{"title":"A Policy-Based Metrics Framework for Information Security Performance Measurement","authors":"C. Martin, M. Refai","doi":"10.1109/BDIM.2007.375016","DOIUrl":null,"url":null,"abstract":"In this article we are proposing a new approach to measure and monitor overall IT security performance. This approach is based on a policy-based frame work that establishes a methodology to measure security performance; it also incorporates a policy performance indicator. The framework is composed of a number of interacting components: security policies and procedures model, a business security goal and targets repository, a set of security measurement processes, a metrics development and analysis process, and a central metrics and measurement model. Lastly a module that derives an overall security posture and generates reports detects trends and develops recommendations. Our approach assists in determining the security posture of an organization, which is becoming a necessity for legal and regulatory compliance.","PeriodicalId":414047,"journal":{"name":"2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-05-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BDIM.2007.375016","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
Abstract
In this article we are proposing a new approach to measure and monitor overall IT security performance. This approach is based on a policy-based frame work that establishes a methodology to measure security performance; it also incorporates a policy performance indicator. The framework is composed of a number of interacting components: security policies and procedures model, a business security goal and targets repository, a set of security measurement processes, a metrics development and analysis process, and a central metrics and measurement model. Lastly a module that derives an overall security posture and generates reports detects trends and develops recommendations. Our approach assists in determining the security posture of an organization, which is becoming a necessity for legal and regulatory compliance.