{"title":"基于策略的信息安全绩效度量框架","authors":"C. Martin, M. Refai","doi":"10.1109/BDIM.2007.375016","DOIUrl":null,"url":null,"abstract":"In this article we are proposing a new approach to measure and monitor overall IT security performance. This approach is based on a policy-based frame work that establishes a methodology to measure security performance; it also incorporates a policy performance indicator. The framework is composed of a number of interacting components: security policies and procedures model, a business security goal and targets repository, a set of security measurement processes, a metrics development and analysis process, and a central metrics and measurement model. Lastly a module that derives an overall security posture and generates reports detects trends and develops recommendations. Our approach assists in determining the security posture of an organization, which is becoming a necessity for legal and regulatory compliance.","PeriodicalId":414047,"journal":{"name":"2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-05-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":"{\"title\":\"A Policy-Based Metrics Framework for Information Security Performance Measurement\",\"authors\":\"C. Martin, M. Refai\",\"doi\":\"10.1109/BDIM.2007.375016\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In this article we are proposing a new approach to measure and monitor overall IT security performance. This approach is based on a policy-based frame work that establishes a methodology to measure security performance; it also incorporates a policy performance indicator. The framework is composed of a number of interacting components: security policies and procedures model, a business security goal and targets repository, a set of security measurement processes, a metrics development and analysis process, and a central metrics and measurement model. Lastly a module that derives an overall security posture and generates reports detects trends and develops recommendations. Our approach assists in determining the security posture of an organization, which is becoming a necessity for legal and regulatory compliance.\",\"PeriodicalId\":414047,\"journal\":{\"name\":\"2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2007-05-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"8\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/BDIM.2007.375016\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 2nd IEEE/IFIP International Workshop on Business-Driven IT Management","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BDIM.2007.375016","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
A Policy-Based Metrics Framework for Information Security Performance Measurement
In this article we are proposing a new approach to measure and monitor overall IT security performance. This approach is based on a policy-based frame work that establishes a methodology to measure security performance; it also incorporates a policy performance indicator. The framework is composed of a number of interacting components: security policies and procedures model, a business security goal and targets repository, a set of security measurement processes, a metrics development and analysis process, and a central metrics and measurement model. Lastly a module that derives an overall security posture and generates reports detects trends and develops recommendations. Our approach assists in determining the security posture of an organization, which is becoming a necessity for legal and regulatory compliance.