Security Metrics Maturity Model for Operational Security

被引:0
|
作者
Muthukrishnan, Murugarasan [1 ]
Palaniappan, Sellapan [1 ]
机构
[1] MUST, Dept Informat Technol, Kuala Lumpur, Malaysia
关键词
Security Metrics; Security Taxonomy; Security Maturity Model;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Information Technology (IT) is continuously evolving at faster rate and enterprises are always trying to keep pace with the changes. So do the threats. As the complexity of IT increase, the unprecedented threat environment and security challenges also have increased multi fold over the years. Security Managers are continuously having challenging task not only protecting their company but also convincing the stakeholders on the security investments. The well informed stakeholder demands higher level transparency, Return on Investment (ROI) and security. Security metrics plays a key role in responding to these demands. However the security metrics alone are not enough but must be substantiated. The stakeholders always question and challenge the metrics provided. They are always skeptical on the numbers shown in metrics. As such, more information is needed to substantiate the metrics claims. Therefore, this research will explore the identification of quality security elements to determine the matured security metrics within operational security environment. The research will categorize the metrics maturity into three types: infant, evolving and matured metrics. The classification is performed by analyzing the quality of a metric through a scorecard and by providing a scoring. Towards the end Security Metrics Maturity Index (SM-Mi) is introduced to label a company on how trustable and confidence on can feel when look into the metrics. The entire classification uses operational security taxonomy for better understanding. The end result of this research will be a guide for the Security Managers to produce a convincing and close to accurate report for C Level management of an organization. This research will look into various studies done on existing measurements and security elements for Security Metrics and produce a method that will portray the maturity of security metrics used in an organization
引用
收藏
页码:101 / 106
页数:6
相关论文
共 50 条
  • [1] Operational security metrics for large networks
    Patriciu, Victor-Valeriu
    Priescu, Iustin
    Nicolaescu, Sebastian
    [J]. INTERNATIONAL JOURNAL OF COMPUTERS COMMUNICATIONS & CONTROL, 2006, 1 : 349 - 354
  • [2] Transportation security and the role of resilience: A foundation for operational metrics
    Cox, Andrew
    Prager, Fynnwin
    Rose, Adam
    [J]. TRANSPORT POLICY, 2011, 18 (02) : 307 - 317
  • [3] Metrics, a fundamental element in the construction of informatics security maturity models
    Villegas, Marianella
    Meza, Marina
    Leon, Pilar
    [J]. TELEMATIQUE, 2011, 10 (01): : 1 - 16
  • [4] OPERATIONAL MODEL FOR SECURITY ANALYSIS AND VALUATION
    WARREN, JM
    [J]. JOURNAL OF FINANCIAL AND QUANTITATIVE ANALYSIS, 1974, 9 (03) : 395 - 422
  • [5] Security Metrics Foundations for Computer Security
    Trcek, Denis
    [J]. COMPUTER JOURNAL, 2010, 53 (07): : 1106 - 1112
  • [6] Security Metrics and Security Investment Models
    Boehme, Rainer
    [J]. ADVANCES IN INFORMATION AND COMPUTER SECURITY, 2010, 6434 : 10 - 24
  • [7] Adopting security maturity model to the organizations' capability model
    Al-Matari, Osamah M. M.
    Helal, Iman M. A.
    Mazen, Sherif A.
    Elhennawy, Sherif
    [J]. EGYPTIAN INFORMATICS JOURNAL, 2021, 22 (02) : 193 - 199
  • [8] Maturity Model of Information Security for Software Developers
    Silva, M. P.
    Barros, R. M.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2017, 15 (10) : 1994 - 1999
  • [9] Organisational Information Security Management Maturity Model
    Zammani, Mazlina
    Razali, Rozilawati
    Singh, Dalbir
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (09) : 668 - 678
  • [10] Towards an Information Security Awareness Maturity Model
    Fertig, Tobias
    Schuetz, Andreas E.
    Weber, Kristin
    Mueller, Nicholas H.
    [J]. LEARNING AND COLLABORATION TECHNOLOGIES. HUMAN AND TECHNOLOGY ECOSYSTEMS, LCT 2020, PT II, 2020, 12206 : 587 - 599