The Robust Measurement Method for Security Metrics Generation

Katarzyna Mazur, Bogdan Ksi̜eżopolski, Zbigniew Kotulski · The Computer Journal · 2014

In the today's world in many organizations, the information security management is one of the most important tasks to be done. Among the tasks which must be considered during security management is that the processes need to be monitored and verified. In the article, we introduce a new security measurement model which extends the approach presented in the ISO/IEC 27004 with measurements validation methods. The presented method generates the security metrics which are robust and reproductable. Our approach systematizes and organizes security metrics development process focusing on the performance and the security of systems, products, processes and services. We also present the Crypto-Metrics Tool (CMTool) which prepares the benchmarking and validates obtained results according to the proposed method. Finally, we present the case study of the proposed method for generating robust benchmarking of the cryptographic modules by means of the CMTool.

Read the paper · More papers on PaperTik