Copyright (c) 2022 Memorias

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
Design of Key Policies for the Operation of the Computer Incident Response Center of Universidad Nacional Abierta y a Distancia (CSIRT-UNAD)
This document presents a proposal aimed at designing key policies for the operations of the Computer Security Incident Response Team (CSIRT) at Universidad Nacional Abierta y a Distancia (UNAD), as part of institutional strategies aimed at strengthening cybersecurity and information protection in digital academic environments. The research arises in a context marked by an increase in cyber incidents at educational institutions and by the need to establish clear guidelines for the ethical, technical, and regulatory management of events related to information security.
The study begins by addressing concepts related to organizational policies, incident management, cybersecurity, and the operations of CSIRT teams, in addition to reviewing recent experiences of cyber incidents at universities and regional statistics on cyberattacks in Latin America. Building on this, the study conducts a literature review of existing regulations, resolutions, and institutional policies at UNAD related to information classification, records management, IT security, digital governance, and data protection.
Based on these guidelines and international best practices, policies are proposed to regulate essential aspects of the CSIRT-UNAD's operations, including information classification and access, data protection and retention, information destruction and disclosure, incident management, inter-institutional cooperation, appropriate use of systems, and ethical compliance and confidentiality. The proposed policies seek to strengthen the capacity to respond to security incidents, ensure legal and contractual compliance, and promote an organizational culture focused on the protection of institutional digital assets.
The proposal highlights the importance of establishing specialized cybersecurity organizational structures within higher education institutions, coordinating technical, regulatory, and ethical processes to address the challenges associated with digital transformation and the rise in cyber threats in academic and administrative settings.