New operational measures improve information security management across organizations.
The article discusses how to measure the effectiveness of information security management by using tools to collect, analyze, and report data. It focuses on using ISO/IEC 27002 controls to assess security measures. The researchers suggest operational measures based on departments to help make decisions and enhance information security management. They also propose a process for evaluating the effectiveness of information security management.