Metrics, a fundamental element in the construction of informatics security maturity models

被引:0
|
作者
Villegas, Marianella [1 ]
Meza, Marina [1 ]
Leon, Pilar [1 ]
机构
[1] Univ Simon Bolivar, Caracas, Venezuela
来源
TELEMATIQUE | 2011年 / 10卷 / 01期
关键词
Indicators; Metrics; Information security management models; Controls;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
In organizations, information security is required to guarantee institutional information environment, through human resources and technological management, to do so, it is necessary to use regulatory devices for functions and activities developed by institution personnel. The purpose of this paper was to construct security metrics that allow measuring, making decisions and improving information security systems performance in Capital District universities. In order to carry out this research, a literature review was done which supported conceptual references about security metrics, their types and indicators, and information security levels were established. From these levels, a questionnaire was designed and validated; it was applied to information security administrators or managers at selected Capital District universities. Then, the data was analyzed and a set of indicators which permitted metrics construction for each level. Resulting metrics made possible to measure institutional performance against challenges for preservation and protection of information, as well as identifying the origin of not satisfactory performance and informatics areas which require being improved. Likewise, metrics facilitate the establishment of new information security policies, where goals and objectives redefinition is carried out at the same time with technological changes to face threats and vulnerabilities that would arise in the future.
引用
收藏
页码:1 / 16
页数:16
相关论文
共 50 条
  • [1] Security Metrics Maturity Model for Operational Security
    Muthukrishnan, Murugarasan
    Palaniappan, Sellapan
    [J]. 2016 IEEE SYMPOSIUM ON COMPUTER APPLICATIONS & INDUSTRIAL ELECTRONICS (ISCAIE), 2016, : 101 - 106
  • [2] Maturity and Maturity Models in Lean Construction
    Nesensohn, Claus
    Bryde, David
    Ochieng, Edward
    Fearon, Damian
    [J]. CONSTRUCTION ECONOMICS AND BUILDING, 2014, 14 (01): : 45 - 59
  • [3] Security Metrics and Security Investment Models
    Boehme, Rainer
    [J]. ADVANCES IN INFORMATION AND COMPUTER SECURITY, 2010, 6434 : 10 - 24
  • [4] Novel security models, metrics and security assessment networks
    Enoch, Simon Yusuf
    Lee, Jang Se
    Kim, Dong Seong
    [J]. COMPUTER NETWORKS, 2021, 189
  • [5] Hardware Security: Threat Models and Metrics
    Rostami, M.
    Koushanfar, F.
    Rajendran, J.
    Karri, R.
    [J]. 2013 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2013, : 819 - 823
  • [6] MATURITY, MODELS, AND GOALS - HOW TO BUILD A METRICS PLAN
    PFLEEGER, SL
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 1995, 31 (02) : 143 - 155
  • [7] Can maturity models support cyber security?
    Le, Ngoc T.
    Hoang, Doan B.
    [J]. 2016 IEEE 35TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2016,
  • [8] Security metrics models and application with SVM in information security management
    Qu, Wei
    Zhang, De-Zheng
    [J]. PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 3234 - +
  • [9] A Primer on Hardware Security: Models, Methods, and Metrics
    Rostami, Masoud
    Koushanfar, Farinaz
    Karri, Ramesh
    [J]. PROCEEDINGS OF THE IEEE, 2014, 102 (08) : 1283 - 1295
  • [10] Project Management Maturity Models for Construction Firms
    Machado, Filipe
    Duarte, Nelson
    Amaral, Antonio
    Barros, Teresa
    [J]. JOURNAL OF RISK AND FINANCIAL MANAGEMENT, 2021, 14 (12)