DocumentCode :
2545409
Title :
Information Security Risk Assessment and Pointed Reporting: Scalable Approach
Author :
Bhilare, D.S. ; Ramani, A.K. ; Tanwani, Sanjay
Author_Institution :
Sch. of Comput. Sci., Devi Ahilya Univ., Indore
Volume :
1
fYear :
2009
fDate :
22-24 Jan. 2009
Firstpage :
365
Lastpage :
370
Abstract :
Network managers of Higher Educational Institutes, are well aware of general information security issues, related to campus networks. There are well developed security metrics, giving exhaustive list of security controls, required to mitigate different risks. Accordingly, various security measures and technologies are being deployed. However, at present, not enough attention is being paid on measuring the effectiveness of these controls and overall state of security in the institution. In this study, attempt is made to build a metric based assessment and reporting plan, specific to the needs of an academic environment. Proposed assessment metric facilitates iterative implementation, by prioritizing each metric. Secondly, to reduce response time, a novel approach of pointed reporting is suggested, where responsibilities are distributed across the institution, based on relevant roles. In this approach, security exceptions are reported directly to the predefined roles, responsible for that particular security control. This pointed reporting, delivers message to the right person in minimum time, resulting in improved response time. The proposed assessment metric and pointed reporting structure, will improve overall security governance. As security measures and practices can be assessed systematically and remedial actions can be taken in less time, which is so crucial for effective security governance.
Keywords :
educational institutions; risk management; security of data; academic environment; campus network; information security; metric based assessment; pointed reporting; reporting plan; risk assessment; security control; security exception; security governance; security measures; security metrics; Collaborative software; Computer network management; Computer science; Delay; Electronic mail; Hardware; Information security; Microprogramming; Risk management; Time measurement; distributed defense; information security; iterative implementation; pointed reporting; security assessment;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Engineering and Technology, 2009. ICCET '09. International Conference on
Conference_Location :
Singapore
Print_ISBN :
978-1-4244-3334-6
Type :
conf
DOI :
10.1109/ICCET.2009.218
Filename :
4769490
Link To Document :
بازگشت