Enhancing Organizational Resilience Through Information Security Performance Measurement: A Structured Approach

Document Type

Conference Proceeding

Source of Publication

Lecture Notes in Networks and Systems

Publication Date

7-2-2026

Abstract

In an increasingly digital world, organizations must not only implement security controls but also measure and manage their effectiveness as a strategic priority to stay resilient against evolving threats. Information Security Performance Measurement (ISPM) enables organizations to monitor, improve, and justify their security investments. This paper explores the theoretical foundations, tiered security metrics (implementation, effectiveness, and impact), and practical applications of ISPM, with an emphasis on industry-standard frameworks such as NIST SP 800-55 and ISO/IEC 27004, highlighting their complementary roles in building measurement systems within an Information Security Management System (ISMS). It also investigates real-world use cases, challenges in implementation, and how organizations can align ISPM with business and compliance goals. Additionally, the paper examines the role of modern tools such as SIEMs, GRC platforms, BI dashboards, and automation in enabling real-time monitoring and decision support. The discussion also covers emerging trends, such as AI-driven analytics and cyber risk quantification, and includes real-world case studies. The findings highlight that mature performance measurement systems are essential for achieving strategic security objectives, enabling regulatory compliance, and fostering a resilient organizational culture.

ISBN

[9783032211736]

ISSN

2367-3370

Publisher

Springer Nature Switzerland

Volume

1889 LNNS

First Page

362

Last Page

373

Disciplines

Computer Engineering

Keywords

Cybersecurity, Information Security, ISMS, ISO/IEC 27001, ISPM, NIST SP 800-55, Performance Metrics, Risk Management

Scopus ID

105047650721

Indexed in Scopus

yes

Open Access

no

Share

COinS