skip to main content
10.1145/2691195.2691275acmotherconferencesArticle/Chapter ViewAbstractPublication PagesicegovConference Proceedingsconference-collections
research-article

Security metrics to evaluate organizational IT security

Published:27 October 2014Publication History

ABSTRACT

Organizations have moved their business activity to the Internet and mobile applications, which make them more exposed to unexpected and underestimated security risks. This fact requires organizations to implement adequate security controls as well as the respective monitoring and evaluation on a regular basis. However, these tasks require strong arguments (in monetary terms) to justify the return of investment in the security controls. In this context, it is crucial for organizations to define metrics to assess the efficiency of the implemented controls, to justify the security investments. This paper highlights some reflections regarding the definition of meaningful metrics of security controls, to deliver actionable information for decision makers for managing their organizational assets and ensure their day-to-day operations.

References

  1. Ashford, W., (2011). Security Think Tank: How can businesses measure the effectiveness of their IT security teams?{on-line}. ComputerWeekly.com. Available from: http://www.computerweekly.com/feature/Security-Think-Tank-How-can-businesses-measure-the-effectiveness-of-their-IT-security-teams. {Accessed January 2014}.Google ScholarGoogle Scholar
  2. ISO/IEC_JTC1, 2009a. ISO/IEC FDIS 27000 Information Technology - Security Techniques - Information Security Management Systems - Overview and Vocabulary. ISO copyright office: Geneva, Switzerland.Google ScholarGoogle Scholar
  3. Pagett, J., Ng, S. (2010). Improving Residual Risk Management Through the Use of Security Metrics {on-line}. Royal Holloway Series 2010. Available from: http://cdn.ttgtmedia.com/searchSecurityUK/downloads/RHUL_Pagett_v2.pdf. {Accessed January 2014}.Google ScholarGoogle Scholar
  4. Peláez, M. H. S., (2010). Measuring effectiveness in Information Security Controls {on-line}. SANS Institute InfoSec Reading Room. Available from: http://www.sans.org/reading-room/whitepapers/basics/measuring-effectiveness-information-security-controls-33398. {Accessed January 2014}.Google ScholarGoogle Scholar
  5. Pereira, T., 2012. Conceptual Framework to Support Information Security Risk Management. Doctoral Thesis. University of Minho.Google ScholarGoogle Scholar

Index Terms

  1. Security metrics to evaluate organizational IT security

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Other conferences
      ICEGOV '14: Proceedings of the 8th International Conference on Theory and Practice of Electronic Governance
      October 2014
      563 pages
      ISBN:9781605586113
      DOI:10.1145/2691195

      Copyright © 2014 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 27 October 2014

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • research-article

      Acceptance Rates

      ICEGOV '14 Paper Acceptance Rate30of73submissions,41%Overall Acceptance Rate350of865submissions,40%

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader