Security maturity assessment method
Abstract
In general, the invention relates to a method for assessing an information security policy and practice of an organization. The method includes collecting information about the information security policy and practice of the organization, generating a rating for each of a plurality of information security items using a security maturity assessment matrix and the collected information, and generating a graphical assessment of the ratings. The security maturity assessment matrix includes a first dimension and a second dimension, where the first dimension corresponds to the information security items and the second dimension corresponds to maturity levels. Further, each rating is derived using the first dimension and the second dimension.
Claims
exact text as granted — not AI-modified1 .- 19 . (canceled)
20 . A method for assessing an information security policy and practice of an organization, comprising:
collecting information about the information security policy and practice of the organization; generating a rating for each of a plurality of information security items using a security maturity assessment matrix and the collected information,
wherein the security maturity assessment matrix comprises a first dimension and a second dimension,
wherein the first dimension corresponds to the plurality of information security items,
wherein the second dimension corresponds to a plurality of maturity levels, and
wherein each rating is derived using the first dimension and the second dimension;
generating a graphical assessment of the ratings; and displaying the graphical assessment of the ratings.
21 . The method of claim 20 , Other comprising:
generating a new rating for each of a plurality of information security items using the security maturity assessment matrix when there is a change in an information security environment of the organization.
22 . The method of claim 20 , wherein the graphical assessment of the ratings is generated by a security maturity assessment reporting tool.
23 . The method of claim 22 , wherein the security maturity assessment reporting tool comprises functionality to track the ratings of each of the plurality of information security items over time.
24 . The method of claim 22 , wherein the security maturity assessment reporting tool comprises functionality to graphically compare the ratings associated with each of the plurality of information security items with a corresponding rating goal associated with each of the plurality of information security items.
25 . The method of claim 20 , further comprising:
determining how to modify the information security policy and practice of the organization using the rating for the at least one of the plurality of security items.
26 . The method of claim 25 , wherein determining how to modify the information security policy and practice of the organization, comprises:
generating a corrective action using the rating for at least one of the plurality of information security items and the security maturity assessment matrix.
27 . The method of claim 26 , wherein generating the corrective action comprises:
obtaining a first description from the security maturity assessment matrix corresponding to the rating of the at least one of the plurality of information security items; obtaining a second description from the security maturity assessment matrix corresponding to a goal rating of the at least one of the plurality of information security items; and comparing the first description with the second description to obtain the corrective action for the at least one of the plurality of information security items.
28 . The method of claim 27 , further comprising:
executing the corrective action to create a new security information policy and practice.
29 . The method of claim 28 , further comprising;
monitoring the new security information policy and practice.
30 . The method of claim 20 , wherein at least one of the plurality of security items corresponds to an information security item associated with at least one selected from the group consisting of BS7799 and ISO17799.
31 . The method of claim 20 , wherein at least one of the plurality of maturity levels corresponds to a maturity level associated with a Capability Maturity Model
32 . The method of claim 31 , wherein the maturity level is at least one selected from the group consisting of: initial, repeatable, defined, managed, and optimized.
33 . The method of claim 20 , wherein at least one of the plurality of information security items in the first dimension is associated with a scope requirement.
34 . The method of claim 33 , wherein the scope requirement defines what portions of the organization to which the at least one of the plurality of information security items applies.
35 . The method of claim 30 , wherein the first dimension is displayed using at least one row and the second dimension is displayed using at least one column.
36 . A computer system for assessing an information security policy and practice of an organization, comprising:
a processor; a memory; an input means; and software instructions stored in the memory for enabling the computer system under control of the processor, to: collect information about the information security policy and practice of the organization; generate a rating for each of a plurality of information security items using a security maturity assessment matrix and the collected information,
wherein the security maturity assessment matrix comprises a first dimension and a second dimension,
wherein the first dimension corresponds to the plurality of information security items,
wherein the second dimension corresponds to a plurality of maturity levels, and
wherein each rating is derived using the first dimension and the second dimension;
generate a graphical assessment of the ratings; display the graphical assessment of the ratings.
37 . The computer system of claim 36 , further comprising software instructions stored in the memory for enabling the computer system under control of the processor, to:
generate a new rating for each of a plurality of information security items using the security maturity assessment matrix when there is a change in an information security environment of the organization.
38 . The computer system of claim 36 , wherein the graphical assessment of the ratings is generated by a security maturity assessment reporting tool.
39 . The computer system of claim 38 , wherein the security maturity assessment reporting tool comprises functionality to track the ratings of each of the plurality of information security items over time.
40 . The computer system of claim 38 , wherein the security maturity assessment reporting tool comprises functionality to graphically compare the ratings associated with each of the plurality of information security items with a corresponding rating goal associated with each of the plurality of information security items.
41 . The computer system of claim 36 , further comprising software instructions stored in the memory for enabling the computer system under control of the processor, to:
determine how to modify the information security policy and practice of the organization using the rating for the at least one of the plurality of security items.
42 . The computer system of claim 41 , wherein software instructions stored in the memory for enabling the computer system under control of the processor, to determine how to modify the information security policy and practice of the organization, comprise software instructions for:
generating a corrective action using the rating for at least one of the plurality of information security items and the security maturity assessment matrix.
43 . The computer system of claim 42 , wherein software instructions stored in the memory for enabling the computer system under control of the processor, to generate the corrective action comprise software instructions for:
obtaining a first description from the security maturity assessment matrix corresponding to the rating of the at least one of the plurality of information security items; obtaining a second description from the security maturity assessment matrix corresponding to a goal rating of the at least one of the plurality of information security items; and comparing the first description with the second description to obtain the corrective action for the at least one of the plurality of information security items.
44 . The computer system of claim 42 , further comprising software instructions stored in the memory for enabling the computer system under control of the processor, to:
execute the corrective action to create a new security information policy and practice.
45 . The computer system of claim 44 , further comprising software instructions stored in the memory for enabling the computer system under control of the processor, to:
monitor the new security information policy and practice.
46 . The computer system of claim 36 , wherein at least one of the plurality of security items corresponds to an information security item associated with at least one selected from the group consisting of BS7799 and ISO17799.
47 . The computer system of claim 36 , wherein at least one of the plurality of maturity levels corresponds to a maturity level associated with a Capability Maturity Model
48 . The computer system of claim 47 , wherein the maturity level is at least one selected from the group consisting of: initial, repeatable, defined, managed, and optimized.
49 . The computer system of claim 36 , wherein at least one of the plurality of information security items in the first dimension is associated with a scope requirement.
50 . The computer system of claim 49 , wherein the scope requirement defines what portions of the organization to which the at least one of the plurality of information security items applies.
51 . The computer system of claim 36 , wherein the first dimension is displayed using at least one row and the second dimension is displayed using at least one column.Join the waitlist — get patent alerts
Track US2009265787A9 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.