Visible to the public Aggregation of Security Metrics for Decision Making: A Reference Architecture

TitleAggregation of Security Metrics for Decision Making: A Reference Architecture
Publication TypeConference Paper
Year of Publication2018
AuthorsAhmed, Yussuf, Naqvi, Syed, Josephs, Mark
Conference NameProceedings of the 12th European Conference on Software Architecture: Companion Proceedings
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6483-6
KeywordsInformation security, Metrics, Network security, pubcrawl, reference architecture, security measurements, security metrics
AbstractExisting security technologies play a significant role in protecting enterprise systems but they are no longer enough on their own given the number of successful cyberattacks against businesses and the sophistication of the tactics used by attackers to bypass the security defences. Security measurement is different to security monitoring in the sense that it provides a means to quantify the security of the systems while security monitoring helps in identifying abnormal events and does not measure the actual state of an infrastructure's security. The goal of enterprise security metrics is to enable understanding of the overall security using measurements to guide decision making. In this paper we present a reference architecture for aggregating the measurement values from the different components of the system in order to enable stakeholders to see the overall security state of their enterprise systems and to assist with decision making. This will provide a newer dimension to security management by shifting from security monitoring to security measurement.
URLhttp://doi.acm.org/10.1145/3241403.3241458
DOI10.1145/3241403.3241458
Citation Keyahmed_aggregation_2018