Ricardo Gomes

@ipleiria.pt

Informatics Engineering Department
School of Technology and Management - Polytechnic Institute of Leiria



                             

https://researchid.co/ricardo.p.gomes

Ricardo Gomes is a Invited Adjunct Professor at of Computers Engineering Dept., School of Technology and Management, Polytechnic of Leiria. He graduated from Polytechnic of Leiria in Computers Engineering and holds an M.Sc. in Computers Engineering from Polytechnic of Leiria. He has worked in the IT field outside of academia for 20 years. His research interests are cybersecurity, cloud infrastructure, and the development of frameworks and methodologies.

EDUCATION

Specialist Title in Informatics Sciences from the Polytechnic Institute of Leiria
MSc in Computer Engineering from the Polytechnic Institute of Leiria
Bs in Informatics Engineering from the Polytechnic Institute of Leiria

RESEARCH INTERESTS

Cloud Computing, Cybersecurity, Software Development, Data Sciences

5

Scopus Publications

91

Scholar Citations

3

Scholar h-index

3

Scholar i10-index

Scopus Publications

  • INFORMATION SECURITY AND CYBERSECURITY ASSESSMENT IN SME – AN IMPLEMENTATION METHODOLOGY


  • A methodology for mapping cybersecurity standards into governance guidelines for SME in Portugal
    Bruno Azinheira, Mário Antunes, Marisa Maximiano, and Ricardo Gomes

    Elsevier BV

  • A Client-Centered Information Security and Cybersecurity Auditing Framework
    Mário Antunes, Marisa Maximiano, and Ricardo Gomes

    MDPI AG
    Information security and cybersecurity management play a key role in modern enterprises. There is a plethora of standards, frameworks, and tools, ISO 27000 and the NIST Cybersecurity Framework being two relevant families of international Information Security Management Standards (ISMSs). Globally, these standards are implemented by dedicated tools to collect and further analyze the information security auditing that is carried out in an enterprise. The overall goal of the auditing is to evaluate and mitigate the information security risk. The risk assessment is grounded by auditing processes, which examine and assess a list of predefined controls in a wide variety of subjects regarding cybersecurity and information security. For each control, a checklist of actions is applied and a set of corrective measures is proposed, in order to mitigate the flaws and to increase the level of compliance with the standard being used. The auditing process can apply different ISMSs in the same time frame. However, as these processes are time-consuming, involve on-site interventions, and imply specialized consulting teams, the methodology usually adopted by enterprises consists of applying a single ISMS and its existing tools and frameworks. This strategy brings overall less flexibility and diversity to the auditing process and, consequently, to the assessment results of the audited enterprise. In a broad sense, the auditing needs of Small and Medium-sized Enterprises (SMEs) are different from large companies and do not fit with all the existing ISMSs’ frameworks, that is a set of controls of a particular ISMS is not suitable to be applied in an auditing process, in an SME. In this paper, we propose a generic and client-centered web-integrated cybersecurity auditing information system. The proposed system can be widely used in a myriad of auditing processes, as it is flexible and it can load a set of predefined controls’ checklist assessment and their corresponding mitigation tasks’ list. It was designed to meet both SMEs’ and large enterprises’ requirements and stores auditing and intervention-related data in a relational database. The information system was tested within an ISO 27001:2013 information security auditing project, in which fifty SMEs participated. The overall architecture and design are depicted and the global results are detailed in this paper.

  • Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal
    Mário Antunes, Marisa Maximiano, Ricardo Gomes, and Daniel Pinto

    MDPI AG
    Information security plays a key role in enterprises management, as it deals with the confidentiality, privacy, integrity, and availability of one of their most valuable resources: data and information. Small and Medium-sized enterprises (SME) are seen as a blind spot in information security and cybersecurity management, which is mainly due to their size, regional and familiar scope, and financial resources. This paper presents an information security and cybersecurity management project, in which a methodology based on the well-known ISO-27001:2013 standard was designed and implemented in fifty SMEs that were located in the center region of Portugal. The project was conducted by a business association located at the center of Portugal and mainly participated by SMEs. The Polytechnic of Leiria and an IT auditing/consulting team were the other two entities that participated on the project. The characterisation of the participating enterprises, the ISO-27001:2013 based methodology developed and implemented in SMEs, as well as the results obtained in this case study, are depicted and analysed in the paper. The attained results show a clear benefit to the audited and intervened SMEs, being mainly attested by the increasing of their information security management robustness and collaborators’ cyberawareness.


RECENT SCHOLAR PUBLICATIONS

  • INFORMATION SECURITY AND CYBERSECURITY ASSESSMENT IN SME-AN IMPLEMENTATION METHODOLOGY.
    B Azinheira, M Antunes, M Maximiano, RP Gomes
    Journal of Global Business & Technology 19 (1) 2023

  • A methodology for mapping cybersecurity standards into governance guidelines for SME in Portugal
    B Azinheira, M Antunes, M Maximiano, R Gomes
    Procedia Computer Science 219, 121-128 2023

  • A Client-Centered Information Security and Cybersecurity Auditing Framework
    M Antunes, M Maximiano, R Gomes
    Applied Sciences 12 (9), 4102 2022

  • Acknowledgment to Reviewers of Journal of Cybersecurity and Privacy in 2021
    A Tonacci, K Perumalla, A Rahmati, K Shaukat, A Melis, K Demertzis, ...
    2022

  • Information System for Security Auditing
    R Gomes, M Maximiano, M Antunes
    https://encyclopedia.pub/entry/22522 2022

  • A Customizable Web Platform to Manage Standards Compliance of Information Security and Cybersecurity Auditing
    M Antunes, M Maximiano, R Gomes
    Procedia Computer Science 196, 36-43 2022

  • Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal
    M Antunes, M Maximiano, R Gomes, D Pinto
    Journal of Cybersecurity and Privacy 1 (2), 219-238 2021

  • Survey on Mobile Application Development Case Study: WineDroid
    R Gomes, L Marcelino, C Silva
    Conferncia Ibrica de Sistemas e Tecnologias de Informao 2011 2011

MOST CITED SCHOLAR PUBLICATIONS

  • Information Security and Cybersecurity Management: A Case Study with SMEs in Portugal
    M Antunes, M Maximiano, R Gomes, D Pinto
    Journal of Cybersecurity and Privacy 1 (2), 219-238 2021
    Citations: 65

  • A Customizable Web Platform to Manage Standards Compliance of Information Security and Cybersecurity Auditing
    M Antunes, M Maximiano, R Gomes
    Procedia Computer Science 196, 36-43 2022
    Citations: 16

  • A Client-Centered Information Security and Cybersecurity Auditing Framework
    M Antunes, M Maximiano, R Gomes
    Applied Sciences 12 (9), 4102 2022
    Citations: 10