TY - GEN
T1 - Planning and Conducting Cybersecurity Audits to Assess the Effectiveness of Controls
AU - Sabillon, Regner
AU - Barr, Michael
PY - 2024/6/17
Y1 - 2024/6/17
N2 - This article reports the findings of an empirical study that assessed the effectiveness of the CyberSecurity Audit Model (CSAM 2.0) in a different Canadian higher education institution. CSAM 2.0 is used to conduct cybersecurity audits in medium to large organizations or even at the national level to assess and measure cybersecurity assurance, maturity, and cyber readiness. CSAM 2.0 is a mature model that enables the effective and comprehensive assessment of security controls that are part of the selected cybersecurity domains to be audited. The authors examined the best practices and methodologies of global leaders in the cybersecurity assurance and audit field, highlighting the absence of standardized guidelines for conducting comprehensive cybersecurity audits and identifying weaknesses in general cybersecurity awareness training programs. The paper outlines the structure of CSAM 2.0 in detail, including its architecture. CSAM 2.0 has undergone testing, implementation, and validation in three research scenarios: (1) a single audit in the cybersecurity domain focused on awareness education, (2) audits in various domains such as governance and strategy, legal and compliance, cyber risks, frameworks and regulations, incident management, cyber insurance, cloud security, and evolving technologies, and (3) a comprehensive cybersecurity audit covering all model domains. The study concludes by demonstrating that the validation of the CSAM 2.0 model provides valuable insights for future decision-making, enabling organizations to address cybersecurity weaknesses and enhance their cybersecurity domains and controls.
AB - This article reports the findings of an empirical study that assessed the effectiveness of the CyberSecurity Audit Model (CSAM 2.0) in a different Canadian higher education institution. CSAM 2.0 is used to conduct cybersecurity audits in medium to large organizations or even at the national level to assess and measure cybersecurity assurance, maturity, and cyber readiness. CSAM 2.0 is a mature model that enables the effective and comprehensive assessment of security controls that are part of the selected cybersecurity domains to be audited. The authors examined the best practices and methodologies of global leaders in the cybersecurity assurance and audit field, highlighting the absence of standardized guidelines for conducting comprehensive cybersecurity audits and identifying weaknesses in general cybersecurity awareness training programs. The paper outlines the structure of CSAM 2.0 in detail, including its architecture. CSAM 2.0 has undergone testing, implementation, and validation in three research scenarios: (1) a single audit in the cybersecurity domain focused on awareness education, (2) audits in various domains such as governance and strategy, legal and compliance, cyber risks, frameworks and regulations, incident management, cyber insurance, cloud security, and evolving technologies, and (3) a comprehensive cybersecurity audit covering all model domains. The study concludes by demonstrating that the validation of the CSAM 2.0 model provides valuable insights for future decision-making, enabling organizations to address cybersecurity weaknesses and enhance their cybersecurity domains and controls.
KW - cyber readiness
KW - cybersecurity
KW - cybersecurity assurance
KW - cybersecurity audit model
KW - cybersecurity audits
KW - cybersecurity audits by domains
KW - cybersecurity controls
KW - cybersecurity domain criticality
KW - cybersecurity maturity assessment
KW - cybersecurity scorecard
UR - http://www.scopus.com/inward/record.url?scp=85197363306&partnerID=8YFLogxK
U2 - 10.1109/SysCon61195.2024.10553588
DO - 10.1109/SysCon61195.2024.10553588
M3 - Chapter in a published conference proceeding
AN - SCOPUS:85197363306
T3 - SysCon 2024 - 18th Annual IEEE International Systems Conference, Proceedings
BT - SysCon 2024 - 18th Annual IEEE International Systems Conference, Proceedings
PB - IEEE
CY - U. S. A.
T2 - 18th Annual IEEE International Systems Conference, SysCon 2024
Y2 - 15 April 2024 through 18 April 2024
ER -