Tietoturvallisuuden mittareiden nykytila

Suosittu sanonta kertoo mittaamisen merkitsevän asian tietämistä. Kuten mitä tahansa muuta prosessia, ei tietoturvallisuuden prosessejakaan voida hallita, mikäli niitä ei voida mitata. Kuitenkaan saatavilla oleva tieto erinäisistä mittareista eivät helpota tietoturva-asiantuntijoiden tuskaa, sillä a...

Täydet tiedot

Bibliografiset tiedot
Päätekijä: Salmi, Niko
Muut tekijät: Informaatioteknologian tiedekunta, Faculty of Information Technology, Informaatioteknologia, Information Technology, Jyväskylän yliopisto, University of Jyväskylä
Aineistotyyppi: Pro gradu
Kieli:fin
Julkaistu: 2018
Aiheet:
Linkit: https://jyx.jyu.fi/handle/123456789/60299
_version_ 1826225721375195136
author Salmi, Niko
author2 Informaatioteknologian tiedekunta Faculty of Information Technology Informaatioteknologia Information Technology Jyväskylän yliopisto University of Jyväskylä
author_facet Salmi, Niko Informaatioteknologian tiedekunta Faculty of Information Technology Informaatioteknologia Information Technology Jyväskylän yliopisto University of Jyväskylä Salmi, Niko Informaatioteknologian tiedekunta Faculty of Information Technology Informaatioteknologia Information Technology Jyväskylän yliopisto University of Jyväskylä
author_sort Salmi, Niko
datasource_str_mv jyx
description Suosittu sanonta kertoo mittaamisen merkitsevän asian tietämistä. Kuten mitä tahansa muuta prosessia, ei tietoturvallisuuden prosessejakaan voida hallita, mikäli niitä ei voida mitata. Kuitenkaan saatavilla oleva tieto erinäisistä mittareista eivät helpota tietoturva-asiantuntijoiden tuskaa, sillä avainmittareiden tunnistaminen saatavilla olevasta massasta voi olla ylivoimaisen vaikeaa. Tämän tutkimuksen tarkoituksena oli kartoittaa tietoturvallisuuden mittareiden nykytilaa Suomessa. Tarkastelun kohteena olivat suuret suomalaiset yritykset ja niiden käyttämät tietoturvallisuuden mittarit. Tutkimus toteutettiin laadullisin menetelmin asiantuntijahaastatteluina ja sisällönanalyysilla. Haastateltaviksi valikoitui tutkimukseen yhteensä viisi tietoturva-asiantuntijaa. Tutkimuksen tuloksena tunnistettiin 28 erilaista tietoturvallisuuden mittaria, joita tutkimuksen aikaan käytettiin suurissa suomalaisissa organisaatioissa. A popular saying state that to measure is to know. Like any other process, you cannot manage information security processes if you cannot measure them. Still the available lists of possible information security metrics do not lessen the unease of information security experts, because identifying the key metrics from this large mass might be exceedingly difficult. This study focuses on identifying the present state of information security metrics in Finland. It was directed at commonly used information security metrics in large Finnish corporations. The study was conducted with qualitative methods using expert interviews and content analysis. Selected interviewees included five information security experts. The end results include 28 identified information security metrics that were used in large Finnish corporations during the study.
first_indexed 2019-09-20T09:14:23Z
format Pro gradu
free_online_boolean 1
fullrecord [{"key": "dc.contributor.advisor", "value": "Siponen, Mikko", "language": "", "element": "contributor", "qualifier": "advisor", "schema": "dc"}, {"key": "dc.contributor.author", "value": "Salmi, Niko", "language": "", "element": "contributor", "qualifier": "author", "schema": "dc"}, {"key": "dc.date.accessioned", "value": "2018-11-23T07:16:31Z", "language": null, "element": "date", "qualifier": "accessioned", "schema": "dc"}, {"key": "dc.date.available", "value": "2018-11-23T07:16:31Z", "language": null, "element": "date", "qualifier": "available", "schema": "dc"}, {"key": "dc.date.issued", "value": "2018", "language": "", "element": "date", "qualifier": "issued", "schema": "dc"}, {"key": "dc.identifier.uri", "value": "https://jyx.jyu.fi/handle/123456789/60299", "language": null, "element": "identifier", "qualifier": "uri", "schema": "dc"}, {"key": "dc.description.abstract", "value": "Suosittu sanonta kertoo mittaamisen merkitsev\u00e4n asian tiet\u00e4mist\u00e4. Kuten mit\u00e4 tahansa muuta prosessia, ei tietoturvallisuuden prosessejakaan voida hallita, mik\u00e4li niit\u00e4 