DATA PROTECTION AND REGULATIONS FOR IT AUDITS

Authors

Keywords:

data protection, IT auditing, information security, ISO 27001, regulations

Abstract

DOI: https://doi.org/10.46296/ig.v9i17.0338

Abstract

The protection of personal data and IT auditing are the foundations upon which information security management is currently built. This paper studies both the regulatory and technical context in which data protection develops and its relationship with IT auditing, as it examines the topic based on international standards and Ecuadorian regulations. Through a theoretical review, the main tools are analyzed, such as the Organic Law on the Protection of Personal Data, the ISO/IEC 27001 standard, and the General Data Protection Regulation (GDPR). The results show that IT auditing allows for the evaluation of compliance, the detection of risks, and the strengthening of information systems security controls. IT auditing also incorporates international standards alongside local regulations, improving data management and information protection. However, this also presents challenges related to implementation, training, and organizational adaptation. Like a robust regulatory framework, IT auditing is ultimately essential for ensuring information security and legal compliance in digital environments.

Keywords: data protection, IT auditing, information security, ISO 27001, regulations.

Downloads

Download data is not yet available.

References

Asamblea Nacional del Ecuador. (2021). Ley Orgánica de Protección de Datos Personales.

Chagmana Pomaquero, R. L. (2022). Auditoría informática aplicando la norma ISO 27001 para optimizar la seguridad de la información. Universidad Técnica de Ambato.

Flores, D. A., & Perugachi, R. (2023). A GDPR-compliant risk management approach based on threat modelling and ISO 27005.

Hjerppe, K., Ruohonen, J., & Leppänen, V. (2019). The General Data Protection Regulation: Requirements, architectures, and constraints.

Mullo-Pilamunga, X., & Camero-Berrones, R. (2025). Políticas de seguridad de la información según la norma ISO 27001 en Ecuador.

Organización Internacional de Normalización (ISO). (2022). ISO/IEC 27001:2022 Information security management systems — Requirements.

Organización Internacional de Normalización (ISO). (2023). ISO/IEC 27701: Privacy Information Management.

Pandit, H. J., Lindquist, J., & Krog, G. P. (2024). Implementing ISO privacy standards and GDPR compliance frameworks.

Ramírez Coello, N. B. (2023). Auditoría informática en la seguridad de la información según la ISO 27001 en empresas comerciales. Universidad Laica Eloy Alfaro de Manabí.

Superintendencia de Protección de Datos Personales. (2025). Guía de gestión de riesgos y evaluación de impacto del tratamiento de datos personales.

Published

2026-04-17

How to Cite

Almeida-Zambrano, E. E., Vélez-Manzaba, D. G., Zambrano-Pilay, E. C., & Asencio-Domínguez, Álvaro J. (2026). DATA PROTECTION AND REGULATIONS FOR IT AUDITS. Scientific Journal INGENIAR: Engineering, Technology and Research, 9(17), 377-383. Retrieved from https://journalingeniar.org/index.php/ingeniar/article/view/449