首页> 外文OA文献 >Measuring information security performance with 10 by 10 model for holistic state evaluation
【2h】

Measuring information security performance with 10 by 10 model for holistic state evaluation

机译:使用10×10模型测量信息安全性能以进行整体状态评估

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Organizations should measure their information security performance if they wish to take the right decisions and develop it in line with their security needs. Since the measurement of information security is generally underdeveloped in practice and many organizations find the existing recommendations too complex, the paper presents a solution in the form of a 10 by 10 information security performance measurement model. The model—ISP 10×10M is composed of ten critical success factors, 100 key performance indicators and 6 performance levels. Its content was devised on the basis of findings presented in the current research studies and standards, while its structure results from an empirical research conducted among information security professionals from Slovenia. Results of the study show that a high level of information security performance is mostly dependent on measures aimed at managing information risks, employees and information sources, while formal and environmental factors have a lesser impact. Experts believe that information security should evolve systematically, where it’s recommended that beginning steps include technical, logical and physical security controls, while advanced activities should relate predominantly strategic management activities. By applying the proposed model, organizations are able to determine the actual level of information security performance based on the weighted indexing technique. In this manner they identify the measures they ought to develop in order to improve the current situation. The ISP 10×10M is a useful tool for conducting internal system evaluations and decision-making. It may also be applied to a larger sample of organizations in order to determine the general state-of-play for research purposes.
机译:如果组织希望做出正确的决策并根据其安全需求进行开发,则应衡量其信息安全绩效。由于信息安全的度量通常在实践中不发达,许多组织发现现有建议过于复杂,因此本文以10 x 10信息安全绩效度量模型的形式提出了一种解决方案。 ISP 10×10M模型由十个关键的成功因素,100个关键性能指标和6个性能级别组成。它的内容是根据当前研究和标准中提出的发现而设计的,其结构是根据斯洛文尼亚的信息安全专业人员进行的一项实证研究得出的。研究结果表明,高水平的信息安全绩效主要取决于旨在管理信息风险,员工和信息源的措施,而正式和环境因素的影响较小。专家认为,信息安全应系统地发展,建议开始步骤包括技术,逻辑和物理安全控制,而高级活动应主要与战略管理活动相关。通过应用提出的模型,组织能够基于加权索引技术确定信息安全性能的实际水平。他们以这种方式确定了应改善现状的措施。 ISP 10×10M是进行内部系统评估和决策的有用工具。它也可以应用于更大的组织样本,以便确定研究的总体运行状况。

著录项

  • 作者

    Bernik, Igor; Prislan, Kaja;

  • 作者单位
  • 年度 2017
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号