Visible to the public A Process Framework for Stakeholder-Specific Visualization of Security Metrics

TitleA Process Framework for Stakeholder-Specific Visualization of Security Metrics
Publication TypeConference Paper
Year of Publication2018
AuthorsHanauer, Tanja, Hommel, Wolfgang, Metzger, Stefan, Pöhn, Daniela
Conference NameProceedings of the 13th International Conference on Availability, Reliability and Security
PublisherACM
ISBN Number978-1-4503-6448-5
KeywordsCollaboration, composability, Human Behavior, human factors, Information security, information theoretic security, Metrics, policy-based governance, pubcrawl, resilience, Resiliency, Scalability, Visualization of Security-Related Data
Abstract

Awareness and knowledge management are key components to achieve a high level of information security in organizations. However, practical evidence suggests that there are significant discrepancies between the typical elements of security awareness campaigns, the decisions made and goals set by top-level management, and routine operations carried out by systems administration personnel. This paper presents Vis4Sec, a process framework for the generation and distribution of stakeholder-specific visualizations of security metrics, which assists in closing the gap between theoretical and practical information security by respecting the different points of view of the involved security report audiences. An implementation for patch management on Linux servers, deployed at a large data center, is used as a running example.

URLhttps://dl.acm.org/citation.cfm?doid=3230833.3232855
DOI10.1145/3230833.3232855
Citation Keyhanauer_process_2018