• DocumentCode
    2545409
  • Title

    Information Security Risk Assessment and Pointed Reporting: Scalable Approach

  • Author

    Bhilare, D.S. ; Ramani, A.K. ; Tanwani, Sanjay

  • Author_Institution
    Sch. of Comput. Sci., Devi Ahilya Univ., Indore
  • Volume
    1
  • fYear
    2009
  • fDate
    22-24 Jan. 2009
  • Firstpage
    365
  • Lastpage
    370
  • Abstract
    Network managers of Higher Educational Institutes, are well aware of general information security issues, related to campus networks. There are well developed security metrics, giving exhaustive list of security controls, required to mitigate different risks. Accordingly, various security measures and technologies are being deployed. However, at present, not enough attention is being paid on measuring the effectiveness of these controls and overall state of security in the institution. In this study, attempt is made to build a metric based assessment and reporting plan, specific to the needs of an academic environment. Proposed assessment metric facilitates iterative implementation, by prioritizing each metric. Secondly, to reduce response time, a novel approach of pointed reporting is suggested, where responsibilities are distributed across the institution, based on relevant roles. In this approach, security exceptions are reported directly to the predefined roles, responsible for that particular security control. This pointed reporting, delivers message to the right person in minimum time, resulting in improved response time. The proposed assessment metric and pointed reporting structure, will improve overall security governance. As security measures and practices can be assessed systematically and remedial actions can be taken in less time, which is so crucial for effective security governance.
  • Keywords
    educational institutions; risk management; security of data; academic environment; campus network; information security; metric based assessment; pointed reporting; reporting plan; risk assessment; security control; security exception; security governance; security measures; security metrics; Collaborative software; Computer network management; Computer science; Delay; Electronic mail; Hardware; Information security; Microprogramming; Risk management; Time measurement; distributed defense; information security; iterative implementation; pointed reporting; security assessment;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Engineering and Technology, 2009. ICCET '09. International Conference on
  • Conference_Location
    Singapore
  • Print_ISBN
    978-1-4244-3334-6
  • Type

    conf

  • DOI
    10.1109/ICCET.2009.218
  • Filename
    4769490