Information Security Metrics: Challenges and Models in an All-Digital World
摘要
The evolution of ICT and the accelerated adoption process in all sectors of activity have revealed immense cybersecurity threats, which can definitively compromise this evolution and with a heavy impact. The problem, the technological and human vulnerabilities, and the possible solutions have been intensely studied and standardised, and it is now widely recognised that cybersecurity is, in essence, a risk management activity. However, to manage something, it is necessary to have metrics, and only a few aspects of cybersecurity are easily and understandably measurable. This article presents a systematic approach to cybersecurity and risk management, emphasising how to obtain appropriate security metrics and focusing on the industrial sector. For this, we use the most well-known standards illustrated with examples extracted from a typical industrial environment. An outline of a taxonomy of metrics and a framework for their identification and application are presented. It also discusses a continuous certification model that derives from the metrics model and aligns with one of the emerging standards to address cybersecurity in industrial environments (ISA/IEC 62443). The article ends by discussing some of the challenges facing the adoption of a metrics program suitable for organisations’ information security objectives.