Information Security Governance Assessment Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for assessing information security governance in enterprises are ineffective in providing continuous assurance for the protection of information and information assets, leading to risks and challenges in risk management, reporting, and accountability.

Innovation Solution

A system and method that classify information security governance into sub-information security governance areas, define governance focus areas and control dimensions, check compliance, assign weights, and calculate scores to assess the effectiveness of information security governance practices across the enterprise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional assessment methods are used for information security governance, then the assessment process is simple, but the assessment effectiveness and reliability are insufficient

Engineering Contradiction:
Improveassessment effectivenessVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The information security governance assessment system is segmented into multiple hierarchical levels: governance focus areas (e.g., security management, risk management), governance control dimensions (e.g., policies, procedures, controls), and specific assessment criteria. This segmentation allows comprehensive coverage of security governance while maintaining structured and manageable assessment processes, resolving the contradiction between assessment effectiveness and system complexity.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If detailed governance control dimensions are defined, then measurement precision improves, but the complexity of implementation increases

Engineering Contradiction:
Improvegovernance assessment precisionVSAvoidgovernance framework complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The assessment framework introduces multiple dimensions for evaluating information security governance: governance focus areas represent the first dimension, governance control dimensions represent the second dimension, and weighted scoring represents the third dimension. This multi-dimensional approach enables precise measurement of governance effectiveness while organizing complexity into manageable hierarchical layers, allowing detailed assessment without overwhelming implementation complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If comprehensive compliance checking is performed across multiple governance areas, then information security protection improves, but the time and resources required increase

Engineering Contradiction:
Improveinformation security protectionVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The framework establishes governance policies, procedures, and control measures in advance across multiple focus areas and dimensions. Organizations can implement these governance structures proactively before assessments occur, enabling continuous compliance monitoring and reducing the time required for actual assessment activities. The pre-defined governance framework allows for ongoing self-assessment and continuous improvement, minimizing assessment time while maintaining comprehensive security protection.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If weighted scoring is applied to governance focus areas and control dimensions, then assessment accuracy improves, but the complexity of calculation and aggregation increases

Engineering Contradiction:
Improvegovernance score accuracyVSAvoidscoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The framework transforms qualitative governance assessments into quantitative measurements by introducing weighted scoring parameters. Each governance focus area and control dimension is assigned specific weights based on its importance and impact on information security. This parameter transformation enables accurate comparison and aggregation of governance effectiveness across different areas, converting complex qualitative judgments into precise quantitative scores that facilitate decision-making while maintaining manageable calculation complexity through standardized weighting schemes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9760849B2Assessing an information security governance of an enterprise
Publication Date: 2017.09.12 TATA CONSULTANCY SERVICES LTD
  • US9760849B2 patent drawing
  • US9760849B2 patent drawing
  • US9760849B2 patent drawing

AI summary

Systems and methods for assessing an information security governance of an enterprise are disclosed. The method includes classifying the information security governance into a plurality of sub-information security governances. The method further comprises defining a plurality of governance focus areas and a plurality of governance control dimensions for a sub-information security governance. The method further comprises checking a compliance, by a processor, of the governance practices of users in the sub-information security governances, in the plurality of governance focus areas, and in the plurality of governance control dimensions. The method further comprises assigning weights to the plurality of governance focus areas, to the plurality of governance control dimensions, and to the sub-information security governances. The method further comprises determining a score for sub-information security governance based on the compliance and the weights.