ei voida mitata. Kuitenkaan saatavilla oleva tieto erin\u00e4isist\u00e4 mittareista eiv\u00e4t helpota tietoturva-asiantuntijoiden tuskaa, sill\u00e4 avainmittareiden tunnistaminen saatavilla olevasta massasta voi olla ylivoimaisen vaikeaa. T\u00e4m\u00e4n tutkimuksen tarkoituksena oli kartoittaa tietoturvallisuuden mittareiden\nnykytilaa Suomessa. Tarkastelun kohteena olivat suuret suomalaiset yritykset ja niiden k\u00e4ytt\u00e4m\u00e4t tietoturvallisuuden mittarit. Tutkimus toteutettiin laadullisin menetelmin asiantuntijahaastatteluina ja sis\u00e4ll\u00f6nanalyysilla. Haastateltaviksi\nvalikoitui tutkimukseen yhteens\u00e4 viisi tietoturva-asiantuntijaa. Tutkimuksen tuloksena tunnistettiin 28 erilaista tietoturvallisuuden mittaria, joita tutkimuksen aikaan k\u00e4ytettiin suurissa suomalaisissa organisaatioissa.", "language": "fi", "element": "description", "qualifier": "abstract", "schema": "dc"}, {"key": "dc.description.abstract", "value": "A popular saying state that to measure is to know. Like any other process, you cannot manage information security processes if you cannot measure them. Still the available lists of possible information security metrics do not lessen the unease of information security experts, because identifying the key metrics from this large mass might be exceedingly difficult. This study focuses on identifying the present state of information security metrics in Finland. It was directed at\ncommonly used information security metrics in large Finnish corporations. The study was conducted with qualitative methods using expert interviews and content analysis. Selected interviewees included five information security experts.\nThe end results include 28 identified information security metrics that were used in large Finnish corporations during the study.", "language": "en", "element": "description", "qualifier": "abstract", "schema": "dc"}, {"key": "dc.description.provenance", "value": "Submitted by Paivi Vuorio (paelvuor@jyu.fi) on 2018-11-23T07:16:31Z\nNo. of bitstreams: 0", "language": "en", "element": "description", "qualifier": "provenance", "schema": "dc"}, {"key": "dc.description.provenance", "value": "Made available in DSpace on 2018-11-23T07:16:31Z (GMT). No. of bitstreams: 0\n Previous issue date: 2018", "language": "en", "element": "description", "qualifier": "provenance", "schema": "dc"}, {"key": "dc.format.extent", "value": "102", "language": "", "element": "format", "qualifier": "extent", "schema": "dc"}, {"key": "dc.format.mimetype", "value": "application/pdf", "language": null, "element": "format", "qualifier": "mimetype", "schema": "dc"}, {"key": "dc.language.iso", "value": "fin", "language": null, "element": "language", "qualifier": "iso", "schema": "dc"}, {"key": "dc.rights", "value": "In Copyright", "language": "en", "element": "rights", "qualifier": null, "schema": "dc"}, {"key": "dc.subject.other", "value": "tietoturvallisuus", "language": "", "element": "subject", "qualifier": "other", "schema": "dc"}, {"key": "dc.subject.other", "value": "mittaaminen", "language": "", "element": "subject", "qualifier": "other", "schema": "dc"}, {"key": "dc.title", "value": "Tietoturvallisuuden mittareiden nykytila", "language": "", "element": "title", "qualifier": null, "schema": "dc"}, {"key": "dc.type", "value": "master thesis", "language": null, "element": "type", "qualifier": null, "schema": "dc"}, {"key": "dc.identifier.urn", "value": "URN:NBN:fi:jyu-201811234850", "language": "", "element": "identifier", "qualifier": "urn", "schema": "dc"}, {"key": "dc.type.ontasot", "value": "Pro gradu -tutkielma", "language": "fi", "element": "type", "qualifier": "ontasot", "schema": "dc"}, {"key": "dc.type.ontasot", "value": "Master\u2019s thesis", "language": "en", "element": "type", "qualifier": "ontasot", "schema": "dc"}, {"key": "dc.contributor.faculty", "value": "Informaatioteknologian tiedekunta", "language": "fi", "element": "contributor", "qualifier": "faculty", "schema": "dc"}, {"key": "dc.contributor.faculty", "value": "Faculty of Information Technology", "language": "en", "element": "contributor", "qualifier": "faculty", "schema": "dc"}, {"key": "dc.contributor.department", "value": "Informaatioteknologia", "language": "fi", "element": "contributor", "qualifier": "department", "schema": "dc"}, {"key": "dc.contributor.department", "value": "Information