Security KPI Prototype
Project Idea Metadata
- Project Idea Name: Security KPI Prototype
- Date: 11/28/2021 12:19:11 AM
- Administrators:
Project Idea Description
Initial situation and problem definition:
SIX, as the central player in the Swiss financial market, operator of the Swiss Stock Exchange, provider of financial information, and various other related activities, needs precise reporting as a foundation for future decision making. Currently, IT Security Management mainly utilizes the Quarterly Security Reporting, which is made in a collaborative effort with multiple teams. Another reporting from the cyber security teams themselves is made as well.
These reports, as well as the main KPIs behind them, have been found and analyzed in a previous step in the WIPRO Project, which was done by the same student who will continue with this bachelor thesis. Using these recommendations, a proposal/prototype will be created.
Aim of the work and expected results:
- New/changed measurements following the SMART guidelines
- Provide SIX with a proposal/prototype using the recommendation from the previous project
- Focus on KPIs/Measurements in cyber security
- Prototype should give SIX an overview of its security posture, allowing SIX to define mitigation actions for worst-case situations
- Proof of Concept and test of prototype with evaluation
Methods/Procedure
1. Using the WIPRO, define which recommendation will be followed in the BAA
2. Research KPI prototypes, to find a fitting structure for the proposal
3. Using the recommendation, create a proposal/prototype to implement in a later project after the BAA
4. Fix current measurements to follow the “SMART” guideline
Creativity, variations, innovation
· Economic project for a company (flexibility is needed according to the real needs of a company)
· Compare and understand the complex interrelationships of KPI / KRIS with practice and standards
Using the previous project and work done in the WIPRO "KPI Security Assessment" a prototype will be created with the made recommendations.