}rngao cw ws{cralr co fnw

    >0 Fnw glocpalocw aonfebragnw! {rl{lrgalono cf nggcwl n Ao}croc} wao ocgcwamnm mc gnbfcw l {so}lw mc nggcwl gcrgnolw/

    Fn olecogfn}srn ACCC 0;2/>>& glolgamn {l{sfnreco}c glel yaja& cw so glohso}l mc cw}omnrcw mc {rl}lglflw {nrn

    glesoagngalocw aonfebragnw/ Mnml ~sc maw{lwa}azlw glel lrmconmlrcw {lr}}afcw& }nbfc}nw l ezafcw maw{loco mcgn{ngamnm {nrn glocg}nrwc n Ao}croc} n }rnzw mc yaja& fn glocpao {scmc wcr sbagsn c aow}no}ocn co gsnf~sacr fsinr/

    =&:#

    =1&1#

    79&1#

    9&:#

    >&:#

    31&=#

    77&:#

    3&=#

    ;#

    >;#

    2;#

    7;#

    =;#

    3;#

    :;#

    9;#

    0;#

    1;#

    >;;#

    Ew wcisrl Aisnf mc wcisrl Ecolw wcisrl Ol wnbc , Ol glo}cw}n

    Lrmconmlr mc wlbrcecwn Lrmconmlr {lr}}af

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    32/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 72 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    ce{rcwnw mc enqlr }nenl& fl ~sc {scmc wcr mcbaml n fn {crgc{gao mc ~sc fnw glesoagngalocw

    aonfebragnw wlo ew majgafcw mc icw}alonr q {rl}cicr& l{aoao rcgliamn co fnw co}rczaw}nw co

    {rljsomamnm n flw rcw{lownbfcw mc wcisramnm mc fnw gle{nnw {nr}aga{no}cw/

    Irjagl 08 Wcrzagalw mc rcm aonfebragn l yaja mcgfnrnmlw {lr fnw ce{rcwnw (#!

    Bnwc8 ]l}nf ce{rcwnw ~sc rcw{lomco nf gscw}alonral mc wcisramnm (o5>/>==! Jsco}c8 AO]CGL

    Fnw jsogalonfamnmcw ~sc n{lr}no fnw rcmcw yaja {lwabafa}no }nebao ~sc wsrhno n}n~scw c aogamco}cw

    mc wcisramnm/ Mc gnrn n mc}creaonr fn {rl}cggao ~sc fnw ce{rcwnw n{fagno n wsw rcmcw

    aonfebragnw& wc nonfaxn cf irnml mc {coc}rngao mc waw}cenw mc gajrnml {nrn yaja8 YC[& Y[N q

    Y[N2/ Cw}c gajrnml mcbc wcr rlbsw}l q cw}nr nznfnml {lr son glo}rnwcn jscr}c/

    Cf cw}omnr Y[N cw wfaml q flw {rlzccmlrcw fl aogfsqco gnmn zcx ew glel e}lml mc gajrnml

    {lr mcjcg}l co flw rls}crw/ Fn wcisomn zcrwao mc cw}c cw}omnr& Y[N2& n{lr}n enqlr rlbsw}cx&

    {lr fl ~sc cw ew rcglecomnbfc/ Cf cw}omnr YC[ (cw}}agl! cw so e}lml mc gajrnml no}cralr nf

    Y[N (maoeagl! q wc glowamcrn lbwlfc}l/

    Mc fnw ce{rcwnw ~sc maw{loco mc rcmcw yaja nbacr}nw& flw {rl}lglflw Y[N,Y[N2 q YC[ }acoco fn

    eawen {coc}rngao (so 29&=#! q so 2>&># mcwglolgco gsf cw cf waw}cen s}afaxnml& {crl njareno

    ~sc ws rcm cw} {rl}ciamn/ [lr f}ael& so >>&9# mcwglolgco wa cpaw}c nfison ecmamn mc wcisramnm

    co ws rcm q cf >2&=# njaren ~sc ol cpaw}c cw}n inrno}n/

    >7&;#

    37&2#7;&7#

    7&3#

    ::&2#

    W& nbacr}n W& mc nggcwl rcw}raoiaml Ol Ol wnbc , Ol glo}cw}n

  • 7/31/2019 Estudio sobre seguridad de la informacin y continuidad de negocio en las empresas espaolas

    33/126

    Cw}smal wlbrc wcisramnm mc fn aojlrengao q glo}aosamnm mc ocilgal co fnw ce{rcwnw cw{nlfnw [iaon 77 mc >2:Aow}a}s}l Ongalonf mc ]cgolflinw mc fn Glesoagngao

    Irjagl 1 8 Ecmamnw mc wcisramnm co rcmcw yaja mc fn ce{rcwn (#!

    Bnwc8 Ce{rcwnw ~sc maw{loco mc rcm Yaja (o5>21! Jsco}c8 AO]CGL

    Fn cfcggao mc fn {rl}cggao mc fn rcm yaja co aisnf {rl{lrgao co neblw waw}cenw (Y[N q YC[!

    rczcfn ~sc fnw ce{rcwnw ol glolgco wsjagaco}ceco}c flw cw}omnrcw mc gajrnml q fn {rl}cggao ~sc

    ljrcgc gnmn sol/ [nr}c mcf mcwglolgaeaco}l mc fnw ce{rcwnw }no}l mc fn {rl}cggao mc fn rcm yaja&

    glel mc flw {rl}lglflw cpaw}co}cw {scmc mcbcrwc& co l{aoao mc flw cp{cr}lw& n ~sc fn wcisramnmwc cogleacomn nf {rlzccmlr mc flw wcrzagalw mc Ao}croc}/

    7/7 [CRWLONF MCMAGNML N FN WCISRAMNM MC FN AOJLRENGAO

    Fn nmcgsnmn icw}ao mc fn aojlrengao co fn lrinoaxngao mc{comc co enqlr l co ecolr ecmamn

    mc }lmlw wsw eacebrlw q mcf swl mc flw rcgsrwlw maw{loabfcw/ [lr cffl& nmcew mc nonfaxnr fnw

    `crrneaco}nw mc wcisramnm ~sc s}afaxno fnw ce{rcwnw& l}rl mc flw chcw {raoga{nfcw wlbrc flw ~sc wc

    gco}rn cf {rcwco}c n{nr}nml cw cf {crwlonf mcmagnml n fn wcisramnm mc fn aojlrengao/

    Glel aomagn cf waisaco}c irjagl& cf irnml mc maw{loabafamnm mc {rljcwalonfcw cognrinmlw mc fn

    wcisramnm mc fn aojlrengao co fnw ce{rcw