Developing a Framework for Evaluating Organizational Information Assurance Metrics Programs

Abstract

The push to secure organizational information has brought about the need to develop better metrics for understanding the state of the organization's security capability. This thesis utilizes case studies of information security metrics programs within Department of Defense organizations, the United States Air Force (USAF), and the National Aeronautics and Space Administration's (NASA's) Jet Propulsion Lab to discover how these organizations make decisions about how the measurement program is designed, how information is collected and disseminated, and how the collected information supports decision making. This research finds that both the DOD and USAF have highly complex information security programs that are primarily focused on determining the return for security investments, meeting budget constraints, and achieving mission objectives while NASA's Jet Propulsion Lab seeks to improve security processes related to compliance. While the analytical techniques were similar in all of the cases, the DOD and USAF use communication processes still based mostly on manual data calls and communications. In contrast, NASA's JPL information security metrics program employs a more automated approach for information collection and dissemination.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 01, 2007
Accession Number
ADA467367

Entities

People

  • Adam R. Bryant

Organizations

  • Air Force Institute of Technology

Tags

Communities of Interest

  • C4I
  • Cyber
  • Materials and Manufacturing Processes
  • Weapons Technologies

DTIC Thesaurus Topics

  • Air Force
  • Business Administration
  • Case Studies
  • Commerce
  • Computer Programs
  • Control Systems
  • Cybersecurity
  • Department Of Defense
  • Information Assurance
  • Information Security
  • Jet Propulsion
  • Reliability
  • Risk
  • Risk Analysis
  • Security
  • Standards
  • Vulnerability

Fields of Study

  • Computer science

Readers

  • Cybersecurity.
  • Systems Analysis and Design
  • Technical Research and Report Writing.

Technology Areas

  • Space