Towards a General Information Security Management Assessment Framework to Compare Cyber-Security of Critical Infrastructure Organizations

被引:1
|
作者
Bernroider, Edward W. N. [1 ]
Margiol, Sebastian [1 ]
Taudes, Alfred [1 ]
机构
[1] Vienna Univ Econ & Business, Inst Informat Management & Control, Welthandelspl 1, A-1020 Vienna, Austria
关键词
BSC; Cyber-security; Critical infrastructure; Design science; Information security management; BALANCED SCORECARD; STRATEGY; IMPLEMENTATION;
D O I
10.1007/978-3-319-49944-4_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper describes the development of an information security framework that aims to comparatively assess the quality of management processes in the context of cyber-security of organizations operating within critical infrastructure sectors. A design science approach was applied to establish a framework artifact that consists of the four dimensions "Security Ambition", "Security Process", "Resilience" and "Business Value". These dimensions were related to the balanced scorecard concept and information security literature. The framework includes metrics, measurement approaches and aggregation methods. In its adapted form, our framework enables a systematic compilation of information security, and seeks to display the security situation of a focal firm against the desired future states, industry benchmarks, and allows for an investigation of interdependencies. The design science research process included workshops, cyclic refinements of the instrument, pretests and the framework evaluation within 30 critical infrastructure organizations. The framework was found to be particularly useful as learning and benchmarking tool capable of highlighting weaknesses, strengths, and gaps in relation to standards.
引用
收藏
页码:127 / 141
页数:15
相关论文
共 50 条
  • [1] Critical Infrastructure Cyber-Security Risk Management
    Spyridopoulos, Theodoros
    Maraslis, Konstantinos
    Tryfonas, Theo
    Oikonomou, George
    [J]. TERRORISTS' USE OF THE INTERNET: ASSESSMENT AND RESPONSE, 2017, 136 : 59 - 76
  • [2] Cyber-Security Risk Assessment Framework for Critical Infrastructures
    Baig, Zubair
    Zeadally, Sherali
    [J]. INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2019, 25 (01): : 121 - 129
  • [3] The Cyber-Security State of our Nation: A Critique of South Africa's Stance on Cyber-Security in Respect of the Protection of Critical Information Infrastructure
    Mohideen, Feroze
    [J]. PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2016), 2016, : 235 - 243
  • [4] On Cyber-Security of Information Systems
    Sneps-Sneppe, Manfred
    Sukhomlin, Vladimir
    Namiot, Dmitry
    [J]. DISTRIBUTED COMPUTER AND COMMUNICATION NETWORKS (DCCN 2018), 2018, 919 : 201 - 211
  • [5] Key competencies for critical infrastructure cyber-security: a systematic literature review
    Chowdhury, Nabin
    Gkioulos, Vasileios
    [J]. INFORMATION AND COMPUTER SECURITY, 2021, 29 (05) : 697 - 723
  • [6] Towards Cyber-Security Protection of Critical Infrastructures by Generating Security Policy for SCADA Systems
    Feltus, Christophe
    Ouedraogo, Moussa
    Khadraoui, Djamel
    [J]. 2014 1ST INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGIES FOR DISASTER MANAGEMENT (ICT-DM), 2014, : 1 - 8
  • [7] An Intelligent Quantum Cyber-Security Framework for Healthcare Data Management
    Gupta, Kishu
    Saxena, Deepika
    Rani, Pooja
    Kumar, Jitendra
    Makkar, Aaisha
    Singh, Ashutosh Kumar
    Lee, Chung-Nan
    [J]. IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2024,
  • [8] Cyber-Security Risk Assessment Framework for Blockchains in Smart Mobility
    Al Mallah, Ranwa
    Lopez, David
    Farooq, Bilal
    [J]. IEEE OPEN JOURNAL OF INTELLIGENT TRANSPORTATION SYSTEMS, 2021, 2 : 294 - 311
  • [9] Implementation Aspects of Smart Grids Cyber-Security Cross-Layered Framework for Critical Infrastructure Operation
    Agnew, Dennis
    Aljohani, Nader
    Mathieu, Reynold
    Boamah, Sharon
    Nagaraj, Keerthiraj
    McNair, Janise
    Bretas, Arturo
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (14):
  • [10] An Economic-based Cyber-security Framework for Identifying Critical Assets
    Yan, Jie
    Bo, Rui
    Ni, Ming
    [J]. 2014 IEEE PES GENERAL MEETING - CONFERENCE & EXPOSITION, 2014,