Towards a cyber security reporting system – a quality improvement process

  • Authors:
  • Jose J. Gonzalez

  • Affiliations:
  • Faculty of Engineering and Science, Research Cell “Security and Quality in Organizations”, Agder University College, GRIMSTAD, Norway

  • Venue:
  • SAFECOMP'05 Proceedings of the 24th international conference on Computer Safety, Reliability, and Security
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

IT-security lacks the equivalent of an Air Safety Reporting System. Yet, the current trend to outsource security processes might be the birth of a Cyber Security Reporting System – CSRS. A necessary condition for providers of security services to evolve toward a CSRS is successful quality management. The increasing demand for “fire-fighting” – deriving from the growth in number and sophistication of attacks and the decline in the expertise of the average system administrator – pushes farther and farther away from “fire-prevention.” But growth of insight, and its codification and communication are prerequisites for even the most rudimentary CSRS. Studies show that few attempts to implement quality improvement processes succeed; yet, successful quality management provides decisive competitive advantage. System dynamics studies of quality management have identified causes of implementation failure and provided guidance for success. Transferring these lessons to security service organizations is a promising path toward the vision of a CSRS.