Skip to main content
QUICK REVIEW

[论文解读] An Adaptable Maturity Strategy for Information Security

Gliner Dias Alencar, Hermano Perrelli de Moura|arXiv (Cornell University)|Jul 17, 2018
Information and Cyber Security参考文献 15被引用 4
一句话总结

本文提出了一种可适应的信息安全成熟度策略,该策略基于来自157家组织的输入,将ISO/IEFC 27001和27002控制措施划分为四个优先级阶段。通过整合COBIT成熟度级别和风险分析矩阵,该策略能够实现安全措施的定制化实施与优先级排序,并在实际公司环境中成功验证。

ABSTRACT

The lack of security in information systems has caused numerous financial and moral losses to several organizations. The organizations have a series of information security measures recommended by literature and international standards. However, the implementation of policies, actions, and adjustment to such standards is not simple and must be addressed by specific needs identified by the Information Security Governance in each organization. There are many challenges in effectively establishing, maintaining, and measuring information security in a way that adds value. Those challenges demonstrate a need for further investigations which address the problem. This paper presents a strategy to measure the maturity in information security aiming, also, to assist in the application and prioritization of information security actions in the corporate environment. For this, a survey was used as the main methodological instrument, reaching 157 distinct companies. As a result, it was possible to classify the ISO/IEC 27001 and 27002 controls in four stages according to the importance given by the companies. The COBIT maturity levels and a risk analysis matrix were also used. Finally, the adaptable strategy was successfully tested in a company

研究动机与目标

  • 解决在多样化组织中有效衡量、实施和优先排序信息安全控制措施的挑战。
  • 基于真实组织的反馈,识别ISO/IEC 27001和27002控制措施的相对重要性。
  • 开发一种灵活的成熟度策略,支持与组织需求和风险状况相匹配的定制化安全实施。
  • 通过在企业环境中的实际应用,验证该策略的有效性。

提出的方法

  • 对157家公司在内开展调查,以评估各ISO/IEC 27001和27002控制措施的感知重要性。
  • 根据调查结果,将控制措施划分为四个成熟度阶段,反映组织的优先事项。
  • 使用COBIT成熟度级别评估组织内信息安全流程的当前状态。
  • 应用风险分析矩阵评估控制失效的潜在影响和发生概率。
  • 整合框架结合基于调查的优先级排序、COBIT成熟度评估和风险分析,以指导行动规划。
  • 在一家真实公司中测试该策略,以评估其实际适用性和有效性。

实验结果

研究问题

  • RQ1组织在实践中如何对ISO/IEC 27001和27002的信息安全控制措施进行优先排序?
  • RQ2哪些因素影响不同组织对特定安全控制措施的感知重要性?
  • RQ3如何将COBIT成熟度级别与风险分析相结合,以指导安全控制措施的优先排序?
  • RQ4该成熟度策略在多大程度上可适应单个组织的独特需求?
  • RQ5该策略在指导真实企业环境中安全措施实施方面的有效性如何?

主要发现

  • 调查显示,各组织在优先排序ISO/IEC 27001和27002控制措施方面存在显著差异,表明不存在“一刀切”的方法。
  • 基于组织输入,成功地将控制措施划分为四个成熟度阶段,反映出不同行业和企业规模之间的优先事项差异。
  • 将COBIT成熟度级别与风险分析相结合,提供了一种结构化的方法,用于评估和指导安全改进工作。
  • 该可适应的策略实现了安全措施的针对性实施,提高了与组织风险状况和治理需求的一致性。
  • 该策略在一家真实公司中成功得到验证,证明了其在指导安全成熟度发展方面的实际可行性与价值。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。