Relationships Between Security Management and Technical Security of Norwegian Energy Entities
摘要
Security management standards such as ISO/IEC 27001 and NIST Cybersecurity Framework are common approaches to audit cybersecurity compliance and maturity. Little is known about how well such security management audits reflect an entity’s technical security performance. Such relationships are, however, important to understand, as the performance of for example patch management and email security may be crucial to stop adversaries. This study is a correlation analysis applying Pearsons r and Spearmans \(\rho \) to test relationships between managerial and technical security. Our analysis was based on a scoring of 20 managerial and 22 technical security categories from 67 entities in the Norwegian energy sector. Our analysis did not show any clear correlation between the tested management scores and technical scores. Through factor analysis, we identified significant weak negative correlation between 8 security configuration categories and 3 security culture categories. Because the only identified correlation was negative, both security management and technical security should be assessed during audits.