*
unknown
inadequate
acceptable
good
An overall
security plan is developed that covers the building of awareness,
establishes clear policies and standards, identifies a cost-effective
and sustainable implementation, and defines monitoring and enforcement
processes
*
unknown
inadequate
acceptable
good
There is
awareness that a good security plan takes time to evolve
*
unknown
inadequate
acceptable
good
The corporate
security function reports to senior management and is responsible
for executing the security plan
*
unknown
inadequate
acceptable
good
Management
and staff have a common understanding of security requirements,
vulnerabilities and threats, and they understand and accept their
own security responsibilities
*
unknown
inadequate
acceptable
good
Third-party
evaluation of security policy and architecture is conducted periodically
*
unknown
inadequate
acceptable
good
A "building
permit" programme is defined, identifying security baselines
that have to be adhered to
*
unknown
inadequate
acceptable
good
A "drivers
licence" programme is in place for those developing, implementing
and using systems, enforcing security certification of staff
*
unknown
inadequate
acceptable
good
The security
function has the means and ability to detect, record, analyse
significance, report and act upon security incidents when they
do occur, while minimising the probability of occurrence by applying
intrusion testing and active monitoring
*
unknown
inadequate
acceptable
good
A centralised
user management process and system provides the means to identify
and assign authorisations to users in a standard and efficient
manner
*
unknown
inadequate
acceptable
good
A process
is in place to authenticate users at reasonable cost, light to
implement and easy to use
*
unknown
inadequate
acceptable
good
*
KEY
GOAL INDICATORS
*
unknown
inadequate
acceptable
good
No incidents
causing public embarrassment
*
unknown
inadequate
acceptable
good
Immediate
reporting on critical incidents
*
unknown
inadequate
acceptable
good
Alignment
of access rights with organisational responsibilities
*
unknown
inadequate
acceptable
good
Reduced number
of new implementations delayed by security concerns
*
unknown
inadequate
acceptable
good
Full compliance,
or agreed and recorded deviations from minimum security requirements
*
unknown
inadequate
acceptable
good
Reduced number
of incidents involving unauthorised access, loss or corruption
of information
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*
KEY
PERFORMANCE INDICATORS
*
unknown
inadequate
acceptable
good
Reduced number
of security-related service calls, change requests and fixes
*
unknown
inadequate
acceptable
good
Amount of
downtime caused by security incidents
*
unknown
inadequate
acceptable
good
Reduced turnaround
time for security administration requests
*
unknown
inadequate
acceptable
good
Number of
systems subject to an intrusion detection process
*
unknown
inadequate
acceptable
good
Number of
systems with active monitoring capabilities
*
unknown
inadequate
acceptable
good
Reduced time
to investigate security incidents
*
unknown
inadequate
acceptable
good
Time lag
between detection, reporting and acting upon security incidents
*
unknown
inadequate
acceptable
good
Number of
IT security awareness training days
*
unknown
inadequate
acceptable
good
*
*
unknown
inadequate
acceptable
good
*