Technology", "language": "en", "element": "contributor", "qualifier": "department", "schema": "dc"}, {"key": "dc.contributor.organization", "value": "Jyv\u00e4skyl\u00e4n yliopisto", "language": "fi", "element": "contributor", "qualifier": "organization", "schema": "dc"}, {"key": "dc.contributor.organization", "value": "University of Jyv\u00e4skyl\u00e4", "language": "en", "element": "contributor", "qualifier": "organization", "schema": "dc"}, {"key": "dc.subject.discipline", "value": "Tietoj\u00e4rjestelm\u00e4tiede", "language": "fi", "element": "subject", "qualifier": "discipline", "schema": "dc"}, {"key": "dc.subject.discipline", "value": "Information Systems Science", "language": "en", "element": "subject", "qualifier": "discipline", "schema": "dc"}, {"key": "yvv.contractresearch.collaborator", "value": "business", "language": "", "element": "contractresearch", "qualifier": "collaborator", "schema": "yvv"}, {"key": "yvv.contractresearch.funding", "value": "0", "language": "", "element": "contractresearch", "qualifier": "funding", "schema": "yvv"}, {"key": "yvv.contractresearch.initiative", "value": "student", "language": "", "element": "contractresearch", "qualifier": "initiative", "schema": "yvv"}, {"key": "dc.type.coar", "value": "http://purl.org/coar/resource_type/c_bdcc", "language": null, "element": "type", "qualifier": "coar", "schema": "dc"}, {"key": "dc.rights.accesslevel", "value": "openAccess", "language": null, "element": "rights", "qualifier": "accesslevel", "schema": "dc"}, {"key": "dc.type.publication", "value": "masterThesis", "language": null, "element": "type", "qualifier": "publication", "schema": "dc"}, {"key": "dc.subject.oppiainekoodi", "value": "601", "language": "", "element": "subject", "qualifier": "oppiainekoodi", "schema": "dc"}, {"key": "dc.subject.yso", "value": "johtaminen", "language": null, "element": "subject", "qualifier": "yso", "schema": "dc"}, {"key": "dc.subject.yso", "value": "tieto", "language": null, "element": "subject", "qualifier": "yso", "schema": "dc"}, {"key": "dc.subject.yso", "value": "tietoturva", "language": null, "element": "subject", "qualifier": "yso", "schema": "dc"}, {"key": "dc.subject.yso", "value": "mittarit (mittaus)", "language": null, "element": "subject", "qualifier": "yso", "schema": "dc"}, {"key": "dc.format.content", "value": "fulltext", "language": null, "element": "format", "qualifier": "content", "schema": "dc"}, {"key": "dc.rights.url", "value": "https://rightsstatements.org/page/InC/1.0/", "language": null, "element": "rights", "qualifier": "url", "schema": "dc"}, {"key": "dc.type.okm", "value": "G2", "language": null, "element": "type", "qualifier": "okm", "schema": "dc"}]
id jyx.123456789_60299
language fin
last_indexed 2025-02-18T10:55:40Z
main_date 2018-01-01T00:00:00Z
main_date_str 2018
online_boolean 1
online_urls_str_mv {"url":"https:\/\/jyx.jyu.fi\/bitstreams\/808c425c-e809-4f53-8d48-5e56eb622d5a\/download","text":"URN:NBN:fi:jyu-201811234850.pdf","source":"jyx","mediaType":"application\/pdf"}
publishDate 2018
record_format qdc
source_str_mv jyx
spellingShingle Salmi, Niko Tietoturvallisuuden mittareiden nykytila tietoturvallisuus mittaaminen Tietojärjestelmätiede Information Systems Science 601 johtaminen tieto tietoturva mittarit (mittaus)
title Tietoturvallisuuden mittareiden nykytila
title_full Tietoturvallisuuden mittareiden nykytila
title_fullStr Tietoturvallisuuden mittareiden nykytila Tietoturvallisuuden mittareiden nykytila
title_full_unstemmed Tietoturvallisuuden mittareiden nykytila Tietoturvallisuuden mittareiden nykytila
title_short Tietoturvallisuuden mittareiden nykytila
title_sort tietoturvallisuuden mittareiden nykytila
title_txtP Tietoturvallisuuden mittareiden nykytila
topic tietoturvallisuus mittaaminen Tietojärjestelmätiede Information Systems Science 601 johtaminen tieto tietoturva mittarit (mittaus)
topic_facet 601 Information Systems Science Tietojärjestelmätiede johtaminen mittaaminen mittarit (mittaus) tieto tietoturva tietoturvallisuus
url https://jyx.jyu.fi/handle/123456789/60299 http://www.urn.fi/URN:NBN:fi:jyu-201811234850
work_keys_str_mv AT salminiko tietoturvallisuudenmittareidennykytila