DocumentCode
2545409
Title
Information Security Risk Assessment and Pointed Reporting: Scalable Approach
Author
Bhilare, D.S. ; Ramani, A.K. ; Tanwani, Sanjay
Author_Institution
Sch. of Comput. Sci., Devi Ahilya Univ., Indore
Volume
1
fYear
2009
fDate
22-24 Jan. 2009
Firstpage
365
Lastpage
370
Abstract
Network managers of Higher Educational Institutes, are well aware of general information security issues, related to campus networks. There are well developed security metrics, giving exhaustive list of security controls, required to mitigate different risks. Accordingly, various security measures and technologies are being deployed. However, at present, not enough attention is being paid on measuring the effectiveness of these controls and overall state of security in the institution. In this study, attempt is made to build a metric based assessment and reporting plan, specific to the needs of an academic environment. Proposed assessment metric facilitates iterative implementation, by prioritizing each metric. Secondly, to reduce response time, a novel approach of pointed reporting is suggested, where responsibilities are distributed across the institution, based on relevant roles. In this approach, security exceptions are reported directly to the predefined roles, responsible for that particular security control. This pointed reporting, delivers message to the right person in minimum time, resulting in improved response time. The proposed assessment metric and pointed reporting structure, will improve overall security governance. As security measures and practices can be assessed systematically and remedial actions can be taken in less time, which is so crucial for effective security governance.
Keywords
educational institutions; risk management; security of data; academic environment; campus network; information security; metric based assessment; pointed reporting; reporting plan; risk assessment; security control; security exception; security governance; security measures; security metrics; Collaborative software; Computer network management; Computer science; Delay; Electronic mail; Hardware; Information security; Microprogramming; Risk management; Time measurement; distributed defense; information security; iterative implementation; pointed reporting; security assessment;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Engineering and Technology, 2009. ICCET '09. International Conference on
Conference_Location
Singapore
Print_ISBN
978-1-4244-3334-6
Type
conf
DOI
10.1109/ICCET.2009.218
Filename
4769490
Link To Document