| Title: |
Cybersecurity Maturity Assessment and Standardisation |
| Authors: |
Yigit Ozkan, Bilge; Afd Intelligent Software Systems; Brinkkemper, Sjaak; Spruit, Marco |
| Publisher Information: |
Universiteit Utrecht; Utrecht University |
| Publication Year: |
2022 |
| Subject Terms: |
cyberbeveiliging; informatiebeveiliging; volwassenheidsbeoordeling; mkb; aanpassingsvermogen; procesverbetering; standaardisering; vaardigheid; cybersecurity; information security; maturity assessment; SME; adaptivity; process improvement; standardisation; capability |
| Description: |
Organisations’ cybersecurity requirements have several origins, including the need to protect their business from cyberattacks, comply with laws and regulations, and build trust. Cyber threats and new regulations emerge, thus the need to implement measures and assure compliance. Cybersecurity maturity assessments and cybersecurity standardisation can be used to implement measures and provide assurance for regulators. Therefore, this dissertation investigates cybersecurity maturity assessment and cybersecurity standardisation to improve organisations' cybersecurity. We state our research objective as follows: To support the improvement of organisations' cybersecurity by means of maturity assessment and standardisation. We employ the Design Science Research approach and investigate our problem space by identifying the stakeholders' needs, goals, and requirements using several research methodologies and propose design artifacts to solve the identified problems. The dissertation is organized into three parts: adaptivity in cybersecurity maturity assessments, cybersecurity standardisation, and the integration of cybersecurity maturity assessments and standardisation. The first part is titled “Adaptivity in cybersecurity maturity assessments”. Chapter 2 investigates the adaptivity of an existing maturity assessment model to organisational contexts. The artifact proposed in this research provides organisations with a method to adapt an existing information security maturity model to their organisational characteristics. Chapter 3 presents an assessment instrument that is adaptable by design through the posed situational questions. The questionnaire model proposed as an artifact helps organisations tailor the assessment instrument interactively by the given answers to the situational questions. Finally, in the first part, Chapter 4 investigates how organisational context affects the design of information security maturity assessment models using design principles and the proposed design requirements can be used for ... |
| Document Type: |
doctoral or postdoctoral thesis |
| File Description: |
text/plain |
| Language: |
English |
| Relation: |
https://dspace.library.uu.nl/handle/1874/421285 |
| Availability: |
https://dspace.library.uu.nl/handle/1874/421285 |
| Rights: |
info:eu-repo/semantics/OpenAccess |
| Accession Number: |
edsbas.4002F28E |
| Database: |
BASE |