Centralized control of vote counting and result declaration is vulnerable to attacks that compromise election integrity, fairness, and transparency. We present a Web3-based system to decentralize the processing of tally sheets generated at polling stations. Our analysis focuses on the electoral systems of Venezuela and Ecuador, both of which rely on a centralized tally sheet processing procedure. We evaluate the vulnerabilities of this approach and propose a solution based on permissioned blockchains and decentralized storage, using Ecuador’s system as a case study. Our solution ensures integrity, fairness, and transparency throughout the digitalization, transmission, processing, and publication of tally sheets and election results. We developed a basic prototype using Hyperledger Fabric and IPFS.
Information security is strategic and is one of the most important assets within an entity or organization; is one of the reasons to analyze and treat the different risks of confidentiality, integrity, availability (CIA) in information management, and that identity, authenticity, authorization and auditing (IAAA) are available both internally and externally, for this reason. Therefore, preventive measures must be taken. The objective of this investigation is to analyze the security standards to mitigate the risks, vulnerabilities and threats. The deductive method and exploratory research were used to analyze the information from the referenced articles. The result was the percentage of compliance with the potential risk indicators, a table of security metrics for compliance and the prototype for risk mitigation of a technological platform. It was concluded that information security management should be standardized considering the standards, good practices and security policies available at the government, strategic, tactical and operational level.
In recent years, higher education institutions have increasingly relied on digital technology for administrative tasks such as student registration, course management, and financial transactions. However, this dependency also increases the risk of cyberattacks and data breaches, which can have serious consequences for both the organization and its stakeholders. Therefore, it is necessary to implement effective security measures to protect the sensitive data stored and processed. The objective is to carry out an analysis on the development of a security model based on artificial intelligence for administrative management in a higher education institution. The deductive method and exploratory research are used to carry out the analysis on the development of a security model based on artificial intelligence for administrative management in a higher education institution. It resulted in indicators established and analyzed by other authors, the main actors and a conceptual model in the use of security based on artificial intelligence. It was concluded that the application of artificial intelligence in the administrative management of a higher education institution, with the aim of improving the security of information and data. However, it should be noted that any security model must adapt and adapt to the specific needs of each organization, and the implementation of artificial intelligence in the security sector also presents challenges. Awareness and risks must be carefully considered.
The problems to promote scientific research on a large scale in Higher Education Institutions in Latin America are frequent, there are great differences with researchers from America, Asia, Europe where researchers have a large number of publications indexed in Scopu, Scimago, and WOS; while in Latin America most researchers have fewer than 50 publications. The objective is to generate a prototype to improve scientific production in Higher Education Institutions. The deductive method was used with exploratory research for the analysis of regulations, provisions, websites and scientific articles related to the research topic. A prototype for the continuous improvement of scientific production resulted, which can be applied in any Higher Education Institution to improve its scientific production. It was concluded that the Pearson correlation obtained is moderate, with respect to the 7 indicators referring to the problems and possible solutions; Cronbach's Alpha is greater than 0.856909289 obtained from 24 indicators that are directly related to improving scientific production that guarantees trust, quality and consistency in research for the generation of the prototype to improve scientific production in Higher Education Institutions.
Public organizations are subjected to a complex security situation, which can be addressed by permanently strengthening and evaluating their cybersecurity capabilities.The objective of this research is to develop a model to identify the cybersecurity management capacity of public organizations.The deductive method was applied for the review and analysis of criteria, factors and variables related to cybersecurity capacity in public organizations.It resulted in a model to identify the Cybersecurity Management Capacity of public organizations, with its process to assess and categorize organizations according to their level of cybersecurity capacity.It was concluded that public organizations from developed countries in cybersecurity such as Spain have better capacities (greater than 60% CMC) than less developed countries such as Ecuador (less than 60% CMC), due to the cybersecurity context where these organizations operate.To obtain a high level of cybersecurity, public organizations must have the support of the governments of the different political divisions of a country, as well as permanent international collaboration in the field of cybersecurity.
