Cyber KPI for Return on Security Investment

被引:0
作者
Onwubiko, Cyril [1 ]
Onwubiko, Austine [2 ]
机构
[1] Res Series Ltd, E Secur Grp, Cyber Secur Intelligence, London, England
[2] Univ West Scotland UWS, Sch Comp Engn & Phys Sci, Informat & Network Secur, Paisley, Renfrew, Scotland
来源
2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA) | 2019年
关键词
Cyber KPI; Return on Security Investment; RoSI; Rol; Return on Investment; Metrics; Cyber-attack; Cyber Security; Cyber Incidents;
D O I
10.1109/cybersa.2019.8899375
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber security return on investment (Rol) or return on security investment (RoSI) is extremely challenging to measure. This is partly because it is difficult to measure the actual cost of a cyber security incident or cyber security proceeds. This is further complicated by the fact that there are no consensus metrics that every organisation agrees to, and even among cyber subject matter experts, there are no set of agreed parameters or metric upon which cyber security benefits or rewards can be assessed against. One approach to demonstrating return on security investment is by producing cyber security reports of certain key performance indicators (KPI) and metrics, such as number of cyber incidents detected, number of cyberattacks or terrorist attacks that were foiled, or ongoing monitoring capabilities. These are some of the demonstratable and empirical metrics that could be used to measure RoSI. In this abstract paper, we investigate some of the cyber KPIs and metrics to be considered for cyber dashboard and reporting for RoSI.
引用
收藏
页数:8
相关论文
共 13 条
[1]  
Australia Cyber Security Strategy, 2016, AUSTR CYB SEC STRAT
[2]  
Cabinet Office, 2017, INT CYB SEC SCI TECH
[3]  
CiSP, 2019, CYB SEC INF SHAR PAR
[4]  
CSEurope, 2019, FEAT CYB SEC RET INV
[5]  
European Network and Information Security Agency (ENISA), 2012, INTR RET SEC INV HEL
[6]  
GCHQ, 2018, INDEPENDENT
[7]  
Investopedia, 2019, RET INV
[8]  
NCSC, 2016, CYB SEC GUID BUS
[9]  
NCSC, 2016, 10 STEPS CYB SEC
[10]  
NCSC, 2017, CYB ESS SCHEM