New game
Download
Get Academic Plan
Share game
Integrate it into your platform

You can integrate the game into an LMS compatible with LTI 1.1 or LTI 1.3 such as Canvas, Moodle, or Blackboard. This way, the scores will be automatically saved into the platform’s gradebook.
Download
You have exceeded the maximum number of games you can integrate into Google Classroom with your current Plan.

To integrate as many games as you want in Google Classroom, you need an Academic Plan or a Commercial Plan.

You have exceeded the maximum number of games you can integrate into Microsoft Teams with your current Plan.

To integrate as many games as you want in Microsoft Teams, you need an Academic Plan or a Commercial Plan.

Downloading games is an exclusive feature for users with an Academic Plan or a Commercial Plan.

Get your Academic Plan or your Commercial Plan now and start integrating your games into your LMS, website or blog.

If you wish, you can download a demo game here and test its integration:

Diagnóstico de Seguridad de la Información

Yes or No

Played 1

About this activity

Evaluación de madurez y riesgos

Created by

Mexico

Download the paper version to play

Make your own free game from our game creator
Compete against your friends to see who gets the best score in this game

Top Games

%
Anonymous
Anonymous
%
%
%
You have exceeded the maximum number of games you can print with your current Plan.

To print as many games as you want, you need an Academic Plan or a Commercial Plan.

Print your game
Diagnóstico de Seguridad de la Información
 

Diagnóstico de Seguridad de la InformaciónOnline version

Evaluación de madurez y riesgos

by Daniel Peña
1

Se utilizan marcos internacionales como ISO/IEC 27001, NIST CSF y COBIT.

2

El entregable principal es solo el informe técnico sin evidencias.

3

El alcance de red LAN/WAN no se debe incluir en Fase 1.

4

Un diagnóstico de seguridad solo necesita revisar antivirus.

5

Un diagnóstico de seguridad busca evaluar el nivel de madurez del sistema de seguridad organizacional.

6

No se contemplan métricas como MTTR o MTBF.

7

La Fase 1 consiste en definir el alcance técnico y delimitar infraestructura, aplicaciones y redes.

8

El modelo de riesgo puede ser cuantitativo (probabilidad × impacto) o cualitativo (bajo, medio, alto, crítico).

9

En la Fase 2 se realiza la prueba de penetración interna.

10

Las herramientas profesionales mencionadas incluyen Nmap, Wireshark, Nessus y Metasploit.

Are you sure you want to leave the page?

If you leave the page, you will lose your game progress.