DocumentCode
3369211
Title
Towards a Security Metrics Taxonomy for the Information and Communication Technology Industry
Author
Savola, Reijo
Author_Institution
VTT Tech. Res. Centre of Finland, Oulu
fYear
2007
fDate
25-31 Aug. 2007
Firstpage
60
Lastpage
60
Abstract
To obtain evidence of the security of different products or organizations, systematic approaches to measuring security are needed. We introduce a high abstraction level taxonomy to support the development of feasible security metrics, along with a survey of the emerging security metrics from the academic, governmental and industrial perspectives. With our taxonomy, we strive to bridge the gap between information security management and ICT products, and services security engineering. We believe that if common metrics approaches between different security disciplines can be found, this will advance our holistic understanding and capabilities, both in security management and engineering. Our taxonomy is based on comparing earlier taxonomy approaches and analyzing types of security metrics. Based on the survey, a discussion of future research directions is given in order to prompt advances in the field.
Keywords
DP industry; DP management; security of data; information and communication technology industry; information security management; security metrics; Bridges; Communication industry; Communication system security; Communications technology; Current measurement; Engineering management; Information management; Information security; Proposals; Taxonomy;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering Advances, 2007. ICSEA 2007. International Conference on
Conference_Location
Cap Esterel
Print_ISBN
0-7695-2937-2
Electronic_ISBN
978-0-7695-2937-0
Type
conf
DOI
10.1109/ICSEA.2007.79
Filename
4299940
Link To Document