An Organisational Model for Information Security Assessment

被引:0
|
作者
McKissack, Jeremy [1 ]
Hooper, Val [1 ]
Hope, Beverley [1 ]
机构
[1] Victoria Univ Wellington, Wellington, New Zealand
关键词
Information security; security assessment framework; security assessment model;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As the importance of information and the supporting technology has increased, so too has the imperative to ensure its security. Security assessment is driven by regulatory compliance and the need to provide stakeholder assurance that information assets are adequately protected. A comprehensive and effective security assessment framework is thus vital to both corporate governance and management of security spending and investment. However, there is little evidence that such a framework is either available or widely adopted. Information security practices that are based on well established practices are usually used to assess the effectiveness of the security function within an organization. Evidence indicates, however, that despite organisational alignment and compliance with standards, losses associated with security incidents continue to occur and are on the increase. Two conclusions can be drawn: that the security controls defined by standards and frameworks are necessary but insufficient to ensure security; and that the measurement tools that support the management of information security are either not implemented or not available. Recent models for information security extend the scope of existing "best practice" security frameworks to include organisational factors for security. Others have suggested the application of CSF analysis to information security management. While these extend the body of knowledge, they do not address the need for a corresponding assessment model. What is required is a comprehensive framework for security assessment that incorporates all relevant organisational capabilities and competencies. The objective of this research is to generate a model that informs the development of such a framework. This paper explores the notion of information security from an organisational perspective, and the various standards and frameworks that are currently used. The concepts of assessment and metrics are also examined in this context and, finally, a conceptual model for security assessment is presented together with an indication of its application.
引用
收藏
页码:218 / 227
页数:10
相关论文
共 50 条
  • [41] Matrix correction method based information system security assessment model
    Yang H.
    Zhang X.
    Lu W.
    1600, Tsinghua University (60): : 393 - 401
  • [42] The model of information security risk assessment based on advanced evidence theory
    Qing H.
    Qingsheng X.
    Shaobo L.
    International Journal of System Assurance Engineering and Management, 2017, 8 (Suppl 3) : 2030 - 2035
  • [43] A Security Situation Assessment Model of Information System for Smart Mobile Devices
    Xie, Lixia
    Yan, Liping
    Zhang, Xugao
    Yang, Hongyu
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2020, 2020 (2020):
  • [44] Limitations of the Information Security Management System Assessment Approaches in the Context of Information Security Policy Assessment
    Corpuz, Maria Soto
    WMSCI 2010: 14TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL IV (POST-CONFERENCE EDITION), 2010, : 148 - 150
  • [45] A framework and tool for the assessment of information security risk, the reduction of information security cost and the sustainability of information security culture
    Govender S.G.
    Kritzinger E.
    Loock M.
    Personal and Ubiquitous Computing, 2021, 25 (05) : 927 - 940
  • [46] Integrated security management model: a proposal applied to organisational resilience
    Marquez-Tejon, Jose
    Jimenez-Partearroyo, Montserrat
    Benito-Osorio, Diana
    SECURITY JOURNAL, 2024, 37 (02) : 375 - 398
  • [47] The security model to combine the corporate and information security
    Virtanen, T
    TRUSTED INFORMATION: THE NEW DECADE CHALLENGE, 2001, 65 : 305 - 316
  • [48] Information security climate and the assessment of information security risk among healthcare employees
    Kessler, Stacey R.
    Pindek, Shani
    Kleinman, Gary
    Andel, Stephanie A.
    Spector, Paul E.
    HEALTH INFORMATICS JOURNAL, 2020, 26 (01) : 461 - 473
  • [49] Information security assessment of SMEs as coursework - learning information security management by doing
    Ilvonen, I. (ilona.ilvonen@tut.fi), 1600, Journal of Information Systems Education (24):
  • [50] Proposing the control-reactance compliance model (CRCM) to explain opposing motivations to comply with organisational information security policies
    Lowry, Paul Benjamin
    Moody, Gregory D.
    INFORMATION SYSTEMS JOURNAL, 2015, 25 (05) : 433 - 463