首页> 外文OA文献 >Enterprise information security policy assessment : an extended framework for metrics development utilising the goal-question-metric approach
【2h】

Enterprise information security policy assessment : an extended framework for metrics development utilising the goal-question-metric approach

机译:企业信息安全策略评估:使用目标-问题-度量方法的度量开发扩展框架

摘要

Effective enterprise information security policy management requires review and assessment activities to ensure information security policies are aligned with business goals and objectives. As security policy management involves the elements of policy development process and the security policy as output, the context for security policy assessment requires goal-based metrics for these two elements. However, the current security management assessment methods only provide checklist types of assessment that are predefined by industry best practices and do not allow for developing specific goal-based metrics. Utilizing theories drawn from literature, this paper proposes the Enterprise Information Security Policy Assessment approach that expands on the Goal-Question-Metric (GQM) approach. The proposed assessment approach is then applied in a case scenario example to illustrate a practical application. It is shown that the proposed framework addresses the requirement for developing assessment metrics and allows for the concurrent undertaking of process-based and product-based assessment. Recommendations for further research activities include the conduct of empirical research to validate the propositions and the practical application of the proposed assessment approach in case studies to provide opportunities to introduce further enhancements to the approach.
机译:有效的企业信息安全策略管理要求进行审查和评估活动,以确保信息安全策略符合业务目标。由于安全策略管理涉及策略开发过程的元素以及安全策略作为输出,因此安全策略评估的上下文需要针对这两个元素的基于目标的度量。但是,当前的安全管理评估方法仅提供由行业最佳实践预定义的评估清单类型,并且不允许开发基于目标的特定指标。利用从文献中得出的理论,本文提出了企业信息安全策略评估方法,该方法是在“目标-问题-指标”(GQM)方法的基础上进行扩展的。然后,将所提出的评估方法应用于案例场景示例中,以说明实际应用。结果表明,所提出的框架满足了开发评估指标的要求,并允许同时进行基于过程和基于产品的评估。对进一步研究活动的建议包括进行实证研究以验证建议,并在案例研究中实际应用拟议的评估方法,以提供机会进一步引入该方法。

著录项

  • 作者

    Corpuz Maria;

  • 作者单位
  • 年度 2011
  • 总页数
  • 原文格式 PDF
  • 正文语种 {"code":"en","name":"English","id":9}
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号