Brown University

Can We Trust Security Ratings? - Use and Credibility of Third-party Security Vendor Security Ratings

Description

Abstract:
This paper explores the questions about whether we can trust security ratings and how we should use them. My approaches are, (1) describing traditional and currently used vendor evaluation methods such as questionnaire, interview, and site-visits, (2) introducing security ratings, including the merits of using security ratings, use cases, limitations, and (3) conducting interviews and using a questionnaire for cybersecurity experts. According to my research, security ratings are quick, cost-effective, and objective; but at the same time, have limitations that security ratings are based on publicly available information and do not consider internal security measures. Due to such a feature, however, security ratings give us a quick view of the security posture of a vendor and tell us whether we should do further due diligence on what aspect. Therefore, I conclude that the security shall be used as a supplement to our vendor due diligence.
Notes:
Capstone (EMCS)--Brown University, 2020

Access Conditions

Rights
In Copyright
Restrictions on Use
All rights reserved. Collection is open for research.

Citation

Koyama, Shunsuke, "Can We Trust Security Ratings? - Use and Credibility of Third-party Security Vendor Security Ratings" (2020). Master of Science in Cybersecurity. Brown Digital Repository. Brown University Library. https://doi.org/10.26300/gvwn-0s71

Relations

Collection:

  • Master of Science in Cybersecurity

    Brown's Master of Science (ScM) in Cybersecurity is a program for professionals designed to cultivate high-demand, industry executives with the unique and critical ability to devise and execute integrated, comprehensive cybersecurity strategies. Students gain immediately applicable knowledge and, through an …
    ...