科技报告详细信息
Methodology for Evaluating Security Controls Based on Key Performance Indicators and Stakeholder Mission.
Technical Information Center Oak Ridge Tennessee
关键词: Information security;    Security controls;    Evaluation;    Methodology;    Key performance indicators;   
RP-ID  :  DE2009946487
学科分类:工程和技术(综合)
美国|英语
来源: National Technical Reports Library
PDF
【 摘 要 】

Information security continues to evolve in response to disruptive changes with a persistent focus on information-centric controls and a healthy debate about balancing endpoint and network protection, with a goal of improved enterprise/business risk management. Economic uncertainty, intensively collaborative styles of work, virtualization, increased outsourcing and ongoing compliance pressures require careful consideration and adaptation. This paper proposes a Cyberspace Security Econometrics System (CSES) that provides a measure (i.e., a quantitative indication) of reliability, performance and/or safety of a system that accounts for the criticality of each requirement as a function of one or more stakeholders' interests in that requirement. For a given stakeholder, CSES reflects the variance that may exist among the stakes she/he attaches to meeting each requirement. This paper introduces the basis, objectives and capabilities for the CSES including inputs/outputs as well as the structural and mathematical underpinnings.

【 预 览 】
附件列表
Files Size Format View
DE2009946487.pdf 2110KB PDF download
  文献评价指标  
  下载次数:26次 浏览次数:31次