The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth

This research establishes a security evaluation model from the insider leakage perspective and suggests an objective evaluation measurement. Organizational security risks are fused and compounded both inside and outside the organization. Although multiple security controls are implemented to minimiz...

Full description

Bibliographic Details
Main Authors: Jawon Kim, Chanwoo Lee, Hangbae Chang
Format: Article
Language:English
Published: MDPI AG 2020-12-01
Series:Sustainability
Subjects:
Online Access:https://www.mdpi.com/2071-1050/12/24/10639
id doaj-643446abe1024e68968c34a5f75af90a
record_format Article
spelling doaj-643446abe1024e68968c34a5f75af90a2020-12-20T00:02:07ZengMDPI AGSustainability2071-10502020-12-0112106391063910.3390/su122410639The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable GrowthJawon Kim0Chanwoo Lee1Hangbae Chang2Department of Convergence Security, Chung-Ang University, Seoul 06974, KoreaInformation Security & International Business Division, Douzone Forensic Center, Seoul 04523, KoreaDepartment of Industrial Security, Chung-Ang University, Seoul 06974, KoreaThis research establishes a security evaluation model from the insider leakage perspective and suggests an objective evaluation measurement. Organizational security risks are fused and compounded both inside and outside the organization. Although multiple security controls are implemented to minimize an organization’s security risk, effective security control requires management to preemptively check the organization’s security level. Existing criteria for evaluating security level are limited to external security risks and have improper limit points for dealing with security risks that are fused and compounded within an organization. The focus of this study is the prevention of technical information leakage. Furthermore, we propose a method for measuring the level at which the objectivity of certain items is secured. We compiled 26 detailed evaluation items, considering the security requirements to prevent technical information leakage. We not only performed suitability, reliability, and factor analyses and statistical validation, but also established a method to measure the security level. This measurement method ensures the effectiveness and objectivity of the evaluation of security level, mitigating the risks of security incidents caused by insiders. The results serve as a reference for organizations when designing security evaluation criteria and automated tools based on our evaluation model for future research.https://www.mdpi.com/2071-1050/12/24/10639insider threatinformation leakage protectionsecurity evaluationsustainable growth
collection DOAJ
language English
format Article
sources DOAJ
author Jawon Kim
Chanwoo Lee
Hangbae Chang
spellingShingle Jawon Kim
Chanwoo Lee
Hangbae Chang
The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
Sustainability
insider threat
information leakage protection
security evaluation
sustainable growth
author_facet Jawon Kim
Chanwoo Lee
Hangbae Chang
author_sort Jawon Kim
title The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
title_short The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
title_full The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
title_fullStr The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
title_full_unstemmed The Development of a Security Evaluation Model Focused on Information Leakage Protection for Sustainable Growth
title_sort development of a security evaluation model focused on information leakage protection for sustainable growth
publisher MDPI AG
series Sustainability
issn 2071-1050
publishDate 2020-12-01
description This research establishes a security evaluation model from the insider leakage perspective and suggests an objective evaluation measurement. Organizational security risks are fused and compounded both inside and outside the organization. Although multiple security controls are implemented to minimize an organization’s security risk, effective security control requires management to preemptively check the organization’s security level. Existing criteria for evaluating security level are limited to external security risks and have improper limit points for dealing with security risks that are fused and compounded within an organization. The focus of this study is the prevention of technical information leakage. Furthermore, we propose a method for measuring the level at which the objectivity of certain items is secured. We compiled 26 detailed evaluation items, considering the security requirements to prevent technical information leakage. We not only performed suitability, reliability, and factor analyses and statistical validation, but also established a method to measure the security level. This measurement method ensures the effectiveness and objectivity of the evaluation of security level, mitigating the risks of security incidents caused by insiders. The results serve as a reference for organizations when designing security evaluation criteria and automated tools based on our evaluation model for future research.
topic insider threat
information leakage protection
security evaluation
sustainable growth
url https://www.mdpi.com/2071-1050/12/24/10639
work_keys_str_mv AT jawonkim thedevelopmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth
AT chanwoolee thedevelopmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth
AT hangbaechang thedevelopmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth
AT jawonkim developmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth
AT chanwoolee developmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth
AT hangbaechang developmentofasecurityevaluationmodelfocusedoninformationleakageprotectionforsustainablegrowth
_version_ 1724377297304158208