Effective Measurement Requirements for Network Security Management
Rabiah Ahmad, Shahrin Sahib, Muhamad Pahri Nor'Azuwa

TL;DR
This paper introduces a model for measuring the effectiveness of network security management using technical security metrics based on the Goal-Question-Metric paradigm, aligning with ISO/IEC 27001 standards.
Contribution
It proposes a new Technical Security Metric model specifically for network security controls and services, enhancing measurement clarity and compliance guidance.
Findings
Introduces a network security management metric within the TSM model.
Aligns security measurement with ISO/IEC 27001 standards.
Provides a comprehensive framework for effective security control evaluation.
Abstract
Technical security metrics provide measurements in ensuring the effectiveness of technical security controls or technology devices/objects that are used in protecting the information systems. However, lack of understanding and method to develop the technical security metrics may lead to unachievable security control objectives and incompetence of the implementation. This paper proposes a model of technical security metric to measure the effectiveness of network security management. The measurement is based on the effectiveness of security performance for (1) network security controls such as firewall, Intrusion Detection Prevention System (IDPS), switch, wireless access point, wireless controllers and network architecture; and (2) network services such as Hypertext Transfer Protocol Secure (HTTPS) and virtual private network (VPN). We use the Goal-Question-Metric (GQM) paradigm [1]…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Web Application Security Vulnerabilities
