SoK: Linking information security metrics to management success factors

Rainer Diesch, Helmut Krcmar

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

Information security metrics are used to measure the effectiveness of information security countermeasures. A large number of metrics and their technical nature creates difficulties when generating reports for the information security management level of an organization. Managers struggle with the usefulness and clarity of the metrics because they are not linked to the security management goals. Also, responsible managers with no technical information security background struggle to understand the metrics. Therefore, this study uses a state-of-the-art literature analysis together with the Goal-Question-Metric approach to investigate linking technical security metrics to management success factors. This study enables the management to design appropriate security reports for their organization and to direct the metrics toward making goal-oriented decisions. Furthermore, the study invites future research by revealing areas in which security metrics do not exist and create new solutions and studies to suggest a standardized information security dashboard.

Original languageEnglish
Title of host publicationProceedings of the 15th International Conference on Availability, Reliability and Security, ARES 2020
PublisherAssociation for Computing Machinery
ISBN (Electronic)9781450388337
DOIs
StatePublished - 25 Aug 2020
Event15th International Conference on Availability, Reliability and Security, ARES 2020 - Virtual, Online, Ireland
Duration: 25 Aug 202028 Aug 2020

Publication series

NameACM International Conference Proceeding Series

Conference

Conference15th International Conference on Availability, Reliability and Security, ARES 2020
Country/TerritoryIreland
CityVirtual, Online
Period25/08/2028/08/20

Keywords

  • Goal-question-metric approach
  • Information security metrics
  • Security management success factors
  • Systematic literature review

Fingerprint

Dive into the research topics of 'SoK: Linking information security metrics to management success factors'. Together they form a unique fingerprint.

Cite this