Show/Hide Menu
Hide/Show Apps
Logout
Türkçe
Türkçe
Search
Search
Login
Login
OpenMETU
OpenMETU
About
About
Open Science Policy
Open Science Policy
Open Access Guideline
Open Access Guideline
Postgraduate Thesis Guideline
Postgraduate Thesis Guideline
Communities & Collections
Communities & Collections
Help
Help
Frequently Asked Questions
Frequently Asked Questions
Guides
Guides
Thesis submission
Thesis submission
MS without thesis term project submission
MS without thesis term project submission
Publication submission with DOI
Publication submission with DOI
Publication submission
Publication submission
Supporting Information
Supporting Information
General Information
General Information
Copyright, Embargo and License
Copyright, Embargo and License
Contact us
Contact us
Continuous improvement on maturity and capability of security operation centers
Download
index.pdf
Date
2019
Author
Erdur, Efe Suat
Metadata
Show full item record
This work is licensed under a
Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License
.
Item Usage Stats
318
views
290
downloads
Cite This
This thesis has been studied to define the importance of maturity and capability assessment, and continuous improvement for Security Operation Centers (SOC). Additionally, it aims contribute to the academic literature to fill the research gap in this specific domain as well. The main focus of this thesis is to combine those two important concepts under same study and define a methodology to provide Security Operation Centers' a self-assessment capability which also evaluates the gaps between current and desired states of the organization and determine the most critical aspects that are suggested to be improved at first. The applicability of the methodology has been supported with a use case scenario. More importantly, it is evaluated using conversational analysis methodology of qualitative analyze approach and evaluation results have been presented at the final part of the thesis report.
Subject Keywords
Database security.
,
Security Operations Center
,
Maturity and Capability Assessment
,
Continuous Improvement.
URI
http://etd.lib.metu.edu.tr/upload/12624864/index.pdf
https://hdl.handle.net/11511/45040
Collections
Graduate School of Informatics, Thesis
Suggestions
OpenMETU
Core
Continuous improvement on maturity and capability of Security Operation Centres
Acartürk, Cengiz; Erdur, Efe (2020-12-01)
This study addresses maturity and capability assessment of Security Operation Centres (SOC). It aims to contribute to continuous improvement for SOCs by proposing a complementary methodology that provides SOCs a self-assessment capability. The method basically involves an assessment of the gaps between the current and the desired states of the organization and facilitates determining critical aspects that have priority. The proposed methodology is based on the define, measure, analyze, improve, and control ...
A review on capability and maturity models of building ınformation modelling
Yılmaz, Gökçen; Akçamete Güngör, Aslı; Demirörs, Onur (null; 2017-07-07)
Process assessment and maturity models in software engineering are widely used for process improvement. Likewise, assessing BIM capability and maturity have important effects on increasing BIM performance and enhancing benefits of BIM usage. Thus, there are various BIM capability and maturity models in the literature which are important for users to be able to select appropriate model for their BIM assessment purposes. This study aims to identify and analyse BIM capability and maturity models in the constru...
A Decision Support System for Optimal Selection of Enterprise Information Security Preventative Actions
Sonmez, Ferda Ozdemir; Günel Kılıç, Banu (2021-09-01)
Types and complexity of information security related vulnerabilities are growing rapidly and present numerous challenges to the enterprises. One of the key challenges is to identify the optimal set of precautions with limited budget. Despite the fact that majority of enterprises have a budget constraint for installing and maintaining the protection systems, the majority of the previous work only focus on prioritization of security targets and do not consider the preventative actions and budget constraints. ...
Comparison of Intelligent Classification Techniques by Practicing a Specific Technology Audit
Berkol, A.; Kara, G.; Turk, A. (2016-09-08)
Technology audit activities arc carried out for assessment of firms' technological requirements, capacity or management capability. The aim of these assessments is to define the weaknesses of firms and develop actions in order to improve firms' technological capacity and/or technology management capability. Generally these activities are implemented with survey questionnaires. These questionnaires can be filled by managers of firms or can be implemented as an interview by independent experts. However, evalu...
Prioritization of interdependent uncertainties in projects
Qazi, Abroon; Dikmen Toker, İrem; Birgönül, Mustafa Talat (2020-08-01)
Purpose The purpose of this paper is to address the limitations of conventional risk matrix based tools such that both positive and negative connotation of uncertainty could be captured within a unified framework that is capable of modeling the direction and strength of causal relationships across uncertainties and prioritizing project uncertainties as both threats and opportunities. Design/methodology/approach Theoretically grounded in the frameworks of Bayesian belief networks (BBNs) and interpretive stru...
Citation Formats
IEEE
ACM
APA
CHICAGO
MLA
BibTeX
E. S. Erdur, “Continuous improvement on maturity and capability of security operation centers,” Thesis (M.S.) -- Graduate School of Informatics. Cyber Security., Middle East Technical University, 2019.