Cargando…

A real-world information security performance assessment using a multidimensional socio-technical approach

Measuring the performance of information security is an essential part of the information security management system within organisations. Studies in the past mainly focused on establishing qualitative measurement approaches. Since these can lead to ambiguous conclusions, quantitative metrics are be...

Descripción completa

Detalles Bibliográficos
Autores principales: Prislan, Kaja, Mihelič, Anže, Bernik, Igor
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7478844/
https://www.ncbi.nlm.nih.gov/pubmed/32898183
http://dx.doi.org/10.1371/journal.pone.0238739
_version_ 1783580145460707328
author Prislan, Kaja
Mihelič, Anže
Bernik, Igor
author_facet Prislan, Kaja
Mihelič, Anže
Bernik, Igor
author_sort Prislan, Kaja
collection PubMed
description Measuring the performance of information security is an essential part of the information security management system within organisations. Studies in the past mainly focused on establishing qualitative measurement approaches. Since these can lead to ambiguous conclusions, quantitative metrics are being increasingly proposed as a useful alternative. Nevertheless, the literature on quantitative approaches remains scarce. Thus, studies on the evaluation of information security performance are challenging, especially since many approaches are not tested in organisational settings. The paper aims to validate the model used for evaluating the performance of information security management system through a multidimensional socio-technical approach, in a real-world settings among medium-sized enterprises in Slovenia. The results indicate that information security is strategically defined and compliant, however, measures are primarily implemented at technical and operational levels, while its strategic management remains underdeveloped. We found that the biggest issues are related to information resources and risk management, where information security measurement-related activities proved to be particularly problematic. Even though enterprises do possess certain information security capabilities and are aware of the importance of information security, their current practices make it difficult for them to keep up with the fast-paced technological and security trends.
format Online
Article
Text
id pubmed-7478844
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-74788442020-09-18 A real-world information security performance assessment using a multidimensional socio-technical approach Prislan, Kaja Mihelič, Anže Bernik, Igor PLoS One Research Article Measuring the performance of information security is an essential part of the information security management system within organisations. Studies in the past mainly focused on establishing qualitative measurement approaches. Since these can lead to ambiguous conclusions, quantitative metrics are being increasingly proposed as a useful alternative. Nevertheless, the literature on quantitative approaches remains scarce. Thus, studies on the evaluation of information security performance are challenging, especially since many approaches are not tested in organisational settings. The paper aims to validate the model used for evaluating the performance of information security management system through a multidimensional socio-technical approach, in a real-world settings among medium-sized enterprises in Slovenia. The results indicate that information security is strategically defined and compliant, however, measures are primarily implemented at technical and operational levels, while its strategic management remains underdeveloped. We found that the biggest issues are related to information resources and risk management, where information security measurement-related activities proved to be particularly problematic. Even though enterprises do possess certain information security capabilities and are aware of the importance of information security, their current practices make it difficult for them to keep up with the fast-paced technological and security trends. Public Library of Science 2020-09-08 /pmc/articles/PMC7478844/ /pubmed/32898183 http://dx.doi.org/10.1371/journal.pone.0238739 Text en © 2020 Prislan et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Prislan, Kaja
Mihelič, Anže
Bernik, Igor
A real-world information security performance assessment using a multidimensional socio-technical approach
title A real-world information security performance assessment using a multidimensional socio-technical approach
title_full A real-world information security performance assessment using a multidimensional socio-technical approach
title_fullStr A real-world information security performance assessment using a multidimensional socio-technical approach
title_full_unstemmed A real-world information security performance assessment using a multidimensional socio-technical approach
title_short A real-world information security performance assessment using a multidimensional socio-technical approach
title_sort real-world information security performance assessment using a multidimensional socio-technical approach
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7478844/
https://www.ncbi.nlm.nih.gov/pubmed/32898183
http://dx.doi.org/10.1371/journal.pone.0238739
work_keys_str_mv AT prislankaja arealworldinformationsecurityperformanceassessmentusingamultidimensionalsociotechnicalapproach
AT mihelicanze arealworldinformationsecurityperformanceassessmentusingamultidimensionalsociotechnicalapproach
AT bernikigor arealworldinformationsecurityperformanceassessmentusingamultidimensionalsociotechnicalapproach
AT prislankaja realworldinformationsecurityperformanceassessmentusingamultidimensionalsociotechnicalapproach
AT mihelicanze realworldinformationsecurityperformanceassessmentusingamultidimensionalsociotechnicalapproach
AT bernikigor realworldinformationsecurityperformanceassessmentusingamultidimensionalsociotechnicalapproach