The objective of this analysis is to evaluate the internal control system in computer security of the company Pinturas y Acabados Essmarr SAS, a company in the construction sector dedicated to providing supply and application services of paintings and finishing touches to structures and surfaces, generating quality projects that are adapted to the profile and needs of each client. Pinturas y Acabados y Essmarr SAS has a group of collaborators who have consolidated a professional career based on good practices, where connectivity spaces are continuously created that seek to positively impact customers, generating value in each project executed. As a consequence of the operation carried out by the organization on a daily basis, there are risks that must be evaluated to safeguard the integrity of the information and generate internal controls that allow facing future threats; strengthening the internal control structure and generating improvement actions to guarantee an adequate development of the operation and the fulfillment of its objectives with a tolerable level of risk. The study assesses the risks to which the organization may be exposed as a result of dependence on information systems in each process carried out. The systems area as a leading area in processes related to ICT (information technology) shows the procedures carried out by the organization to counter cybercrime and the loss of information. Each procedure, policy and proposed tool, as a result of the analysis carried out, aims to mitigate the exposure to risk in information technologies and avoid economic losses that may cause liquidity problems. Likewise, the COSO system is disclosed to manage the risks that would negatively impact the organization. The system seeks to direct the General Management to the development of an effective tool to generate high-scope returns and promote a culture of control within each area. The results obtained show weaknesses in the computer security controls, generating alerts that are key to be able to create timely policies, procedures and response mechanisms to future contingencies.