An Organisational Model for Information Security Assessment

被引:0
|
作者
McKissack, Jeremy [1 ]
Hooper, Val [1 ]
Hope, Beverley [1 ]
机构
[1] Victoria Univ Wellington, Wellington, New Zealand
关键词
Information security; security assessment framework; security assessment model;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the importance of information and the supporting technology has increased, so too has the imperative to ensure its security. Security assessment is driven by regulatory compliance and the need to provide stakeholder assurance that information assets are adequately protected. A comprehensive and effective security assessment framework is thus vital to both corporate governance and management of security spending and investment. However, there is little evidence that such a framework is either available or widely adopted. Information security practices that are based on well established practices are usually used to assess the effectiveness of the security function within an organization. Evidence indicates, however, that despite organisational alignment and compliance with standards, losses associated with security incidents continue to occur and are on the increase. Two conclusions can be drawn: that the security controls defined by standards and frameworks are necessary but insufficient to ensure security; and that the measurement tools that support the management of information security are either not implemented or not available. Recent models for information security extend the scope of existing "best practice" security frameworks to include organisational factors for security. Others have suggested the application of CSF analysis to information security management. While these extend the body of knowledge, they do not address the need for a corresponding assessment model. What is required is a comprehensive framework for security assessment that incorporates all relevant organisational capabilities and competencies. The objective of this research is to generate a model that informs the development of such a framework. This paper explores the notion of information security from an organisational perspective, and the various standards and frameworks that are currently used. The concepts of assessment and metrics are also examined in this context and, finally, a conceptual model for security assessment is presented together with an indication of its application.
引用
收藏
页码:218 / 227
页数:10
相关论文
共 50 条
  • [21] pISRA: privacy considered information security risk assessment model
    Wei, Yu-Chih
    Wu, Wei-Chen
    Lai, Gu-Hsin
    Chu, Ya-Chi
    JOURNAL OF SUPERCOMPUTING, 2020, 76 (03): : 1468 - 1481
  • [22] Classified Information System Security Risk Assessment Model of the Research
    Peng, Chong
    Shao, Liping
    2015 INTERNATIONAL CONFERENCE ON LOGISTICS, INFORMATICS AND SERVICE SCIENCES (LISS), 2015,
  • [23] Approximate reduced model based on mutual information for security assessment
    Li, Wei
    Fan, Ming-Yu
    Kongzhi yu Juece/Control and Decision, 2010, 25 (09): : 1426 - 1430
  • [24] Development of Information Security Management Assessment Model for the Financial Sector
    Oh, Eun
    Kim, Tae-Sung
    Cho, Tae-Hee
    INFORMATION SECURITY APPLICATIONS, WISA 2016, 2017, 10144 : 186 - 197
  • [25] pISRA: privacy considered information security risk assessment model
    Yu-Chih Wei
    Wei-Chen Wu
    Gu-Hsin Lai
    Ya-Chi Chu
    The Journal of Supercomputing, 2020, 76 : 1468 - 1481
  • [26] Model of assessment of risks of information security in the environment of cloud computing
    Djuraev, R. X.
    Umirzakov, B. M.
    2016 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND COMMUNICATIONS TECHNOLOGIES (ICISCT), 2016,
  • [27] Evaluation of Information Security Risks Using Hybrid Assessment Model
    Alese, B. K.
    Oyebade, O.
    Festus, Osuolale A.
    Iyare, O.
    Thompson, A. F.
    2014 9TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2014, : 387 - 395
  • [28] Study on Model-based Security Assessment of Information Systems
    Li, Xiangdong
    Han, Xinchao
    Zheng, Qiusheng
    2010 SECOND INTERNATIONAL CONFERENCE ON E-LEARNING, E-BUSINESS, ENTERPRISE INFORMATION SYSTEMS, AND E-GOVERNMENT (EEEE 2010), VOL I, 2010, : 289 - 292
  • [29] The Information Security Risk Assessment Model Based on GA - BP
    Song, Yongqiang
    Shen, Yongjun
    Zhang, Guidong
    Hu, Yuming
    PROCEEDINGS OF 2016 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2016), 2016, : 119 - 122
  • [30] Construction of Information Security Risk Assessment Model in Smart City
    Hui, Pan
    2020 IEEE CONFERENCE ON TELECOMMUNICATIONS, OPTICS AND COMPUTER SCIENCE (TOCS), 2020, : 393 - 396