A Model to Measure the Maturity of Smartphone Security at Software Consultancies

被引:0
|
作者
Allam, S. [1 ]
Flowerday, S. [1 ]
机构
[1] Univ Ft Hare, Dept Informat Syst, Alice, South Africa
来源
PROCEEDINGS OF THE SOUTH AFRICAN INFORMATION SECURITY MULTI-CONFERENCE | 2010年
关键词
Smartphones; Mobile Computing; Information Security; Software Consultancies;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smartphones are proliferating into the workplace at an ever-increasing rate. Similarly the information security threats that they pose are increasing. In an era of constant connectivity and availability, information is freed up of constraints of time and place. The risks introduced by smartphones are analysed through multiple cases studies, and a maturity measurement model is formulated. This model is based on recommendations from two leading information security frameworks, the COBIT 4.1 framework and ISO27002 code of practice. Ultimately, a combination of Smartphone specific risks are integrated with key control recommendations to provide a set of key measurable security maturity components. The empirical evidence is gathered using an in-depth questionnaire of 67 question statements adapted from each of the activities recommended by the COBIT 4.1 processes which target risk management as a primary objective. The opinions of 58 respondents are included as key components in the model. The solution addresses the concerns of not only policy makers, but also the employees subjected to security policies. Nurturing security awareness into organisational culture through reinforcement and employee acceptance is highlighted in this research paper. Software consultancies can use this model to mitigate risks, while harnessing the potential strategic advantages of mobile computing through smartphones. In addition, the critical components of a Smartphone security solution are identified. As a result, a model is provided for software consultancies due to the intense reliance on information within these types of organisations. The model is applicable to any information intensive organisation.
引用
收藏
页码:110 / 121
页数:12
相关论文
共 50 条
  • [41] Security Maturity Model of Web Applications for Cyber Attacks
    Rojas, Renato
    Muedas, Ana
    Mauricio, David
    PROCEEDINGS OF 2019 THE 3RD INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP 2019) WITH WORKSHOP 2019 THE 4TH INTERNATIONAL CONFERENCE ON MULTIMEDIA AND IMAGE PROCESSING (ICMIP 2019), 2019, : 130 - 137
  • [42] A Dynamic Capability Maturity Model for Improving Cyber Security
    Adler, Richard M.
    2013 IEEE INTERNATIONAL CONFERENCE ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2013, : 230 - 235
  • [43] Towards a Systemic Maturity Model for Public Software Ecosystems
    Alves, Angela M.
    Pessoa, Marcelo
    Salviano, Clenio F.
    SOFTWARE PROCESS IMPROVEMENT AND CAPABILITY DETERMINATION, 2011, 155 : 145 - +
  • [44] A business maturity model of software product line engineering
    Faheem Ahmed
    Luiz Fernando Capretz
    Information Systems Frontiers, 2011, 13 : 543 - 560
  • [45] Communication in Distributed Software Development: A Preliminary Maturity Model
    Farias Junior, Ivaldir
    Marczak, Sabrina
    Santos, Rodrigo
    Moura, Hermano
    2016 IEEE 11TH INTERNATIONAL CONFERENCE ON GLOBAL SOFTWARE ENGINEERING (ICGSE), 2016, : 164 - 168
  • [46] COMPARING ISO 9001 AND THE CAPABILITY MATURITY MODEL FOR SOFTWARE
    PAULK, MC
    SOFTWARE QUALITY JOURNAL, 1993, 2 (04) : 245 - 256
  • [47] A Maturity Model for Secure Software Design: A Multivocal Study
    Al-Matouq, Hassan
    Mahmood, Sajjad
    Alshayeb, Mohammad
    Niazi, Mahmood
    IEEE ACCESS, 2020, 8 (08): : 215758 - 215776
  • [48] Development of a Maturity Model for Software Quality Assurance Practices
    Al MohamadSaleh, Ahmad
    Alzahrani, Saeed
    SYSTEMS, 2023, 11 (09):
  • [49] An organizational maturity model of software product line engineering
    Faheem Ahmed
    Luiz Fernando Capretz
    Software Quality Journal, 2010, 18 : 195 - 225
  • [50] A business maturity model of software product line engineering
    Ahmed, Faheem
    Capretz, Luiz Fernando
    INFORMATION SYSTEMS FRONTIERS, 2011, 13 (04) : 543 - 560