The constant evolution of Information and Communication Technologies, Internet, access to different free software, among others; they generate problems in the management of information security in companies; to mitigate risks, vulnerabilities, and information threats, an alternative was presented considering that information security systems are the basis for decision-making at the government, strategic, tactical, and operational levels.The objective is to design a security prototype applied to business management to mitigate risks, vulnerabilities and threats to information.The deductive method and exploratory research were used for the analysis of the information.Turned out prototypes that allow mitigating risks, vulnerabilities and threats in information management for data control and integrity.It was concluded that the security prototype proposed for a commercial information system; it is security system suitable for public and private companies.In the simulation carried out, it was determined that if the number of risks and threats is high, there will be a greater probability that a problem will arise in the security of the system.
Public organizations lack adequate models and methods to efficiently support and manage processes related to information security and IT investments. The objective is to optimize the management of strategic projects planned to improve the information security of a public organization and make efficient use of its available resources. The deductive method and exploratory research were used to review and analyze the available information. A mathematical model resulted that optimizes two objectives: (1) minimizing the costs of the strategic projects to be executed, and (2) maximizing the percentage of improvement in the organization's information security. According to the result of the simulation, a subset of planned strategic projects was obtained that allows improving the information security of a public organization from 84.64% to 92.20%, considering the budgetary limitations of the organization. It was concluded that the proposed model is efficient, practical and can be a support tool for the IT management of a public organization.
Information security and cybersecurity governance problems are persistent worldwide in all public and private organizations. The objective of this research is to define appropriate indicators for professional identity to improve the governance of information security as an alternative to solving problems. The deductive method and exploratory research were used to analyze the reference articles. Turned out a table of indicators to define the appropriate professional identity to improve the governance of information security, which is an alternative to solve the problems of governance of information security and cybersecurity. It was concluded that it is necessary for public and private companies to redefine the profile of the professional for the management of ICT and governance of information security, considering their undergraduate, postgraduate academic training in the same area of knowledge of Information Technologies, in accordance with international standards and provisions of national and international control bodies, professional experience, courses related to IT management, projects, courses prior to certification, among others.
Public organizations have the responsibility by law to manage sensitive data that must be shared; the problem was found that organizations are very vulnerable and that computer attacks are becoming more and more effective and dangerous. As an objective of this research, the Information Security of public organizations in Ecuador was analyzed, the current status was known and improvements in its management were proposed. The deductive method was applied for the review and analysis of factors and variables that allow improving information security management in public organizations. The result was an Information security management model based on strategic planning, process and matrices for the evaluation of the information security management capacity. It was concluded that public organizations in Ecuador have a low level of information security management capacity, 70% are at a "Formative" level and 22% at a "Managed" level. To Manage Information Security in an optimal way, it is necessary to start from a strategic planning that allows directing the resources and capacities available to the achievement of the objectives established for the organization.
Las organizaciones públicas tienen la tarea permanente de administrar adecuadamente la seguridad de la información que manejan. El objetivo de esta investigación es analizar los estándares de seguridad adoptados por las organizaciones públicas en Ecuador para mejorar su gestión de la seguridad de la información. Se aplicó el método deductivo para la revisión y análisis de estándares adecuados para las instituciones públicas. Como resultado, se obtuvo información sobre las diferentes políticas, estándares y lineamientos de seguridad que aplican, organismos públicos nacionales e internacionales. Resultó un Diagrama de actividades para la adopción de estándares para organismos públicos; un prototipo de modelo de gestión de la seguridad de la información basado en estándares; y una Matriz de Gestión de Seguridad de la Información, a partir de la cual se calculó el Porcentaje de Mitigación de Riesgos. Se concluyó que mantener altos niveles de seguridad en las organizaciones públicas requiere la adopción de estándares de control en diferentes áreas y la colaboración de los diferentes niveles organizativos y jerárquicos de las organizaciones públicas.
