Author
Listed:
- Šarūnas Grigaliūnas
(Department of Computer Sciences, Kaunas University of Technology, Studentu Str. 50, 51368 Kaunas, Lithuania
These authors contributed equally to this work.)
- Michael Schmidt
(Leibniz Supercomputing Centre, Boltzmann Str. 1, 85748 Garching, Germany
These authors contributed equally to this work.)
- Rasa Brūzgienė
(Department of Computer Sciences, Kaunas University of Technology, Studentu Str. 50, 51368 Kaunas, Lithuania
These authors contributed equally to this work.)
- Panayiota Smyrli
(Cyprus Research & Academic Network, 33 Neas Egkomis, Egkomi, Nicosia 2409, Cyprus
These authors contributed equally to this work.)
- Vladislav Bidikov
(Faculty of Computer Science and Engineering, Ss. Cyril and Methodius University in Skopje, “Rugjer Boshkovikj” 16, P.O. Box 393, 1000 Skopje, North Macedonia
These authors contributed equally to this work.)
Abstract
A surge in successful Information Security (IS) breaches targeting Research and Education (R&E) institutions highlights a pressing need for enhanced protection. Addressing this, a consortium of European National Research and Education Network (NREN) organizations has developed a unified IS framework. This paper aims to introduce the Security Baseline for NRENs and a security maturity model tailored for R&E entities, derived from established security best practices to meet the specific needs of NRENs, universities, and various research institutions. The models currently in existence do not possess a system to smoothly correlate varying requirement tiers with distinct user groups or scenarios, baseline standards, and existing legislative actions. This segmentation poses a significant hurdle to the community’s capacity to guarantee consistency, congruency, and thorough compliance with a cohesive array of security standards and regulations. By employing taxonomical engineering principles, a mapping of baseline requirements to other security frameworks and regulations has been established. This reveals a correlation across most regulations impacting R&E institutions and uncovers an overlap in the high-level requirements, which is beneficial for the implementation of multiple standards. Consequently, organizations can systematically compare diverse security requirements, pinpoint gaps in their strategy, and formulate a roadmap to bolster their security initiatives.
Suggested Citation
Šarūnas Grigaliūnas & Michael Schmidt & Rasa Brūzgienė & Panayiota Smyrli & Vladislav Bidikov, 2023.
"Leveraging Taxonomical Engineering for Security Baseline Compliance in International Regulatory Frameworks,"
Future Internet, MDPI, vol. 15(10), pages 1-37, October.
Handle:
RePEc:gam:jftint:v:15:y:2023:i:10:p:330-:d:1254900
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:15:y:2023:i:10:p:330-:d:1254900. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.