EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS
Quality assessment of information security management system is an important step for obtaining baseline data for analysis of the security system control effectiveness, and evaluating implementation of the specified information security requirements of the organization. Proceeding from current ana...
Main Author: | |
---|---|
Format: | Article |
Language: | English |
Published: |
Saint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University)
2014-07-01
|
Series: | Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki |
Subjects: | |
Online Access: | http://ntv.ifmo.ru/file/article/10355.pdf |
_version_ | 1818050727598096384 |
---|---|
author | F. N. Shago |
author_facet | F. N. Shago |
author_sort | F. N. Shago |
collection | DOAJ |
description | Quality assessment of information security management system is an important step for obtaining baseline data for
analysis of the security system control effectiveness, and evaluating implementation of the specified information security
requirements of the organization. Proceeding from current analysis practice of information security management systems
effectiveness assessment, it can be concluded that, in most cases, independent measurement of security control is carried out
without regard to their interaction. The uncertainty of the stochastic nature of the measured security controls is not taken into
account. There is a list of related measures for control and management; however, structural elements for measuring of these
interactions are absent. Thus, there is an important and urgent task of improving the effectiveness assessing methodology for
information security management system that can be solved by introducing a new integral effectiveness indicator of the
system, which would give the possibility to take into account the above-mentioned shortcomings.
The author proposes the usage of a new integral efficiency indicator - system response time to information security incidents.
This efficiency indicator will make it possible to pass from the binary effectiveness assessment of the system "approve or
disapprove" to a quantitative one. New performance indicator gives the possibility to take into account the uncertainty of the
stochastic nature of the attributes and measures of management and control, provides a quantitative assessment of the
information security state and has a clear physical interpretation for the organization management and information security
officers. Dynamics of the indicator change from test to test will assess the information security management system state in
general and effectiveness of taken control and management measures. The method for calculating of the new information
security management system performance indicator is based on the experimental design theory. Its advantages are:
information security service staff has an opportunity to control the attributes measurement, the same accuracy of estimates for
attribute parameters during the measurement is provided, interaction degree between attributes and their importance in the
computation of the effectiveness of information security management |
first_indexed | 2024-12-10T10:58:04Z |
format | Article |
id | doaj.art-cd59ebb14d204169aa42ac369cf7f4c9 |
institution | Directory Open Access Journal |
issn | 2226-1494 2500-0373 |
language | English |
last_indexed | 2024-12-10T10:58:04Z |
publishDate | 2014-07-01 |
publisher | Saint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University) |
record_format | Article |
series | Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki |
spelling | doaj.art-cd59ebb14d204169aa42ac369cf7f4c92022-12-22T01:51:48ZengSaint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University)Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki2226-14942500-03732014-07-01144115123EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTSF. N. ShagoQuality assessment of information security management system is an important step for obtaining baseline data for analysis of the security system control effectiveness, and evaluating implementation of the specified information security requirements of the organization. Proceeding from current analysis practice of information security management systems effectiveness assessment, it can be concluded that, in most cases, independent measurement of security control is carried out without regard to their interaction. The uncertainty of the stochastic nature of the measured security controls is not taken into account. There is a list of related measures for control and management; however, structural elements for measuring of these interactions are absent. Thus, there is an important and urgent task of improving the effectiveness assessing methodology for information security management system that can be solved by introducing a new integral effectiveness indicator of the system, which would give the possibility to take into account the above-mentioned shortcomings. The author proposes the usage of a new integral efficiency indicator - system response time to information security incidents. This efficiency indicator will make it possible to pass from the binary effectiveness assessment of the system "approve or disapprove" to a quantitative one. New performance indicator gives the possibility to take into account the uncertainty of the stochastic nature of the attributes and measures of management and control, provides a quantitative assessment of the information security state and has a clear physical interpretation for the organization management and information security officers. Dynamics of the indicator change from test to test will assess the information security management system state in general and effectiveness of taken control and management measures. The method for calculating of the new information security management system performance indicator is based on the experimental design theory. Its advantages are: information security service staff has an opportunity to control the attributes measurement, the same accuracy of estimates for attribute parameters during the measurement is provided, interaction degree between attributes and their importance in the computation of the effectiveness of information security managementhttp://ntv.ifmo.ru/file/article/10355.pdfinformation securityeffectiveness of information security management systemISMS quality indexISMS efficiency assessment |
spellingShingle | F. N. Shago EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki information security effectiveness of information security management system ISMS quality index ISMS efficiency assessment |
title | EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS |
title_full | EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS |
title_fullStr | EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS |
title_full_unstemmed | EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS |
title_short | EFFECTIVENESS ASSESSMENT METHODOLOGY OF INFORMATION SECURITY MANAGEMENT SYSTEM THROUGH THE SYSTEM RESPONSE TIME TO INFORMATION SECURITY INCIDENTS |
title_sort | effectiveness assessment methodology of information security management system through the system response time to information security incidents |
topic | information security effectiveness of information security management system ISMS quality index ISMS efficiency assessment |
url | http://ntv.ifmo.ru/file/article/10355.pdf |
work_keys_str_mv | AT fnshago effectivenessassessmentmethodologyofinformationsecuritymanagementsystemthroughthesystemresponsetimetoinformationsecurityincidents |