Planning and Conducting Cybersecurity Audits to Assess the Effectiveness of Controls

Regner Sabillon, Michael Barr

Research output: Chapter or section in a book/report/conference proceedingChapter in a published conference proceeding

Abstract

This article reports the findings of an empirical study that assessed the effectiveness of the CyberSecurity Audit Model (CSAM 2.0) in a different Canadian higher education institution. CSAM 2.0 is used to conduct cybersecurity audits in medium to large organizations or even at the national level to assess and measure cybersecurity assurance, maturity, and cyber readiness. CSAM 2.0 is a mature model that enables the effective and comprehensive assessment of security controls that are part of the selected cybersecurity domains to be audited. The authors examined the best practices and methodologies of global leaders in the cybersecurity assurance and audit field, highlighting the absence of standardized guidelines for conducting comprehensive cybersecurity audits and identifying weaknesses in general cybersecurity awareness training programs. The paper outlines the structure of CSAM 2.0 in detail, including its architecture. CSAM 2.0 has undergone testing, implementation, and validation in three research scenarios: (1) a single audit in the cybersecurity domain focused on awareness education, (2) audits in various domains such as governance and strategy, legal and compliance, cyber risks, frameworks and regulations, incident management, cyber insurance, cloud security, and evolving technologies, and (3) a comprehensive cybersecurity audit covering all model domains. The study concludes by demonstrating that the validation of the CSAM 2.0 model provides valuable insights for future decision-making, enabling organizations to address cybersecurity weaknesses and enhance their cybersecurity domains and controls.

Original languageEnglish
Title of host publicationSysCon 2024 - 18th Annual IEEE International Systems Conference, Proceedings
Place of PublicationU. S. A.
PublisherIEEE
ISBN (Electronic)9798350358803
DOIs
Publication statusE-pub ahead of print - 17 Jun 2024
Event18th Annual IEEE International Systems Conference, SysCon 2024 - Montreal, Canada
Duration: 15 Apr 202418 Apr 2024

Publication series

NameSysCon 2024 - 18th Annual IEEE International Systems Conference, Proceedings

Conference

Conference18th Annual IEEE International Systems Conference, SysCon 2024
Country/TerritoryCanada
CityMontreal
Period15/04/2418/04/24

Keywords

  • cyber readiness
  • cybersecurity
  • cybersecurity assurance
  • cybersecurity audit model
  • cybersecurity audits
  • cybersecurity audits by domains
  • cybersecurity controls
  • cybersecurity domain criticality
  • cybersecurity maturity assessment
  • cybersecurity scorecard

ASJC Scopus subject areas

  • Artificial Intelligence
  • Hardware and Architecture
  • Information Systems
  • Decision Sciences (miscellaneous)
  • Information Systems and Management
  • Control and Optimization
  • Modelling and Simulation

Fingerprint

Dive into the research topics of 'Planning and Conducting Cybersecurity Audits to Assess the Effectiveness of Controls'. Together they form a unique fingerprint.

Cite this