Information security governance metrics: a survey and taxonomy

Vaibhav Anu
{"title":"Information security governance metrics: a survey and taxonomy","authors":"Vaibhav Anu","doi":"10.1080/19393555.2021.1922786","DOIUrl":null,"url":null,"abstract":"ABSTRACT Information Security Governance (ISG) is now considered a vital component of any organization’s Information Technology (IT) Governance. ISG consists of the processes, organizational structures, and most importantly, the corporate leadership involved in the safeguarding of organization’s information assets. Hence, the purpose of ISG is to bring information security to the attention of the executives such as CEOs and Boards, so that the executives can address the issues of information security and take security-related decisions that lead to outcomes that better align with organizational goals such as value delivery, better performance measurement, business process assurance, and risk management. In order for the corporate leadership to make data-driven decisions, data related to various security metrics are collected and presented in the form of dashboards. The goal of this article is to identify those security metrics that are particularly important from an ISG standpoint. A survey was performed on security literature to identify and categorize ISG metrics. An ISG metrics taxonomy was developed as a result of this study. Security teams can benefit from the ISG metrics taxonomy as, when creating security dashboards, the taxonomy can focus their attention on those specific security metrics that are of most value to the corporate leadership.","PeriodicalId":103842,"journal":{"name":"Information Security Journal: A Global Perspective","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-05-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Information Security Journal: A Global Perspective","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1080/19393555.2021.1922786","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

ABSTRACT Information Security Governance (ISG) is now considered a vital component of any organization’s Information Technology (IT) Governance. ISG consists of the processes, organizational structures, and most importantly, the corporate leadership involved in the safeguarding of organization’s information assets. Hence, the purpose of ISG is to bring information security to the attention of the executives such as CEOs and Boards, so that the executives can address the issues of information security and take security-related decisions that lead to outcomes that better align with organizational goals such as value delivery, better performance measurement, business process assurance, and risk management. In order for the corporate leadership to make data-driven decisions, data related to various security metrics are collected and presented in the form of dashboards. The goal of this article is to identify those security metrics that are particularly important from an ISG standpoint. A survey was performed on security literature to identify and categorize ISG metrics. An ISG metrics taxonomy was developed as a result of this study. Security teams can benefit from the ISG metrics taxonomy as, when creating security dashboards, the taxonomy can focus their attention on those specific security metrics that are of most value to the corporate leadership.
信息安全治理度量:调查和分类
信息安全治理(ISG)现在被认为是任何组织信息技术(IT)治理的重要组成部分。ISG包括流程、组织结构,最重要的是,包括保护组织信息资产的公司领导层。因此,ISG的目的是使信息安全引起执行人员(如ceo和董事会)的注意,以便执行人员能够处理信息安全问题,并采取与安全相关的决策,从而产生与组织目标(如价值交付、更好的性能度量、业务流程保证和风险管理)更好地一致的结果。为了让公司领导层做出数据驱动的决策,与各种安全指标相关的数据被收集起来,并以仪表板的形式呈现。本文的目标是从ISG的角度确定那些特别重要的安全度量。对安全文献进行了一项调查,以确定和分类ISG指标。作为这项研究的结果,开发了ISG度量分类法。安全团队可以从ISG指标分类法中受益,因为在创建安全指示板时,分类法可以将他们的注意力集中在对公司领导层最有价值的特定安全指标上。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信