
Closed
Posted
Paid on delivery
Necesito elaborar, como parte de mi Trabajo Fin de Máster, una metodología completa que demuestre cómo aplicar ISO 27001 dentro de una entidad bancaria, poniendo el énfasis en la fase de evaluación de riesgos. Quiero que la propuesta aterrice los pasos prácticos para identificar y valorar amenazas internas, amenazas externas y fallas de procesos, de modo que un equipo de seguridad pueda adoptarla sin grandes ajustes. Además de los requisitos propios de ISO 27001, la metodología debe enlazar de forma natural con el marco NIST CSF para mostrar equivalencias y sinergias. No es necesario incorporar otros estándares. Es importante que las referencias bibliograficas sean válidas. Entregable esperado – Documento estructurado (Word o equivalente) que incluya: Introducción 1.1. Motivación (YA ESTÁ HECHO) 1.2. Planteamiento del problema (YA ESTÁ HECHO) 1.3. Estructura del trabajo (YA ESTÁ HECHO) 2. Estado del arte 3. Objetivos concretos y metodología de trabajo 3.1. Objetivo general 3.2. Objetivos específicos 3.3. Metodología del trabajo 4. Desarrollo específico de la contribución 4.1. Tipo 3. Desarrollo de metodología 4.1.1. Identificación de requisitos 4.1.2. Descripción de la metodología 4.1.3. Evaluación 5. Conclusiones y trabajo futuro Referencias bibliográficas Criterios de aceptación 1. Coherencia con todos los requisitos citados en ISO 27001:2022 y con las funciones, categorías y subcategorías del NIST CSF. 2. Ejemplos y casos claramente orientados al entorno bancario (sucursales, canales digitales, servicios de cajeros, proveedores críticos, etc.). 3. Claridad del lenguaje y referencias bibliográficas académicas recientes. Aporto cualquier política o diagrama interno que sea necesario una vez acordado el trabajo. Espero tu propuesta de índice y cronograma para comenzar cuanto antes.
Project ID: 40455647
9 proposals
Remote project
Active 12 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
9 freelancers are bidding on average €99 EUR for this job

Hola buen dia, La propuesta me parece muy interesante y alineada con mi experiencia en gestión de riesgos, gobierno TI y proyectos de transformación en entornos corporativos complejos. Puedo apoyar en el desarrollo de una metodología práctica y académicamente sustentada para implementar ISO 27001:2022 en una entidad bancaria, con foco en evaluación de riesgos y alineación con NIST CSF. El enfoque sería construir un documento claro y aplicable, incluyendo: • Identificación y valoración de amenazas internas, externas y fallas de proceso • Matrices y criterios de evaluación de riesgos • Casos orientados a banca (sucursales, banca digital, ATM, terceros críticos, etc.) • Relación entre controles ISO 27001:2022 y funciones/categorías NIST CSF • Referencias bibliográficas válidas y recientes Como siguiente paso, puedo compartir: • Propuesta de índice detallado • Cronograma de trabajo • Metodología base para validación antes del desarrollo completo Quedo atenta para comenzar. Saludos!
€52 EUR in 3 days
2.4
2.4

Hola, puedo desarrollar una metodología completa basada en ISO 27001:2022 para el sector bancario, enfocada en evaluación de riesgos e integración con NIST CSF. Tengo experiencia en compliance, gestión de riesgos y documentación técnica. ¿Tiene una extensión objetivo o formato académico específico requerido por la universidad?
€54 EUR in 7 days
0.0
0.0

Hello, I have reviewed your project description and understand that you require the development of a comprehensive methodology for implementing ISO 27001 within a banking entity, with a focus on the risk assessment phase. I will ensure that the practical steps for identifying and assessing internal threats, external threats, and process failures are clearly outlined to facilitate easy adoption by a security team. In addition to complying with ISO 27001 requirements, the methodology will be seamlessly linked with the NIST CSF framework to demonstrate equivalences and synergies, without the inclusion of other standards. Valid academic references will be incorporated as per your requirement. Expected Deliverable: - Structured document (Word or equivalent) including: - Introduction - State of the Art - Specific Objectives and Work Methodology - Specific Development of Contribution - Conclusions and Future Work - Bibliographic References Acceptance Criteria: 1. Alignment with ISO 27001:2022 requirements and NIST CSF functions, categories, and subcategories. 2. Examples and cases tailored to the banking environment (branches, digital channels, ATM services, critical vendors, etc.). 3. Clarity of language and recent academic bibliographic references. I will share my portfolio with you in the DM. Kindly ping me there. My experience with cybersecurity and risk assessment ensures quality, consistency, and a smooth delivery. I'd be happy to discuss your project further and answer any questions. Best regards,
€55 EUR in 3 days
0.0
0.0

