Abstract:
The current digital ecosystem requires the adoption of robust security policies, aligned with the highest standards and regulations in the field. The efficiency and consistency of preventive measures are essential to ensure the integrity, confidentiality and availability of sensitive information. Cyber security must be integrated into the overall strategy of organizations, especially within institutions with complex and interconnected information systems. This article proposes a systemic framework for security auditing and compliance verification in institutional information systems, based on the premise that security is a continuous process and not a finished product.