Different models and standards of information security were analyzed, to adopt a model that mitigates vulnerabilities, risks and threats in the quota allocation process for the State University in Ecuador.The main objective is defining a prototype for the management of processes and information security in this type of organization.It was used the deductive and exploratory research method to analyze the information in the references.In this work, the characteristics of the attacks were analyzed.It turned out a model performs the detection and defense of attacks based on the differences in data and time between them and the browsing behavior of normal users.It was concluded that the prototypes presented as results are an alternative to improve the security of the processes and the flow of information and that these can be used as a reference in this type of organization.
The globalization of information has been present in several contexts and required in digital lathes with cutting-edge technology, both for private and public institutions. In Ecuador the need has been observed to invest in new technologies, in public institutions, be it education, in the electoral field or companies of other services. The objective was to analyze the benefits of Hyperledger technology in public institutions in Ecuador. The deductive method was used and a quantitative criterion was maintained, through the study of research papers that allowed a description of the use of said technology and its applicability in said organizations. The problem was oriented to the need to apply a technology that provides better processes and with greater security. It turned out that Hyperledger technology allowed us to work faster, reduce costs, environmentally friendly and provide greater security. It was concluded that the application of Blockchain Hyperledger technology provides a framework for public administrations, because it has improved the different transactions made, helped reduce fraud by applying encryption, minimized the possibility of error, and improved communication between government and citizen services.
It was analyzed the information of databases, encryption algorithms, and information security that are the main components of a Smart City. The problem is the lack of security of public or secret data that is stored in a repository, where there is access to the citizen, local government, and central government. The objective is to define a security prototype and adopt a cryptographic algorithm to mitigate the risks of the database in the management of a Smart City. It was used the deductive method and exploratory research to analyze the information of the reference articles. It turned out a general prototype of security; an algorithm to implement a database for Smart City; an algorithm of data protection expressed in flowcharts. It was concluded that information protected with an encryption algorithm, is a support to be more efficient, reduce costs, reduce the environmental footprint and improve the management of a Smart City.
The need to analyze the risks of cyberbullying that children and adolescents face through the use of social networks was determined. Given this, the problem focuses on the need to provide an ICT management model to mitigate the conflict situations to which users are exposed. It was used deductive and exploratory research w as a methodology to analyze information regarding the rates of users of social networks in Ecuador; in addition to establishing their ages. Turned out a conceptual model related to the development of digital skills, qualitative description in the handling of digital content by children and adolescents; as well as the qualitative description of digital content. It was concluded what is necessary to provide optimal environments for the development of digital skills or competences in children and adolescents in order to mitigate the risks of cyberbullying. In this way, it contributes to the efficient treatment of personal information indigital media.
Cyberbullying is a critical issue in society worldwide, however in Ecuador is not given necessary importance to mitigate this cybercrime. It has been proposed to develop an exhaustive analysis of the laws that are currently considered to sanction cyberbullying when denouncing this fact. The deductive method and exploratory research were employed to make the analysis of the information consulted from the various sources that are obtained on the network about the topic discussed. The investigation revealed how cyberbullying cases arise, from which it is obtained that only 0.07% have been reported, with this result it can be deduced that the number of reported cases is very low in relation to the total number of cellphones activated in Ecuador and people who may be victims of this cyber-crime. In addition, a "Criminal Process Diagram" was obtained that determines the sequence of how the judicial process work. The applied method resulted the following: Can be created a law project that battles each type of derived cyberbullying. It was concluded that several institutions in Ecuador work together with organizations to prevent cyberbullying, however, when this happens, the laws are not enough to punish the act.
