Maturity of organisational security governance
A case study at Damen Naval
M.R. Renne (TU Delft - Technology, Policy and Management)
S.E. Parkin – Mentor (TU Delft - Technology, Policy and Management)
G. van de Kaa – Graduation committee member (TU Delft - Technology, Policy and Management)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
Existing research has shown that due to increasing digitalization and the adoption of digital technologies and complex (big) data solutions, along with higher firm-level productivity, there is a growing and more dynamic threat environment. Organisations rely on data and digital environments. These environments enlarge the potential attack surface, as every endpoint device or network node is a potential entry point for malicious actors. The (un)intentional insider threat is also increasingly important for the protection of intellectual property (IP) and business assets. Not only has the attack surface grown over the years, but also the consequences of security breaches have become more severe. Loss of confidentiality, integrity, and availability can disrupt working practices or threaten organisational continuity.
The stakes for organisational security have therefore never been higher. Current trends include increasing oversight and strict regulations via internal policy and external regulators. Extant literature also emphasises increased security spending and technical measures to protect business assets. This paper proposes a framework for determining the maturity of security governance within organisations. Security governance concerns the alignment of business and security goals. Good governance means that both goals are achieved without conflict, and preferably in a complementary way.
The research argues that security governance consists of more than technical measures and punitive oversight. It also departs from views that more security (spending, measures, policies) is always better and that security is addressed in isolation. Instead, security governance should align with the organisation’s business. Literature shows that security and productivity can conflict. Therefore, maturity is introduced, focusing on alignment between security and business goals. A conventional view of maturity assesses effectiveness in improving either security or productivity. A social view of maturity focuses on how alignment is achieved, emphasising dialogue between stakeholders rather than top-down imposition of policies.
A case study at Damen Naval, a large naval shipbuilding organisation relying heavily on IP and operating under strict regulations, was conducted. Data were collected through literature review, interviews, and a focus group, across three security fields: access control, data classification, and monitoring & incident response. A framework was developed combining a conventional assessment of governance maturity with a social dimension of alignment.
The framework is based on six dimensions of security governance: (1) organisation-wide security responsibility and accountability, (2) risk-based approach, (3) acquisition direction and resource commitment, (4) compliance with internal and external requirements, (5) security-conscious culture, and (6) security performance measurement and alignment. These dimensions guided interviews and produced performance indicators. The indicators are applicable across all security fields, showing organisation-wide generalisability.
Results led to practical recommendations for Damen Naval, including empowering engineers in data classification decisions, clarifying performance expectations, and ensuring that additional effort caused by security measures is not absorbed by engineers. It is also recommended to better quantify the total costs of security measures, both direct and indirect, to improve transparency and policy evaluation.
The final stage examined concordance in security governance using a focus group and a doctor–patient metaphor of negotiated treatment. While such a model is difficult in large organisations and constrained by external regulation, results indicate that concordance is possible at intra- and inter-organisational levels. Intra-organisationally, representation from business, ICT, and security should be ensured to support alignment. Inter-organisationally, dialogue with regulators should be strengthened. The framework and indicators allow systematic identification of misalignment and support structured discussion. Future research should extend the framework toward a Capability Maturity Model (CMM) and include external regulators in case studies.