Adaptable Security Maturity Assessment and Standardization for Digital SMEs

被引:7
作者
Ozkan, Bilge Yigit [1 ]
Spruit, Marco [1 ,2 ,3 ]
机构
[1] Univ Utrecht, Utrecht, Netherlands
[2] Leiden Univ, Med Ctr, Leiden, Netherlands
[3] Leiden Univ, Leiden, Netherlands
基金
欧盟地平线“2020”;
关键词
Cybersecurity; information security; SME; maturity; standardization; DESIGN SCIENCE RESEARCH; INFORMATION; MODEL; MANAGEMENT;
D O I
10.1080/08874417.2022.2119442
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Small and Medium-sized Enterprises (SMEs) constitute a very large part of every country's economy and play an essential role in economic growth and social development. SMEs are frequent targets of cyberattacks. Unlike large enterprises, SMEs generally have limited capabilities regarding cybersecurity practices. Assessment and improvement of cybersecurity capabilities are crucial for SMEs to survive and sustain their operations. Despite the availability of maturity assessment models and standards to assess and improve cybersecurity capabilities, SMEs' specific requirements and roles in the digital ecosystem are often neglected. This paper presents high-level SME requirements regarding cybersecurity maturity assessment and standardization and translates them into an Adaptable Security Maturity Assessment and Standardization (ASMAS) framework to address this gap. The framework is demonstrated by a web-based software prototype. In the evaluation study conducted with SMEs, we obtained positive results for perceived usefulness, perceived ease of use of the framework, and intention to use it.
引用
收藏
页码:965 / 987
页数:23
相关论文
共 73 条
[1]  
Akinsanya OO., 2019, Current Cybersecurity Maturity Models: How Effective in Healthcare Cloud?
[2]  
[Anonymous], 2018, Drivers of Philippine SME Competitiveness: Results of the 2018 SME Survey
[3]  
[Anonymous], 2013, ISO/IEC 27002:2013
[4]  
[Anonymous], 2013, ISO/IEC 27001
[5]  
Barlette Y., 2008, Hawaii International Conference on System Sciences, Proceedings of the 41st Annual, P308, DOI DOI 10.1109/HICSS.2008.167
[6]  
Barrett Matthew P., 2018, Framework for Improving Critical Infrastructure Cybersecurity, DOI [10.6028/NIST.CSWP.04162018, DOI 10.6028/NIST.CSWP.04162018, DOI 10.1109/JPROC.2011.2165269]
[7]   Calculated risk? A cybersecurity evaluation tool for SMEs [J].
Benz, Michael ;
Chatterjee, Dave .
BUSINESS HORIZONS, 2020, 63 (04) :531-540
[8]  
Blanchette S., 2018, SELF ASSESSMENT CMMI, DOI [10.1184/R1/6583784.v1, DOI 10.1184/R1/6583784.V1]
[9]  
Cebula J.J., 2014, A taxonomy of operational cyber security risks version 2
[10]  
Center for Internet Security, 2018, CIS CONTR