Information Security Metrics: Challenges and Models in an All-Digital World

  • Chapter
  • First Online:
Legal Developments on Cybersecurity and Related Fields

Abstract

The evolution of ICT and the accelerated adoption process in all sectors of activity have revealed immense cybersecurity threats, which can definitively compromise this evolution and with a heavy impact. The problem, the technological and human vulnerabilities, and the possible solutions have been intensely studied and standardised, and it is now widely recognised that cybersecurity is, in essence, a risk management activity. However, to manage something, it is necessary to have metrics, and only a few aspects of cybersecurity are easily and understandably measurable. This article presents a systematic approach to cybersecurity and risk management, emphasising how to obtain appropriate security metrics and focusing on the industrial sector. For this, we use the most well-known standards illustrated with examples extracted from a typical industrial environment. An outline of a taxonomy of metrics and a framework for their identification and application are presented. It also discusses a continuous certification model that derives from the metrics model and aligns with one of the emerging standards to address cybersecurity in industrial environments (ISA/IEC 62443). The article ends by discussing some of the challenges facing the adoption of a metrics program suitable for organisations’ information security objectives.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Subscribe and save

Springer+ Basic
EUR 32.99 /Month
  • Get 10 units per month
  • Download Article/Chapter or Ebook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Chapter
EUR 29.95
Price includes VAT (Germany)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
EUR 128.39
Price includes VAT (Germany)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Hardcover Book
EUR 171.19
Price includes VAT (Germany)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free ship** worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Similar content being viewed by others

References

Download references

Acknowledgements

This project has received funding from the European Union’s Horizon 2020 research and innovation programme under grant agreement No 952644. Additionally, this work has been supported by FCT – Fundação para a Ciência e Tecnologia within the R&D Units Project Scope: UIDB/00319/2020.

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Henrique Santos .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2024 The Author(s), under exclusive license to Springer Nature Switzerland AG

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Santos, H., Pereira, T., Oliveira, A. (2024). Information Security Metrics: Challenges and Models in an All-Digital World. In: Carneiro Pacheco de Andrade, F.A., Fernandes Freitas, P.M., de Sousa Covelo de Abreu, J.R. (eds) Legal Developments on Cybersecurity and Related Fields. Law, Governance and Technology Series, vol 60. Springer, Cham. https://doi.org/10.1007/978-3-031-41820-4_6

Download citation

  • DOI: https://doi.org/10.1007/978-3-031-41820-4_6

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-031-41819-8

  • Online ISBN: 978-3-031-41820-4

  • eBook Packages: Law and CriminologyLaw and Criminology (R0)

Publish with us

Policies and ethics

Navigation