skip to main content
10.1145/1314257.1314266acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections
Article

Towards a taxonomy for information security metrics

Published:29 October 2007Publication History

ABSTRACT

Systematic approaches to measuring security are needed in order to obtain evidence of the security performance of products or an organization. In this study we survey the emerging security metrics approaches from the academic, governmental and industrial perspectives and aim to bridge the gap between information security management and Information and Communication Technology (ICT) product security practices. If common metrics approaches between different security disciplines can be found, this will advance our holistic understanding and capabilities, both in management and engineering practices.

References

  1. Bellovin, S. M. On the Brittleness of Software and the Infeasibility of Security Metrics. IEEE Security & Privacy, Jul/Aug, 2006, 96. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Burris, P., King, C. A Few Good Security Metrics. METAGroup, Inc., Oct. 2000.Google ScholarGoogle Scholar
  3. Henning, R. et al. Proc. of Workshop on Information Security System, Scoring and Ranking - Information System Security Attribute Quantification or Ordering, ACSA and MITRE, Williamsburg, Virginia, May 2001, 2002Google ScholarGoogle Scholar
  4. ISO/IEC 17799:2005. Information Technology - Security Techniques - Code of Practice for Information Security Management. ISO, 2005.Google ScholarGoogle Scholar
  5. Jelen, G. SSE-CMM Security Metrics. NIST and CSSPAB Workshop, Washington, D.C., June, 2000.Google ScholarGoogle Scholar
  6. McHugh, J. Quantitative Measures of Assurance: Prophecy, Process or Pipedream? Proc. of Workshop on Information Security System Scoring and Ranking (WISSSR), ACSA and MITRE, Williamsburg, Virginia, May 2001, 2002Google ScholarGoogle Scholar
  7. Payne, S. C. A Guide to Security Metrics. SANS Institute Information Security Reading Room, June, 2006.Google ScholarGoogle Scholar
  8. Seddigh, N., Pieda, P., Matrawy, A., Nandy, B., Lambadaris, I., Hatfield, A. Current Trends and Advances in Information Assurance Metrics. Proc. of the 2nd Ann. Conf. Privacy, Security and Trust (PST 2004), Fredericton, NB, Oct., 2004.Google ScholarGoogle Scholar
  9. Stoddard, M. et al. Process Control System Security Metrics - State of Practice. I3P Institute for Information Infrastructure Protection Research Report No. 1, Aug., 2005.Google ScholarGoogle Scholar
  10. Swanson, M. Security Self-Assessment Guide for Information Technology Systems. NIST Special Publication 800-26, Nov., 2001.Google ScholarGoogle Scholar
  11. Swanson, M., Bartol, N., Sabato, J., Hash, J., Graffo, L. Security Metrics Guide for Information Technology Systems. NIST Special Publication 800-55, Jul., 2003.Google ScholarGoogle Scholar
  12. Vaughn, R., Henning, R. and Siraj, A. Information Assurance Measures and Metrics: State of Practice and Proposed Taxonomy. Proc. of 36th Hawaii Int. Conf. on System Sciences HICSS 03., 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Towards a taxonomy for information security metrics

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      QoP '07: Proceedings of the 2007 ACM workshop on Quality of protection
      October 2007
      64 pages
      ISBN:9781595938855
      DOI:10.1145/1314257

      Copyright © 2007 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 29 October 2007

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • Article

      Upcoming Conference

      CCS '24
      ACM SIGSAC Conference on Computer and Communications Security
      October 14 - 18, 2024
      Salt Lake City , UT , USA

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader