The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
This research establishes a security evaluation model from the insider leakage perspective and suggests an objective evaluation measurement. Organizational security risks are fused and compounded both inside and outside the organization. Although multiple security controls are implemented to minimiz...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2020-12-01
|
Series: | Sustainability |
Subjects: | |
Online Access: | https://www.mdpi.com/2071-1050/12/24/10639 |
id |
doaj-643446abe1024e68968c34a5f75af90a |
---|---|
record_format |
Article |
spelling |
doaj-643446abe1024e68968c34a5f75af90a2020-12-20T00:02:07ZengMDPI AGSustainability2071-10502020-12-0112106391063910.3390/su122410639The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable GrowthJawon Kim0Chanwoo Lee1Hangbae Chang2Department of Convergence Security, Chung-Ang University, Seoul 06974, KoreaInformation Security & International Business Division, Douzone Forensic Center, Seoul 04523, KoreaDepartment of Industrial Security, Chung-Ang University, Seoul 06974, KoreaThis research establishes a security evaluation model from the insider leakage perspective and suggests an objective evaluation measurement. Organizational security risks are fused and compounded both inside and outside the organization. Although multiple security controls are implemented to minimize an organization’s security risk, effective security control requires management to preemptively check the organization’s security level. Existing criteria for evaluating security level are limited to external security risks and have improper limit points for dealing with security risks that are fused and compounded within an organization. The focus of this study is the prevention of technical information leakage. Furthermore, we propose a method for measuring the level at which the objectivity of certain items is secured. We compiled 26 detailed evaluation items, considering the security requirements to prevent technical information leakage. We not only performed suitability, reliability, and factor analyses and statistical validation, but also established a method to measure the security level. This measurement method ensures the effectiveness and objectivity of the evaluation of security level, mitigating the risks of security incidents caused by insiders. The results serve as a reference for organizations when designing security evaluation criteria and automated tools based on our evaluation model for future research.https://www.mdpi.com/2071-1050/12/24/10639insider threatinformation leakage protectionsecurity evaluationsustainable growth |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Jawon Kim Chanwoo Lee Hangbae Chang |
spellingShingle |
Jawon Kim Chanwoo Lee Hangbae Chang The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth Sustainability insider threat information leakage protection security evaluation sustainable growth |
author_facet |
Jawon Kim Chanwoo Lee Hangbae Chang |
author_sort |
Jawon Kim |
title |
The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth |
title_short |
The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth |
title_full |
The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth |
title_fullStr |
The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth |
title_full_unstemmed |
The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth |
title_sort |
development of a security evaluation model focused on information leakage protection for sustainable growth |
publisher |
MDPI AG |
series |
Sustainability |
issn |
2071-1050 |
publishDate |
2020-12-01 |
description |
This research establishes a security evaluation model from the insider leakage perspective and suggests an objective evaluation measurement. Organizational security risks are fused and compounded both inside and outside the organization. Although multiple security controls are implemented to minimize an organization’s security risk, effective security control requires management to preemptively check the organization’s security level. Existing criteria for evaluating security level are limited to external security risks and have improper limit points for dealing with security risks that are fused and compounded within an organization. The focus of this study is the prevention of technical information leakage. Furthermore, we propose a method for measuring the level at which the objectivity of certain items is secured. We compiled 26 detailed evaluation items, considering the security requirements to prevent technical information leakage. We not only performed suitability, reliability, and factor analyses and statistical validation, but also established a method to measure the security level. This measurement method ensures the effectiveness and objectivity of the evaluation of security level, mitigating the risks of security incidents caused by insiders. The results serve as a reference for organizations when designing security evaluation criteria and automated tools based on our evaluation model for future research. |
topic |
insider threat information leakage protection security evaluation sustainable growth |
url |
https://www.mdpi.com/2071-1050/12/24/10639 |
work_keys_str_mv |
AT jawonkim thedevelopmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth AT chanwoolee thedevelopmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth AT hangbaechang thedevelopmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth AT jawonkim developmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth AT chanwoolee developmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth AT hangbaechang developmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth |
_version_ |
1724377297304158208 |