Adopting security maturity model to the organizations' capability model

被引:11
|
作者
Al-Matari, Osamah M. M. [1 ]
Helal, Iman M. A. [1 ]
Mazen, Sherif A. [1 ]
Elhennawy, Sherif
机构
[1] Cairo Univ, Dept Informat Syst, FCI, Giza, Egypt
关键词
Security maturity; Security controls; Maturity assessments; Capability process; Cybersecurity; INFORMATION SECURITY; MANAGEMENT;
D O I
10.1016/j.eij.2020.08.001
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Each organization faces threats and risks in daily operations. One of the main risks is how to assess the security level to protect from the increasing risks associated with technology evolution. So, organizations can specify the required approaches and skills. In this paper, we propose a security maturity model that classifies the organizations into five levels. Each level determines the technologies and process capability used by the organizations. There is a set of factors that can help in determining the security maturity level, such as technology, people, and infrastructure. This paper adopts an Information Security Management model to assess organization's security level. The authors make a correspondence between maturity levels and security levels in an organization. Also, the proposed process capability controls influence both levels. The proposed model helps the organizations bridging the cybersecurity gaps. These gaps relate to talent, technology, organizational units, financial, management and operations gaps. Thus, the model helps the cybersecurity auditors to create a comprehensive plan for measuring the security level of the organization. This plan can manage and develop the organization's automated countermeasures. Also, it can help in applying the suitable standard and framework based on the organization's daily operation. Cybersecurity auditors use cybersecurity techniques and tools to assess the organization's postures. Finally, the authors applied the security maturity controls in two case studies: retirement organization and public telecommunication corporation in the Republic of Yemen. (C) 2021 THE AUTHORS. Published by Elsevier BV on behalf of Faculty of Computers and Artificial Intelligence, Cairo University.
引用
收藏
页码:193 / 199
页数:7
相关论文
共 50 条
  • [41] A Capability Assessment Model for Emergency Management Organizations
    Xinzhi Wang
    Vijayan Sugumaran
    Hui Zhang
    Zheng Xu
    [J]. Information Systems Frontiers, 2018, 20 : 653 - 667
  • [42] Motivations for and Benefits of Adopting the Test Maturity Model integration (TMMi)
    van Veenendaal, Erik
    Garousi, Vahid
    Felderer, Michael
    [J]. SOFTWARE QUALITY: THE NEXT BIG THING IN SOFTWARE ENGINEERING AND QUALITY, SWQD 2022, 2022, 439 : 13 - 19
  • [43] Spice: Is a capability maturity model applicable in the construction industry?
    Sarshar, M
    Finnemore, M
    Haigh, R
    Goulding, J
    [J]. DURABILITY OF BUILDING MATERIALS AND COMPONENTS 8, VOLS 1-4, PROCEEDINGS, 1999, : 2836 - 2843
  • [44] Enterprise SPICE Based Education Capability Maturity Model
    Mitasiunas, Antanas
    Novickis, Leonids
    [J]. WORKSHOPS ON BUSINESS INFORMATICS RESEARCH, 2012, 106 : 102 - +
  • [45] The systems engineering capability maturity model: Where to start?
    Cusick, K
    [J]. PROCEEDINGS OF THE IEEE 1997 AEROSPACE AND ELECTRONICS CONFERENCE - NAECON 1997, VOLS 1 AND 2, 1997, : 410 - 416
  • [46] COMPARING ISO 9001 AND THE CAPABILITY MATURITY MODEL FOR SOFTWARE
    PAULK, MC
    [J]. SOFTWARE QUALITY JOURNAL, 1993, 2 (04) : 245 - 256
  • [47] Study on Enterprise Technological Innovation Capability Maturity Model
    Qin Dezhi
    Hu Hong
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON PRODUCT INNOVATION MANAGEMENT, VOLS I AND II, 2010, : 693 - 697
  • [48] Towards a capability maturity model for digital forensic readiness
    Ludwig Englbrecht
    Stefan Meier
    Günther Pernul
    [J]. Wireless Networks, 2020, 26 : 4895 - 4907
  • [49] Built Environment Flood Resilience Capability Maturity Model
    Adeniyi, Onaopepo
    Perera, Srinath
    Ginige, Kanchana
    [J]. 7TH INTERNATIONAL CONFERENCE ON BUILDING RESILIENCE: USING SCIENTIFIC KNOWLEDGE TO INFORM POLICY AND PRACTICE IN DISASTER RISK REDUCTION, 2018, 212 : 776 - 783
  • [50] Capability Maturity Model Integrated for Ship Design and Construction
    Caracchi, Serena
    Sriram, Pavan Kumar
    Semini, Marco
    Strandhagen, Jan Ola
    [J]. ADVANCES IN PRODUCTION MANAGEMENT SYSTEMS: INNOVATIVE AND KNOWLEDGE-BASED PRODUCTION MANAGEMENT IN A GLOBAL-LOCAL WORLD, APMS 2014, PT III, 2014, 440 : 296 - 303