Vis enkel innførsel

dc.contributor.advisorKnapskog, Svein Johannb_NO
dc.contributor.advisorVidhammer, Gjermundnb_NO
dc.contributor.authorSkaaland, Sirinb_NO
dc.date.accessioned2014-12-19T14:11:54Z
dc.date.available2014-12-19T14:11:54Z
dc.date.created2010-09-02nb_NO
dc.date.issued2008nb_NO
dc.identifier347027nb_NO
dc.identifierntnudaim:4192nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/261608
dc.description.abstractWith an increasing need for information security in IT the need for measuring is present to display the improvement and development of your information security over time. No best practice has been accepted in the area. ISO/IEC 27001 - textit{Information technology - Security techniques - Information security management systems - Requirements} requires measuring of effectiveness of both management system and controls implemented. A new standard ISO/IEC 27004 textit{Information technology - Security techniques - Information security management - Measurements} is under development to address this requirement, but is not scheduled for publication until 2009. This report has aimed to evaluate the draft ISO/IEC 3rd CD 27004, both in relation to requirements of ISO/IEC 27001 and also in relation to measuring of the effectiveness of information security controls in general. Research conducted to gain results has been consisting of investigation of measuring solutions within different organizations certified toward ISO/IEC 27001, interviews with individuals familiar with measuring in these environments and also research of published material covering the subject. Conclusions of this study has shown that the requirement of measuring the effectiveness of the management system and not only the controls has been overseen by many. Further the different solutions found has been much simpler than the proposed solutions depicted in ISO/IEC 3rd CD 27004, which indicates two things. Both that if the draft becomes a standard and the standard then becomes normative, then the task of upgrading the solutions to adhere to it may be difficult, and in that the draft is too extensive and unnecessarily complex for smaller organizations. The fact that several organizations have been certified toward ISO/IEC 27001, without having measuring implemented in a good way, is concerning. The main driver behind measuring the effectiveness of information security controls seems to be a required need for measuring, like compliance with standards, not the benefits from measuring. The benefits could however be many with a good measuring implementation, but this requires better visualization of the drivers.nb_NO
dc.languageengnb_NO
dc.publisherInstitutt for telematikknb_NO
dc.subjectntnudaimno_NO
dc.subjectSIE7 kommunikasjonsteknologino_NO
dc.subjectTelematikkno_NO
dc.titleMeasuring the effectiveness of information security controlsnb_NO
dc.typeMaster thesisnb_NO
dc.source.pagenumber125nb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for telematikknb_NO


Tilhørende fil(er)

Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel