Comparative Analysis of the Cyber Security Capabilities Maturity Models

Authors

  • Prof. Dr Venelin Georgiev National and International Security Department, New Bulgarian University image/svg+xml Author

DOI:

https://doi.org/10.37075/YB.2021.2.02

Keywords:

Capabilities, Cybersecurity, Cyber resilience, Levels of maturity, Cybersecurity areas, A model for measuring the maturity of cybersecurity capabilities
A10, F60

Abstract

Everything that is being done in the field of cybersecurity, cyber resilience and the fight against cybercrime can be focused on one term and that is the term cybersecurity capabilities. Cybersecurity capabilities demonstrate the ability to implement policies, standards, guidelines, and operational procedures for the security of information systems, networks, applications, and information. In turn, cybersecurity capabilities are a dynamic object that is built, maintained, developed, modified and adapted to the changing security environment. The dynamics of security capabilities require measuring the degree of their maturity and comparing them with the target levels. The article makes a comparative analysis of existing models for assessing the maturity of cybersecurity capabilities, thus creating an opportunity for a reasoned choice of such a method for the needs of specific assessment.

References

NCSS: Practical Guide on Development and Execution. (2012). European Network and Information Security Agency (ENISA). URL: https://www.enisa.europa.eu/publications/national-cyber-security-strategies-an-implementation-guide (accessed 2020-10-01)

National Capabilities Assessment Framework. (2020). European Union Agency for Cybersecurity (ENISA).

CSIRT Maturity – Self-assessment Tool. (2021). ENISA. URL: https://www.enisa.europa.eu/topics/csirts-in-europe/csirt-capabilities/csirt-maturity/csirt-maturity-self-assessment-survey (accessed 2020-10-01)

Georgiev, V. (2021). Scenario planning for cybersecurity capabilities.

Institute of Internal Auditors Research (2009). Internal audit capability Model (IA-CM) for the public sector. Altamonte Springs, Fla: Institute of Internal Auditors, Research Foundation. ISBN: 0-89413-675-5

The Global Cybersecurity Index. (2018). International Telecommunication Union (ITU). URL: https://www.itu.int/dms_pub/itu-d/opb/str/D-STR-GCI.01-2018-PDF-E.pdf (accessed 2021-02-01)

NIST (2018). Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. National Institute of Standards and Technology (NIST). DOI: https://doi.org/10.6028/nist.cswp.04162018

Sharkov, George (2020). Assessing the Maturity of National Cybersecurity and Resilience. Connections The Quarterly Journal, 19(4), 5-24. DOI: https://doi.org/10.11610/connections.19.4.01

White, Gregory (2007). The Community Cyber Security Maturity Model. 2007 40th Annual Hawaii International Conference on System Sciences (HICSS'07). DOI: https://doi.org/10.1109/hicss.2007.522

Downloads

Published

2021-12-20

Issue

Section

Articles

How to Cite

Georgiev, V. (2021). Comparative Analysis of the Cyber Security Capabilities Maturity Models. Yearbook of UNWE, 2, 31-42. https://doi.org/10.37075/YB.2021.2.02