Hi there, I’ve reviewed your project and understand you need a **risk assessment methodology based on ISO 27001 for the banking sector**, including structured processes for identifying, analyzing, and treating information security risks. I have strong experience working with **ISO 27001 frameworks, IT risk management, and compliance documentation**, including designing risk assessment methodologies, ISMS documentation, and control mapping for regulated environments. My approach focuses on: * Building a clear ISO 27001-aligned risk assessment methodology * Defining asset, threat, and vulnerability identification process * Creating risk scoring model (likelihood × impact) and risk matrix * Structuring a risk register for tracking and reporting * Mapping risks to ISO 27001 Annex A controls for mitigation * Ensuring compliance with banking sector security and audit requirements The methodology will follow ISO 27001 best practices, where risk is systematically evaluated and treated to ensure appropriate security controls are implemented and continuously improved. I focus on delivering a **practical, audit-ready, and easy-to-implement framework** that can be directly used within your organization’s ISMS. I can start immediately and deliver a structured, well-documented methodology ready for implementation. Looking forward to working with you.
€54 EUR in 7 days
0.0
0.0

Combining my extensive background in Cyber Security and Risk Management, I am confident that I can deliver exactly what you need for your project. As a certified professional with years of experience, particularly in Data Protection and ISO standards, I have developed a comprehensive understanding of the ISO 27001 standard you require. My acumen will come in handy while creating a well-structured document which takes into account both primary standards and NIST CSF integration. The objective of providing practical steps for identifying and assessing internal and external threats aligns perfectly with my approach to risk assessment. I specialize in creating frameworks that are tailored to specific industries such as banking, thereby ensuring that the provided methodology will include relevant examples, such as on banking channels or critical service providers. Aside from my skillset, I place great importance on clear communication and rigorous citations. So you can be assured that not only will the produced document meet all your specifications but major emphasis will also be placed on the productivity, efficiency, and compliance aspects of your project. Contact me to discuss any other detail you might have or get a breakdown of the project timeline and we can get started!
€100 EUR in 1 day
0.0
0.0

Hello. I am pleased to submit my proposal to develop a detailed, practical methodology for implementing ISO 27001 within a banking environment, with a particular emphasis on the risk assessment phase. This methodology will provide clear, actionable steps for identifying and evaluating internal threats, external threats, and process failures, ensuring that security teams can adopt it seamlessly with minimal adjustments. Key aspects of the proposed methodology include: - Practical procedures tailored to the banking context, covering branches, digital channels, ATMs, and critical suppliers. - Alignment with ISO 27001:2022 requirements, ensuring compliance and effectiveness. Natural integration with the NIST Cybersecurity Framework (CSF), illustrating equivalences and synergies across controls and functions. - Use of recent, validated academic references to support the approach. - Clear, concise language suitable for technical teams in banking institutions. The deliverable will be a structured document including an introduction, state of the art, objectives, methodology, detailed development, and conclusions, aligned with the outlined project structure. I am confident my expertise in information security standards, risk management, and the banking sector will meet your expectations and provide a valuable tool for your organization. I look forward to your response and the opportunity to collaborate on this project.
€50 EUR in 5 days
0.0
0.0

Hola. Puedo construir el documento como o necesitas. Llevo varios años trabajando en la implementación de la norma ISO/IEC 27001. Supongo que el costo promedio de las propuestas que has recibido es por que lo podrías hacer con IA si así lo quisieras, pero la IA comete muchos errores.
€280 EUR in 5 days
0.0
0.0

Toledo, Spain
Payment method verified
Member since Feb 28, 2023
€8-40 EUR
€30-250 EUR
$30-250 USD
€30-250 EUR
€8-30 EUR
₹400-750 INR / hour
₹1500-12500 INR
$30-250 USD
₹600-1500 INR
$30-250 USD
$2500-6500 USD
$10-50 USD
$250-750 AUD
$10000-20000 USD
₹37500-75000 INR
$15-25 USD / hour
€30-250 EUR
$750-1500 USD
$90-115 USD / hour
$250-750 CAD
₹400-750 INR / hour
£10-15 GBP / hour
₹12500-37500 INR
€8-30 EUR
€250-750 EUR