An approach to information system security assessment

Chien-Hua Mike Lin, Shu-Chuan Chao · 2005

As the tremendous growth of networks and e-business changes the nature of traditional information security threats, the capability to provide prompt and accurate information to authorized users boosts the competitive power of an organization. In addition to the threats, organizations face complex requirements in complying with security and privacy regulations. These conditions force organizations to seek more robust information security systems. An effective information security program, requires periodic security assessments. This study aims to develop an information security assessment model to evaluate the security level of an information security system. Based on respondents' comments, we choose higher education institutions as survey subjects. Utilizing literature reviews, information security standards, best practices, and information security assessment guides, we have formed the essential components of our information security assessment model. These components are organized as a two-layer structure---security controls and sub-security controls. In order to validate this model, we conducted two field studies and one web-survey. Based on the comments and number of responses, we chose higher education institutions as the survey subject for this study. The results of this study identify the different importance levels of security controls and sub-security controls. This model offers an improved security evaluation metric over extant methods. It also provides a potential baseline for the standard of information security metric. In this research, it does not only verify the varying importance levels of security controls and sub-security controls among different types of institutions but also in different sizes of organizations. This study also establishes a framework for information security assessment models for industries.

Read the paper · More papers on PaperTik