TY - GEN
T1 - GoCoMM
T2 - 1st ACM Workshop on Information Security Governance, WISG '09, Co-located with the 16th ACM Computer and Communications Security Conference, CCS'09
AU - Gheorghe, G.
AU - Massacci, F.
AU - Neuhaus, S.
AU - Pretschner, A.
PY - 2009
Y1 - 2009
N2 - Advanced methodologies for compliance such as CobiT identify a number of maturity levels that must be reached: first the existence of an infrastructure for the enforcement of security controls; second, the ability to continuously monitor and audit quantifiable indicators for the controls put in place; and third, the ability to react when a policy violation is detected. In this paper, we go further and define a governance and compliance maturity model (GoCoMM) that is process-oriented. As an instance of the highest level of governance and compliance, we suggest a method of goal correlation that provides measurable indicators of security and compliance by systematically refining business processes and regulatory goals. We also introduce a run-time architecture to support this model. Copyright 2009 ACM.
AB - Advanced methodologies for compliance such as CobiT identify a number of maturity levels that must be reached: first the existence of an infrastructure for the enforcement of security controls; second, the ability to continuously monitor and audit quantifiable indicators for the controls put in place; and third, the ability to react when a policy violation is detected. In this paper, we go further and define a governance and compliance maturity model (GoCoMM) that is process-oriented. As an instance of the highest level of governance and compliance, we suggest a method of goal correlation that provides measurable indicators of security and compliance by systematically refining business processes and regulatory goals. We also introduce a run-time architecture to support this model. Copyright 2009 ACM.
UR - https://www.scopus.com/pages/publications/74049162359
UR - https://www.scopus.com/pages/publications/74049162359#tab=citedBy
U2 - 10.1145/1655168.1655175
DO - 10.1145/1655168.1655175
M3 - Conference contribution
SN - 9781605587875
T3 - Proceedings of the ACM Conference on Computer and Communications Security
SP - 33
EP - 37
BT - Proceedings of the 1st ACM Workshop on Information Security Governance, WISG '09, Co-located with the 16th ACM Computer and Communications Security Conference, CCS'09
Y2 - 9 November 2009 through 13 November 2009
ER -