4.2 Article

Assessing data cybersecurity using ISO/IEC 25012

Journal

SOFTWARE QUALITY JOURNAL
Volume 28, Issue 3, Pages 965-985

Publisher

SPRINGER
DOI: 10.1007/s11219-019-09494-x

Keywords

Data cybersecurity; Data evaluation; Data certification; ISO; IEC 25012; GDPR

Funding

  1. CDTI
  2. ECD project by Torres Quevedo Program of the Spanish Ministry of Economy, Industry and Competitiveness [INNO-20171086, PT3Q-16-08504]
  3. CYBERDATA project by Consejeria de Economia, Empresas y Empleo JCCM [(ISO/IEC 14598-1 1999)/17/IN/013]
  4. FEDER (Fondo Europeo de Desarrollo Regional)
  5. ECLIPSE project (Ministerio de Ciencia, Innovacion y Universidades)
  6. ECLIPSE project (Fondo Europeo de Desarrollo Regional FEDER) [RTI2018-094283-B-C31]
  7. TESTIMO project (Consejeria de Educacion, Cultura y Deportes de la Junta de Comunidades de Castilla La Mancha)
  8. TESTIMO project (Fondo Europeo de Desarrollo Regional FEDER) [SBPLY/17/180501/000503]

Ask authors/readers for more resources

Data is of ever-growing importance and is widely considered to be a company's most valuable asset. Since data is becoming the main driver of business value, data quality and, specifically, data security are of paramount importance to companies. Various regulations related to data cybersecurity have been drawn up, such as the GDPR and the Cybersecurity Act, thus proving the importance placed on data cybersecurity by influential legislative institutions. Several standards related to security have emerged in recent years, most notably those of the ISO/IEC 27000 series. They are, however, focused on management systems and security infrastructure and ignore the security of the data itself. Other standards related to data quality, such as ISO 8000, also fail to address data security in depth. This paper, therefore, proposes a framework for the evaluation of data cybersecurity, consisting of a quality model, an evaluation process, and a tool for the visualization of the assessment results. This evaluation framework has been employed as the basis for a data cybersecurity certification scheme, which complements other certifiable standards related to data and security, such as ISO/IEC 27001 and ISO 8000. This work additionally presents the results of a pilot project in which the data cybersecurity of a commercial product was evaluated. The results of this pilot application allowed us to validate the feasibility of the evaluation framework defined.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.2
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available