{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,31]],"date-time":"2025-12-31T12:05:48Z","timestamp":1767182748764,"version":"3.40.3"},"publisher-location":"Cham","reference-count":10,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031057595"},{"type":"electronic","value":"9783031057601"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,5,14]],"date-time":"2022-05-14T00:00:00Z","timestamp":1652486400000},"content-version":"vor","delay-in-days":133,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>This paper introduces a method for evaluating information security levels of organisations using a developed framework. The framework is based on Estonian Information Security Standard categories which is compatible with ISO 27001 standard. The framework covers both technical and organisational aspects of information security.<\/jats:p><jats:p>The results provide an overview of security to the organisation\u2019s management, compare different organisations across the region, and support strategic decision-making on a national level.\n<\/jats:p>","DOI":"10.1007\/978-3-031-05760-1_39","type":"book-chapter","created":{"date-parts":[[2022,5,13]],"date-time":"2022-05-13T07:03:06Z","timestamp":1652425386000},"page":"644-652","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Method for Evaluating Information Security Level in Organisations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9066-2467","authenticated-orcid":false,"given":"Mari","family":"Seeba","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1599-8649","authenticated-orcid":false,"given":"Sten","family":"M\u00e4ses","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1829-4794","authenticated-orcid":false,"given":"Raimundas","family":"Matulevi\u010dius","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,5,14]]},"reference":[{"issue":"10","key":"39_CR1","first-page":"26","volume":"64","author":"R Bannam","year":"2017","unstructured":"Bannam, R.: Cyber scorekeepers: a growing number of ratings firms aim to help companies and their insurers assess and manage cybersecurity risks. Risk Manage. 64(10), 26\u201330 (2017)","journal-title":"Risk Manage."},{"key":"39_CR2","unstructured":"Center of Internet Security: Blog | CIS Introduces v2.0 of the CIS Community Defense Model, September 2021. https:\/\/www.cisecurity.org\/blog\/cis-introduces-v2-0-of-the-cis-community-defense-model\/"},{"key":"39_CR3","doi-asserted-by":"crossref","unstructured":"Le, N.T., Hoang, D.B.: Can maturity models support cyber security? In: 2016 IEEE 35th International Performance Computing and Communications Conference (IPCCC), pp. 1\u20137 (2016)","DOI":"10.1109\/PCCC.2016.7820663"},{"key":"39_CR4","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1016\/j.cose.2013.12.003","volume":"42","author":"K Parsons","year":"2014","unstructured":"Parsons, K., McCormac, A., Butavicius, M., Pattinson, M., Jerram, C.: Determining employee awareness using the human aspects of information security questionnaire (HAIS-Q). Comput. Secur. 42, 165\u2013176 (2014)","journal-title":"Comput. Secur."},{"issue":"3","key":"39_CR5","doi-asserted-by":"publisher","first-page":"45","DOI":"10.2753\/MIS0742-1222240302","volume":"24","author":"K Peffers","year":"2007","unstructured":"Peffers, K., Tuunanen, T., Rothenberger, M.A., Chatterjee, S.: A design science research methodology for information systems research. J. Manage. Inf. Syst. 24(3), 45\u201377 (2007)","journal-title":"J. Manage. Inf. Syst."},{"issue":"4","key":"39_CR6","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1109\/MSP.2010.60","volume":"8","author":"SL Pfleeger","year":"2010","unstructured":"Pfleeger, S.L., Cunningham, R.K.: Why measuring security is hard. IEEE Secur. Priv. Mag. 8(4), 46\u201354 (2010)","journal-title":"IEEE Secur. Priv. Mag."},{"key":"39_CR7","unstructured":"RIA (Estonian Information System Authority): E-ITS. https:\/\/eits.ria.ee\/"},{"key":"39_CR8","doi-asserted-by":"publisher","unstructured":"Seeba, M.: Estonian Information Security Standard (E-ITS) Based Security Level Evaluation Instrument (2021). https:\/\/doi.org\/10.23673\/re-298","DOI":"10.23673\/re-298"},{"key":"39_CR9","doi-asserted-by":"crossref","unstructured":"Shukla, A., Katt, B., Nweke, L.O., Yeng, P.K., Weldehawaryat, G.K.: System security assurance: a systematic literature review. arXiv:2110.01904 [cs] (2021)","DOI":"10.1016\/j.cosrev.2022.100496"},{"key":"39_CR10","doi-asserted-by":"crossref","unstructured":"Woods, D.W., B\u00f6hme, R.: SoK: quantifying cyber risk. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 211\u2013228 (2021)","DOI":"10.1109\/SP40001.2021.00053"}],"container-title":["Lecture Notes in Business Information Processing","Research Challenges in Information Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-05760-1_39","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,12]],"date-time":"2024-03-12T15:57:08Z","timestamp":1710259028000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-05760-1_39"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031057595","9783031057601"],"references-count":10,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-05760-1_39","relation":{},"ISSN":["1865-1348","1865-1356"],"issn-type":[{"type":"print","value":"1865-1348"},{"type":"electronic","value":"1865-1356"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"14 May 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"RCIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Research Challenges in Information Science","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Barcelona","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 May 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 May 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"rcis2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.rcis-conf.com\/rcis2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}