DATA PROTECTION AND REGULATIONS FOR IT AUDITS
Keywords:
data protection, IT auditing, information security, ISO 27001, regulationsAbstract
DOI: https://doi.org/10.46296/ig.v9i17.0338
Abstract
The protection of personal data and IT auditing are the foundations upon which information security management is currently built. This paper studies both the regulatory and technical context in which data protection develops and its relationship with IT auditing, as it examines the topic based on international standards and Ecuadorian regulations. Through a theoretical review, the main tools are analyzed, such as the Organic Law on the Protection of Personal Data, the ISO/IEC 27001 standard, and the General Data Protection Regulation (GDPR). The results show that IT auditing allows for the evaluation of compliance, the detection of risks, and the strengthening of information systems security controls. IT auditing also incorporates international standards alongside local regulations, improving data management and information protection. However, this also presents challenges related to implementation, training, and organizational adaptation. Like a robust regulatory framework, IT auditing is ultimately essential for ensuring information security and legal compliance in digital environments.
Keywords: data protection, IT auditing, information security, ISO 27001, regulations.
Downloads
References
Asamblea Nacional del Ecuador. (2021). Ley Orgánica de Protección de Datos Personales.
Chagmana Pomaquero, R. L. (2022). Auditoría informática aplicando la norma ISO 27001 para optimizar la seguridad de la información. Universidad Técnica de Ambato.
Flores, D. A., & Perugachi, R. (2023). A GDPR-compliant risk management approach based on threat modelling and ISO 27005.
Hjerppe, K., Ruohonen, J., & Leppänen, V. (2019). The General Data Protection Regulation: Requirements, architectures, and constraints.
Mullo-Pilamunga, X., & Camero-Berrones, R. (2025). Políticas de seguridad de la información según la norma ISO 27001 en Ecuador.
Organización Internacional de Normalización (ISO). (2022). ISO/IEC 27001:2022 Information security management systems — Requirements.
Organización Internacional de Normalización (ISO). (2023). ISO/IEC 27701: Privacy Information Management.
Pandit, H. J., Lindquist, J., & Krog, G. P. (2024). Implementing ISO privacy standards and GDPR compliance frameworks.
Ramírez Coello, N. B. (2023). Auditoría informática en la seguridad de la información según la ISO 27001 en empresas comerciales. Universidad Laica Eloy Alfaro de Manabí.
Superintendencia de Protección de Datos Personales. (2025). Guía de gestión de riesgos y evaluación de impacto del tratamiento de datos personales.
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Scientific Journal INGENIAR: Engineering, Technology and Research

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.












