Information system security metrics are critical in assessing and mitigating data protection risks. Executives must improve the security of their information systems. However, it is important to note that there is a wide variety of metrics available and that generic measurements may not be effective for the broader enterprise. This article provides an overview of information system security metrics and introduces a novel hierarchical model for them. Adopting a comparative approach across five sectors (health, finance, industry, government, and education), the Analytical Hierarchy Process (AHP) was used to design and evaluate the model in each sector context. The objective was to identify the variation in security criteria based on the sector. The results obtained confirm that the criteria weights vary according to the sector involving a change in the hierarchical evaluation model.
Read full abstract