DocumentCode
633021
Title
A new method for the identification of proactive information security management system metrics
Author
Hajdarevic, Kemal ; Allen, Peter
Author_Institution
Fac. of Electr. Eng., Univ. of Sarajevo, Sarajevo, Bosnia-Herzegovina
fYear
2013
fDate
20-24 May 2013
Firstpage
1121
Lastpage
1126
Abstract
Information security is topic of everyday interest, with mainstream media reports revealing information security incidents in many different areas. These reports demonstrate the importance to any organization of having an information security management system (ISMS). Foreseeing potential security risks is usually key to successful risk management. Available information security standards such as the ISO 27000 set of standards give a formal framework for successful information security management in any size of organisation or company. In this paper we draw on experience gained during a project leading to successful ISO 27001 certification at the Central Bank of Bosnia and Herzegovina in 2009. We review recent work on proactive damage prevention, and we propose methodology based on the GQM (Goal, Question, Metrics) paradigm for determining proactive steps for detection and resolution of different information security control violations. For creating proactive measurement metrics we use the well recognised standards ISO 27004:2009, and NIST 800-55. We present several examples of proactive metrics.
Keywords
ISO standards; bank data processing; computer crime; risk management; software metrics; Central Bank of Bosnia; Central Bank of Herzegovina; GQM paradigm; ISMS; ISO 27000; ISO 27001 certification; ISO 27004:2009; NIST 800-55; cyber crime; cyber warfare; data corruption; data thefts; goal-question-metrics paradigm; information security control violation detection; information security control violation resolution; information security incidents; information security standards; media reports; potential security risks; proactive damage prevention; proactive information security management system metrics; risk management; Availability; ISO standards; Information security; Measurement; Monitoring; NIST;
fLanguage
English
Publisher
ieee
Conference_Titel
Information & Communication Technology Electronics & Microelectronics (MIPRO), 2013 36th International Convention on
Conference_Location
Opatija
Print_ISBN
978-953-233-076-2
Type
conf
Filename
6596425
Link To Document