Search
Program Calendar
Browse By Day
Search Tips
Virtual Exhibit Hall
Personal Schedule
Sign In
Measures of information security activities and overall effectiveness are not readily available to researchers. Consequently, researchers often rely upon self-reported qualitative measures. However, this approach raises issues concerning both the scope and the reliability of data collected. This study avoids such concerns by using rich, holistic scales (the COBIT 4.1 Maturity Model rubrics) created by a professional organization. Our results suggest that the COBIT 4.1 Maturity Model rubrics may be a useful tool for information security researchers.
We show that the COBIT rubric scores reliably predict both subjective (i.e., an overall grade) and objective (security incidents) measures of information security effectiveness.
Paul J Steinbart, Arizona State University
Robyn L Raschke, University of Nevada-Las Vegas
Graham Gal, University of Massachusetts Amherst
William N Dilla, Iowa State University