Sie sind auf Seite 1von 6

Identity Privacy

Risks scorecard
helps to
measure and
control privacy
related risks

Identity Privacy Risks


Perspective

Performance

Computer protection

66.96%

Identity information structure

43.75%

Process efficiency

44.70%

Staff effectiveness

51.39%

Financial Perspective
Total Performance

61.11%
53.58%

Scorecard includes 5 categories, 16 indicators

Help
- You can change the values in "weight" column, the value must be between 0 and 10;
"10" value means that the perspective or goal is the most valuable
- You can change the values in "Performance" column;

Strategy tree and scorecard details :


Perspective
Goal
Computer protection

Weight
(x of 10)

Description

66.96%

System
compliance

Number of users and network devices that


are security policy compliant, divided by
the total number of users/devices on the
1 network, multiplied by 100

Incident
Forensics

The number of incidents attributable to


policy failures divided by the total number
1 of incidents, multiplied by 100

Total Performance in group

Identity information structure

Performance
(%)

Computer protection

60%

25%
66.96%

43.75%

Identity
repository size

The total number of accounts, groups, and


other objects of interest clustered by the
1 identity provider or relying party

2%

Secured objects

The number of accounts, groups, and other


objects
of interest with a sufficient level of security
divided by the total number of accounts,
groups, and other objects of interest
clustered by the identity provider or relying
1 party, multiplied by 100

40%

Provisioning
process
coverage

The number of identity repositories and


subjects the provisioning system governs,
divided by the total number of repositories
(including repositories that rely on custom
or ad hoc provisioning processes),
1 multiplied by 100

30%

Identity
assurance

The number of identity repositories that


use proven, standards-based
authentication and authorization protocols
divided by the total number of repositories
(including repositories that rely on customcoded access control mechanisms),
1 multiplied by 100

Total Performance in group

Process efficiency

Identity information structure

70%
43.75%

44.70%

Provisioning
process
efficiency

The length of time from the initial request


to the time the subject is
provisioned or terminated in the identity
repository, compared with the industry best
1 practices

40%

Authorization
claims

The number of rejected claims for


authorization, divided by the total number
1 of authorization claims, multiplied by 100

30%

Sensitive claims

The number of claims whose release


would injure the subject, identity provider,
or relying party, divided by the total number
1 of authorization claims, multiplied by 100

20%

Provisioning
geodesics

The lengths a digital identity claim


traverses to complete processes such as
account creation, registration, and
provisioning, compared with the industry
1 best practices

30%

Total Performance in group

Staff effectiveness

Process efficiency

44.70%

51.39%

User account
statistics

The number of accounts associated with all


users, divided by the total number of users,
1 multiplied by 100

Identity proofing
strength

The strength of secrets used for each user


1 authentication

1%

Audit system
usage

The number of successful user


authentication events, divided by the total
number of authentication events, multiplied
1 by 100

60%

Policy
compliance

The number of users compliant with each


element of the security policy divided by
1 the total number of users, multiplied by 100

40%

Total Performance in group

Financial Perspective

Staff effectiveness

51.39%

61.11%

Return on
Security
Investment

The financial benefit of security investment


divided by the cost of the investment,
1 multipled by 100

Collateral
damage
potential (CDP)

The quantification of potential damage in


physical assets, property as a result of a
1 security breach

Total Performance in group

300%

Financial Perspective

Total Performance in Identity Privacy Risks

60%

2%
61.11%

53.58%

Powered by

Balanced Scorecard Designer

Target
Values

Max
Real
Performance Performance

90%

0.01

0.00625

10%

5%

0.01

0.0071428571

75%

0.02

0.0133928571

0.01

0.005

1%

100%

0.01

0.0033333333

10%

90%

0.01

0.0025

10%

3% 1-small, 2-medium,

100%

0.01

0.0066666667

0.04

0.0175

120%

0.01

0.0027272727

10%

0%

0.01

0.006

75%

0%

0.01

0.0073333333

75%

120%

0.01

0.0018181818

10%

0.04

0.0178787879

0.01

0.0066666667

600%

0.01

0.005

0%

100%

0.01

0.0055555556

10%

100%

0.01

0.0033333333

10%

0.04

0.0205555556

0.01

0.0055555556

10%

0.01

0.0066666667

0%

0.02

0.0122222222

150%

2% 0-low, 1-medium, 2

100%

3% 0-None, 1-low, 2-m

10%

Das könnte Ihnen auch gefallen