Security Metrics Maturity Model for Operational Security

被引:0
|
作者
Muthukrishnan, Murugarasan [1 ]
Palaniappan, Sellapan [1 ]
机构
[1] MUST, Dept Informat Technol, Kuala Lumpur, Malaysia
关键词
Security Metrics; Security Taxonomy; Security Maturity Model;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Information Technology (IT) is continuously evolving at faster rate and enterprises are always trying to keep pace with the changes. So do the threats. As the complexity of IT increase, the unprecedented threat environment and security challenges also have increased multi fold over the years. Security Managers are continuously having challenging task not only protecting their company but also convincing the stakeholders on the security investments. The well informed stakeholder demands higher level transparency, Return on Investment (ROI) and security. Security metrics plays a key role in responding to these demands. However the security metrics alone are not enough but must be substantiated. The stakeholders always question and challenge the metrics provided. They are always skeptical on the numbers shown in metrics. As such, more information is needed to substantiate the metrics claims. Therefore, this research will explore the identification of quality security elements to determine the matured security metrics within operational security environment. The research will categorize the metrics maturity into three types: infant, evolving and matured metrics. The classification is performed by analyzing the quality of a metric through a scorecard and by providing a scoring. Towards the end Security Metrics Maturity Index (SM-Mi) is introduced to label a company on how trustable and confidence on can feel when look into the metrics. The entire classification uses operational security taxonomy for better understanding. The end result of this research will be a guide for the Security Managers to produce a convincing and close to accurate report for C Level management of an organization. This research will look into various studies done on existing measurements and security elements for Security Metrics and produce a method that will portray the maturity of security metrics used in an organization
引用
收藏
页码:101 / 106
页数:6
相关论文
共 50 条
  • [31] Operational Security - Security-based Corporate Governance
    Szenes, Katalin
    [J]. IEEE 9TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL CYBERNETICS (ICCC 2013), 2013, : 375 - 378
  • [32] Security evolves towards maturity
    Navarro, Moises
    [J]. UNIVERSIA BUSINESS REVIEW, 2006, (10): : 96 - 103
  • [33] A Readiness Model for Measuring the Maturity of Cyber Security Incident Management
    Rieger, David
    Tjoa, Simon
    [J]. ADVANCES IN INTELLIGENT NETWORKING AND COLLABORATIVE SYSTEMS, 2019, 23 : 283 - 293
  • [34] Information Security Maturity Model for Healthcare Organizations in the United States
    Barnes, Bridget
    Daim, Tugrul
    [J]. IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2024, 71 : 928 - 939
  • [35] A Maturity Model for Part of the African Union Convention on Cyber Security
    von Solms, Sh
    [J]. 2015 SCIENCE AND INFORMATION CONFERENCE (SAI), 2015, : 1316 - 1320
  • [36] Lessons learned with the Systems Security Engineering Capability Maturity Model
    Hefner, R
    [J]. PROCEEDINGS OF THE 1997 INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, 1997, : 566 - 567
  • [37] Information Security Multiprofile Maturity Model (ISM3)
    Briceag, Valentin
    [J]. ROMANIAN JOURNAL OF INFORMATION TECHNOLOGY AND AUTOMATIC CONTROL-REVISTA ROMANA DE INFORMATICA SI AUTOMATICA, 2022, 32 (01): : 99 - 112
  • [38] A New Adaptive Cyber-security Capability Maturity Model
    Ghaffari, Fariba
    Arabsorkhi, Abouzar
    [J]. 2018 9TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2018, : 298 - 304
  • [39] SOASMM: a Novel Service Oriented Architecture Security Maturity Model
    Kassou, Meryem
    Kjiri, Laila
    [J]. 2012 INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS), 2012, : 911 - 917
  • [40] Security Awareness for medium-sized businesses How a maturity model can increase security awareness
    Siegwart, Christian
    Scherhag, Felix
    Krannnnel, Michael
    Frey, Georg
    [J]. ATP MAGAZINE, 2021, (6-7): : 82 - 89