An Organisational Model for Information Security Assessment

被引:0
|
作者
McKissack, Jeremy [1 ]
Hooper, Val [1 ]
Hope, Beverley [1 ]
机构
[1] Victoria Univ Wellington, Wellington, New Zealand
关键词
Information security; security assessment framework; security assessment model;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the importance of information and the supporting technology has increased, so too has the imperative to ensure its security. Security assessment is driven by regulatory compliance and the need to provide stakeholder assurance that information assets are adequately protected. A comprehensive and effective security assessment framework is thus vital to both corporate governance and management of security spending and investment. However, there is little evidence that such a framework is either available or widely adopted. Information security practices that are based on well established practices are usually used to assess the effectiveness of the security function within an organization. Evidence indicates, however, that despite organisational alignment and compliance with standards, losses associated with security incidents continue to occur and are on the increase. Two conclusions can be drawn: that the security controls defined by standards and frameworks are necessary but insufficient to ensure security; and that the measurement tools that support the management of information security are either not implemented or not available. Recent models for information security extend the scope of existing "best practice" security frameworks to include organisational factors for security. Others have suggested the application of CSF analysis to information security management. While these extend the body of knowledge, they do not address the need for a corresponding assessment model. What is required is a comprehensive framework for security assessment that incorporates all relevant organisational capabilities and competencies. The objective of this research is to generate a model that informs the development of such a framework. This paper explores the notion of information security from an organisational perspective, and the various standards and frameworks that are currently used. The concepts of assessment and metrics are also examined in this context and, finally, a conceptual model for security assessment is presented together with an indication of its application.
引用
收藏
页码:218 / 227
页数:10
相关论文
共 50 条
  • [1] Organisational Information Security Management Maturity Model
    Zammani, Mazlina
    Razali, Rozilawati
    Singh, Dalbir
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (09) : 668 - 678
  • [2] Quantitative Assessment for Organisational Security & Dependability
    Asnar, Yudistira
    Felici, Massimo
    Massacci, Fabio
    Tedeschi, Alessandra
    Yautsiukhin, Artsiom
    DEPEND: 2009 SECOND INTERNATIONAL CONFERENCE ON DEPENDABILITY, 2009, : 40 - +
  • [3] Information security: Listening to the perspective of organisational insiders
    Choi, SeEun
    Martins, Jorge Tiago
    Bernik, Igor
    JOURNAL OF INFORMATION SCIENCE, 2018, 44 (06) : 752 - 767
  • [4] A Capability Approach to Managing Organisational Information Security
    Carcary, Marian
    Doherty, Eileen
    Conway, Gerry
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 97 - 105
  • [5] Risk assessment model of information security SVRAMIS
    Wu, D. (jump_wude@163.com), 2013, Science Press (40):
  • [6] Managing security risks for inter-organisational information systems: a multiagent collaborative model
    Feng, Nan
    Wu, Harris
    Li, Minqiang
    Wu, Desheng
    Chen, Fuzan
    Tian, Jin
    ENTERPRISE INFORMATION SYSTEMS, 2016, 10 (07) : 751 - 770
  • [7] The impact of information security management practices on organisational agility
    Zaini, Muhamad Khairulnizam
    Masrek, Mohamad Noorman
    Sani, Mad Khir Johari Abdullah
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (05) : 681 - 700
  • [9] Assessment Model and Method Research of Information Security Risk
    Lu Zhen
    Xiong Zhen
    Tu Keqin
    FRONTIERS OF MANUFACTURING AND DESIGN SCIENCE IV, PTS 1-5, 2014, 496-500 : 2170 - +
  • [10] General risk assessment model for information system security
    Chi, Yue
    Zhang, Yong-Zheng
    Yun, Xiao-Chun
    Harbin Gongye Daxue Xuebao/Journal of Harbin Institute of Technology, 2005, 37 (SUPPL. 1): : 192 - 194