Organizational Characteristics Influencing SME Information Security Maturity
2016
AbstractIn the current business environment, many organizations use popular standards such as the ISO 27000x series, COBIT, and related frameworks to protect themselves against security incidents. However, these standards and frameworks are overly complicated for small to medium-sized enterprises, leaving these organizations with no easy to understand toolkit to address their security needs. This research builds upon the recent Information Security Focus Area Maturity (ISFAM) model for SME information security as a cornerstone in the development of an assessment tool for tailor-made, fast, and easy-to-use information security advice for SMEs. By performing an extensive literature review and evaluating the results with security experts, we propose the Characterizing Organizations’ Information Security for SMEs (CHOISS) model to relate measurable organizational characteristics in four categories through 47 parameters to help SMEs distinguish and prioritize which risks to mitigate.
Keywords:
- Security information and event management
- Information security
- Knowledge management
- Information security audit
- Marketing
- Standard of Good Practice
- Computer science
- Information security standards
- Information security management
- ITIL security management
- Certified Information Security Manager
- COBIT
- Information security management system
- Correction
- Source
- Cite
- Save
- Machine Reading By IdeaReader
33
References
23
Citations
NaN
KQI