Information Security Committee

Image

Information Security Committee of the University of La Serena

The Information Security Committee of the University of La Serena is a transversal body, whose creation responds to the need and commitment to manage the information security of the Institution as a process of continuous improvement, which must be fulfilled within the framework of current legal and regulatory standards, based on the Chilean standard NCh ISO 27.001, the cybersecurity guidelines issued by the State of Chile and, if required, the inclusion of best practices or national and international regulations, in order to complement specific areas necessary to comply with the demands of the institutional functions. All of the above, through the execution of the activities and tasks that are necessary to establish the security levels that the Institution itself determines, in order to identify, evaluate and control the risks that could affect the confidentiality, integrity and availability of data. all its relevant information assets, as a key principle in the management of its processes.

COMMITTEE MEMBERS

photo of the vice-rector for economic and administrative affairs

Vice Chancellor for Economic and Administrative Affairs
Dr. Hector Cuevas Larenas

photo of the Coordinator of the Directorate of Strategic Development and Quality

Director of the Strategic Development and Quality Department
Ms. Viviana Vasquez

photo of the Internal Comptroller Mg. Enrique Acevedo González

Internal Controller
mg. Enrique Acevedo Gonzalez

photo of the Coordinator of the Directorate of Strategic Development and Quality

HR director
Miguel Sanchez Sanchez

photo of the Internal Comptroller Mg. Enrique Acevedo González

Director of the Center for Informatics and Computing
mg. Luis Andres Moya Baeza

photo of the Coordinator of the Directorate of Strategic Development and Quality

Director of Services
----------

photo of the Internal Comptroller Mg. Enrique Acevedo González

Teaching Director
-------

photo of the Coordinator of the Directorate of Strategic Development and Quality

CFO
mg. Jose Ojeda Cossio

photo of the Internal Comptroller Mg. Enrique Acevedo González

Lawyer Legal Advice
mg. Julio Landaeta Pastene

photo of the Coordinator of the Directorate of Strategic Development and Quality

Network and Datacenter Coordinator CICULS
mg. Carlos Pedreros Lizama

photo of the Internal Comptroller Mg. Enrique Acevedo González

Institutional Security Officer CICULS Operations Coordinator
Mg. Marcelo Zepeda Dubo

Features

Functions of the Information Security Committee

1. Manage the Information Security Policy and supervise that the activities carried out by both the academic and administrative units in these matters are in accordance with said Policy, as it is a matter of Law.

2. Define and submit for the corresponding approval, the implementation of standards linked to the information security policy.

3. Identify, evaluate and follow up on corrective actions to solve audit observations together with reporting non-compliance to the Direct Supervisors and the Internal Comptroller.

4. Approve the methodologies and processes related to risk assessment and information security.

5. Identify significant changes that could generate risks in the processing of information.

6. Propose solutions and evaluate the suitability and coordination in the implementation of information security controls.

7. Establish means for staff awareness and training on information security issues.

8. Evaluate the information received from information security incidents, issuing recommendations for their prevention, detection and correction.

9. Recommend to the Center for Information Technology and Computing and the Office of the Vice-Rector for Economic and Administrative Affairs, regarding opportunities for improvement in the Information Security Management System (ISMS), as well as relevant incidents and their solution.

decrees

Download decree 488 2019
Download decree 184 2020
download decree 213 2020

FAQs

What is an information asset?

R: Are all those relevant elements in the production, issuance, storage, communication, visualization and recovery of information of value for the institution, in which three levels are distinguished: (a) The information itself, in its multiple formats (paper, digital, text, image, audio, video, among others) (b) The equipment/systems/infrastructure that support this information (c) The people who use the information, and who have knowledge of the institutional processes