ABSTRACT: Information security has evolved over the years and has become increasingly important to society at large. Similarly, information security measurement and testing have evolved over the years,from the days of BS 7799 to the present day ISO 27001 and others.The measurement and testing techniques have been incredibly beneficial to the world of today. Though it has its limitations, there are opportunities for improvement and future research and development. This paperexplores these themes, highlighting the evolution of information security measurement and testing, the current trends, the benefits and the challenges, gaps, opportunities for improvement, and future research and development. With thesethemes, the discussion examines the evolution ofinformation security measurement and testing.
Keywords:Information security, Measurement, Testing, Metrics, Management, and Risk
[1]. Ahmad, R., Sahid, S., &Azuwa, M.P. (2014). Effective Measurement Requirements for Network Security Management.International Journal of Computer Science and InformationSecurity, 12(4), 37-44.
[2]. Arora, A., Hall, D., Piato, C. A., Ramsey, D., &Telang, R. (2004). Measuring the risk-based value of IT security solutions. IT Professional, 6(6), 35–42. doi:10.1109/MITP.2004.89.
[3]. Atyam, S. B. (2010). Effectiveness of security control risk assessments for enterprises: Assess on the business perspective of security risks. Information Security Journal, 19(6), 343–350. doi:10.1080/19393555.2010.514892.
[4]. Barabanov, R., Kowalski, S., &Yngström, L. (2011). Information security metrics: Research directions. 2011 2nd European Security Conference (pp.1-16), Örebro, Sweden, June 13-14, 2011.
[5]. Chapple, M., Stewart, J.M., & Gibson, D. (2015). Certified information system security professional (8th ed.). Indianapolis, Indiana: Sybex.