首页> 外文期刊>Computers & Security >Maturity level assessments of information security controls: An empirical analysis of practitioners assessment capabilities
【24h】

Maturity level assessments of information security controls: An empirical analysis of practitioners assessment capabilities

机译:信息安全控制的成熟程度评估:从业者评估能力的实证分析

获取原文
获取原文并翻译 | 示例
           

摘要

Maturity models are a widely used concept for measuring information security. The idea is to systematically evaluate the maturity of security-relevant processes in an organisation. This enables decision-makers to get an overview of the implementation status of relevant processes to identify neuralgic points. Maturity models thus play a central role in the conception of information security management systems (ISMS). Some industries, for instance, the German automotive industry, have even established security maturity levels as the de facto standard for measuring information security. However, the quality of security maturity level assessments has not been sufficiently investigated yet. Therefore, we have analysed to what extent security managers can accurately assess the maturity levels of security controls. To verify the quality of maturity level assessments a case study was conducted where security experts assessed a subset of the ISO/IEC 27002 security controls for a hypothetical scenario using the COBIT maturity levels. Additionally, ex-post interviews have been conducted with several participants of the study to verify some of the hypotheses developed during the previous analyses. Our results show that many security experts struggled with the task and did not perform well. However, we discovered professional characteristics that have a strong significant effect on the assessment capabilities. We also identified various types of additional support that can help practitioners to make more reliable assessments in practice. Moreover, the experts' self-perception was overly optimistic when asked to assess their performance. We even found a weak inverted correlation for more experienced experts, also known as Dunning-Kruger effect. Our results have a strong impact on practice since they indicate that practitioners need support to carry out high-quality assessments and they also show what kind of support addresses the identified challenges.
机译:成熟度模型是一种广泛使用的概念,用于测量信息安全性。该想法是系统地评估组织中安全相关流程的成熟度。这使得决策者能够概述相关流程的实施状态,以识别神经内脏。因此,成熟模型在信息安全管理系统(ISMS)的概念中起着核心作用。例如,一些行业,德国汽车行业,甚至建立了安全成熟度水平,作为测量信息安全的事实标准。但是,尚未充分调查安全成熟度评估的质量。因此,我们已经分析了安全管理人员可以准确地评估安全控制的成熟程度。为了验证到期性级别评估的质量,在安全专家评估了使用COBIT成熟度水平的假设方案的ISO / IEC 27002安全控制的子集的情况下进行了案例研究。此外,已经使用研究的几个参与者进行了前后面试,以验证在前次分析期间开发的一些假设。我们的研究结果表明,许多安全专家们与任务挣扎,并没有表现良好。但是,我们发现了对评估能力产生了强烈显着影响的专业特征。我们还确定了各种类型的额外支持,可以帮助从业者在实践中做出更可靠的评估。此外,当被要求评估其表现时,专家的自我感知是过于乐观的。我们甚至发现更多有经验的专家倒置相关性,也称为令人垂涎的克鲁格效应。我们的结果对实践产生了强烈影响,因为他们表明从业者需要支持开展高质量的评估,并且他们还表明了什么样的支持解决了所确定的挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号