适应网络安全成熟度模型的资源约束设置:秘鲁的案例研究

IF 1.1 Q2 SOCIAL SCIENCES, INTERDISCIPLINARY
GangSeok Lee, SuHyun Kim, ImYoung Lee, Suzana Brown, Yuri Aldoradin Carbajal
{"title":"适应网络安全成熟度模型的资源约束设置:秘鲁的案例研究","authors":"GangSeok Lee,&nbsp;SuHyun Kim,&nbsp;ImYoung Lee,&nbsp;Suzana Brown,&nbsp;Yuri Aldoradin Carbajal","doi":"10.1002/isd2.12350","DOIUrl":null,"url":null,"abstract":"<p>Developing countries are rapidly embracing digitalization, but this exposes them to heightened cybersecurity risks. They often look to standard established cybersecurity models from developed countries to build their national defenses. However, significant developmental, political, social, and economic differences can render these models unsuitable for developing countries. This study addresses this gap by proposing a new framework that would be more useful in a developing country context. We first examine existing cybersecurity maturity models (CMMs) and metrics. Through a case study of Peru's national computer security incident response team (CSIRT), we assess the applicability of the security incident management maturity model (SIM3) and the security operation center CMM (SOC-CMM) frameworks. By applying these frameworks to the Peruvian context, we identify limitations in standard maturity models for developing countries. In response, we propose a novel framework that allows developing countries like Peru to leverage existing models by tailoring them to their specific environment. This tailored approach can be a powerful tool for developing countries to improve and build their cybersecurity on a national level.</p>","PeriodicalId":46610,"journal":{"name":"Electronic Journal of Information Systems in Developing Countries","volume":"91 1","pages":""},"PeriodicalIF":1.1000,"publicationDate":"2024-10-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/isd2.12350","citationCount":"0","resultStr":"{\"title\":\"Adapting cybersecurity maturity models for resource-constrained settings: A case study of Peru\",\"authors\":\"GangSeok Lee,&nbsp;SuHyun Kim,&nbsp;ImYoung Lee,&nbsp;Suzana Brown,&nbsp;Yuri Aldoradin Carbajal\",\"doi\":\"10.1002/isd2.12350\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>Developing countries are rapidly embracing digitalization, but this exposes them to heightened cybersecurity risks. They often look to standard established cybersecurity models from developed countries to build their national defenses. However, significant developmental, political, social, and economic differences can render these models unsuitable for developing countries. This study addresses this gap by proposing a new framework that would be more useful in a developing country context. We first examine existing cybersecurity maturity models (CMMs) and metrics. Through a case study of Peru's national computer security incident response team (CSIRT), we assess the applicability of the security incident management maturity model (SIM3) and the security operation center CMM (SOC-CMM) frameworks. By applying these frameworks to the Peruvian context, we identify limitations in standard maturity models for developing countries. In response, we propose a novel framework that allows developing countries like Peru to leverage existing models by tailoring them to their specific environment. This tailored approach can be a powerful tool for developing countries to improve and build their cybersecurity on a national level.</p>\",\"PeriodicalId\":46610,\"journal\":{\"name\":\"Electronic Journal of Information Systems in Developing Countries\",\"volume\":\"91 1\",\"pages\":\"\"},\"PeriodicalIF\":1.1000,\"publicationDate\":\"2024-10-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1002/isd2.12350\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Electronic Journal of Information Systems in Developing Countries\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1002/isd2.12350\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"SOCIAL SCIENCES, INTERDISCIPLINARY\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Electronic Journal of Information Systems in Developing Countries","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/isd2.12350","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"SOCIAL SCIENCES, INTERDISCIPLINARY","Score":null,"Total":0}
引用次数: 0

摘要

发展中国家正在迅速接受数字化,但这使他们面临更大的网络安全风险。他们经常借鉴发达国家标准的网络安全模式来建立自己的国家防御。然而,重大的发展、政治、社会和经济差异可能使这些模式不适合发展中国家。这项研究通过提出一个在发展中国家背景下更有用的新框架来解决这一差距。我们首先检查现有的网络安全成熟度模型(cmm)和指标。通过对秘鲁国家计算机安全事件响应小组(CSIRT)的案例研究,我们评估了安全事件管理成熟度模型(SIM3)和安全运营中心CMM (SOC-CMM)框架的适用性。通过将这些框架应用于秘鲁的情况,我们发现了适用于发展中国家的标准成熟度模型的局限性。作为回应,我们提出了一个新的框架,允许像秘鲁这样的发展中国家利用现有模式,使其适应其具体环境。这种量身定制的方法可以成为发展中国家在国家层面上改善和建立网络安全的有力工具。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

Adapting cybersecurity maturity models for resource-constrained settings: A case study of Peru

Adapting cybersecurity maturity models for resource-constrained settings: A case study of Peru

Developing countries are rapidly embracing digitalization, but this exposes them to heightened cybersecurity risks. They often look to standard established cybersecurity models from developed countries to build their national defenses. However, significant developmental, political, social, and economic differences can render these models unsuitable for developing countries. This study addresses this gap by proposing a new framework that would be more useful in a developing country context. We first examine existing cybersecurity maturity models (CMMs) and metrics. Through a case study of Peru's national computer security incident response team (CSIRT), we assess the applicability of the security incident management maturity model (SIM3) and the security operation center CMM (SOC-CMM) frameworks. By applying these frameworks to the Peruvian context, we identify limitations in standard maturity models for developing countries. In response, we propose a novel framework that allows developing countries like Peru to leverage existing models by tailoring them to their specific environment. This tailored approach can be a powerful tool for developing countries to improve and build their cybersecurity on a national level.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
3.60
自引率
15.40%
发文量
51
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信