Information on alternative technologies or new prototypes was analyzed to help improve the quality of business management services.The problem is the lack of application of new technologies that improve the quality of service and reduce disagreements in the management of organizations.The objective is to present a prototype for the management of engineering and ICT companies to improve the quality of services.The deductive method and exploratory research were used to analyze the information.The result was a mixed conceptual model of quality of service approach, a dual-security architecture for business management, control of algorithms with processes for quality of service and control of algorithms with information filter.It was concluded that an information filter with Blockchain is considered a fundamental alternative to provide control, reliability, immutability and improved quality of service.
Currently, the use of technological resources, within public and private institutions, has become essential, due to the need to modernize processes, high commercial needs and mandatory continuous improvement. A problem has been observed at the national level, in relation to the ease with which the databases of natural or legal persons are accessed, which has motivated them to provide the respective security measures. For this reason, a study has been carried out on the security measures of the database of the National Customs Service of Ecuador, with a quantitative methodology which allowed to know, objectively, what are the different security measures that must be implemented to improve the operations with the utmost care. In addition, a qualitative analysis of the revised texts was carried out to minimize the threats and vulnerabilities present in security systems. The objective of this study was to establish adequate security algorithms to mitigate risks in a database of the National Customs Service of Ecuador, which has been working, since 2007, on risk management, training personnel, following strategies international and implementing technological aspects to systematize the processes that until then were mainly carried out physically. The need for the institution to take care of its database was evident, applying HASH computer security measures that reduce or eliminate computer thefts, with encrypted algorithms, training of personnel throughout the process and articles of the law that allow the use of adequate mechanisms for the care and protection of information, as appropriate.
The problems of cybersecurity, cyberbullying in social networks worldwide are persistent and increasingly evident and prejudicial to society regardless of age or sex; during the COVID-19 pandemic, the Ecuador study case can show negative and psychological impacts; another of the radical problems is the information security of public organizations for strategic decision making in natural or anthropogenic disasters in Ecuador, has caused serious problems to generate public policies with effectiveness and efficiency in health, education, basic services among others. The objective of the study is to identify cybersecurity problems, cyberbullying in social networks and present alternatives to improve information security in public organizations during a pandemic. It was used deductive method and exploratory research were to analyze the information. Turned out the early evaluation in the identification of cyberattack, cyberbullying and positive, negative and psychological impacts of the use of social networks during the pandemic and a prototype of a National System of Public Data Registration based on Blockchain to improve management of risks against natural or anthropogenic disasters in Ecuador. It was concluded that for making decisions effectively, efficiently at the strategic level during a pandemic such as COVID-19 or any other natural disaster, the most important thing in the first instance is to have information with integrity, to carry out adequate planning according to the reality of each country.
Security problems due to cyberattacks were analyzed, checked security models designed to protect and preserve databases of information from these institutions, using all the parameters of information security. It is planted propose a prototype of a security model to mitigate the risks of cyberattacks on public institutions to define the organizational structure and security levels in order to adopt security protocols. A security model was proposed, and a general network topology that helped meet the objective. The deductive method was used in the investigation to verify the current trends of security models and to protect the information available on the ministerial entity. The prototype of a security model was established to mitigate the risks of cyberattacks. It is concluded that a security strategy are necessary data through a correct, reliable and highly available route that offers a higher level of reliability. The content of this plan was presented and made available to all members of the public institution, especially those who are actively involved in safety procedures of information.
It was analyzed information on references to cyberbullying in social networks, text analysis, harassment detection, factors and behavior. The problem is the lack of auditing models on social networks that generate reliable information to determine cyberbullying. The objective of this research is to develop a prototype to perform audits on social networks to determine cyberbullying. It was used the deductive method and exploratory research to identify proposals that detect cyberbullying on social networks. It resulted in an Architecture prototype to perform audits on social networks to determine cyberbullying and an Algorithm prototype to perform audits on social networks to determine cyberbullying expressed in a flow chart. It was concluded that the algorithm prototype obtains valid information from social networks in a clear and precise way through the classification and weight of the offensive text; the prototype obtained 93.80% of average performance.