EVALUATION OF INFORMATION SECURITY EFFECTIVENESS MEASURES UNDER UNCERTAINTY

被引:0
|
作者
Efimov, Evgeny [1 ]
Lapitskaya, Galina [1 ]
机构
[1] Rostov State Econ Univ, Fac Comp Technol & Informat Secur, Dept Informat Technol & Informat Protect, 69 Bolshaya Sadovaya St, Rostov Na Donu 344002, Russia
来源
关键词
information security; effectiveness; modeling; losses prevented;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Uncertainty of information security system properties is inherent at all stages of its life cycle due to real exposure to random factors of external and internal environment. As a project is implemented, the system uncertainty tends to reduce, but its operation efficiency can never be adequately expressed and described by deterministic parameters. In this case probabilistic methods are most applicable to evaluate efficiency of implementation and operation of information security systems. In accordance with these methods, levels of system safeguards are transformed into confidence levels of corresponding estimates. Under these conditions, data to evaluate effectiveness of information security enhancement measures can be obtained by using simulation modeling. A suggested methodology for information security impact assessment at a company implies modeling of estimates of losses avoided. The value of losses avoided can be calculated on the basis of the likelihood of an information security incident and resulting possible economic losses before and after implementation of information security measures at an object. Total losses avoided resulting from the simulation covering all information security incidents enable to specify and to carry out scenario-based calculations of potential effects of such measures. The final evaluation of information security enhancement measures can be performed by any known method. Globally a standard method of cost-benefit analysis (CBA) is widely used to evaluate effectiveness of IT projects. Implementation of the suggested information security enhancements evaluation methodology has been based on the CBA method. The main advantage of the proposed information security enhancements evaluation methodology is its ability to pay due regard to the real world uncertainty thanks to simulation modeling. This enables to some extent to increase the validity of evaluation estimates.
引用
收藏
页码:51 / 57
页数:7
相关论文
共 50 条
  • [1] Implementation and effectiveness of organizational information security measures
    Hagen, Janne Merete
    Albrechtsen, Eirik
    Hovden, Jan
    Information Management and Computer Security, 2008, 16 (04): : 377 - 397
  • [2] EVALUATION MEASURES AND GOAL CONGRUENCE UNDER UNCERTAINTY
    ITAMI, H
    JOURNAL OF ACCOUNTING RESEARCH, 1975, 13 (01) : 73 - 96
  • [3] The Effectiveness of Security Measures
    Christin, Nicolas
    COMMUNICATIONS OF THE ACM, 2022, 65 (09) : 92 - 92
  • [4] The effectiveness of strategic information systems planning under environmental uncertainty
    Newkirk, Henry E.
    Lederer, Albert L.
    INFORMATION & MANAGEMENT, 2006, 43 (04) : 481 - 501
  • [5] MEASURES OF UNCERTAINTY AND INFORMATION IN COMPUTATION
    PACKEL, EW
    TRAUB, JF
    WOZNIAKOWSKI, H
    INFORMATION SCIENCES, 1992, 65 (03) : 253 - 273
  • [6] Evaluation of the effectiveness of conservation practices under implementation site uncertainty
    Abouali, Mohammad
    Nejadhashemi, A. Pouyan
    Daneshvar, Fariborz
    Herman, Matthew R.
    Adhikari, Umesh
    Calappi, Timothy J.
    Selegean, James P.
    JOURNAL OF ENVIRONMENTAL MANAGEMENT, 2018, 228 : 197 - 204
  • [7] On Measures of Information Theoretic Security
    Liu, Shuiyin
    Hong, Yi
    Viterbo, Emanuele
    2014 IEEE INFORMATION THEORY WORKSHOP (ITW), 2014, : 309 - 310
  • [8] MEASURES OF RETURN UNDER UNCERTAINTY
    BAUMLER, JV
    OMEGA-INTERNATIONAL JOURNAL OF MANAGEMENT SCIENCE, 1975, 3 (01): : 101 - 105
  • [9] Effectiveness of the Information Security in the Banks
    Kirilov, Rosen
    CYBERNETICS AND INFORMATION TECHNOLOGIES, 2006, 6 (02) : 70 - 85
  • [10] POLICY EVALUATION UNDER UNCERTAINTY - APPROACH USING SUBJECTIVE INFORMATION
    TYDEMAN, J
    MITCHELL, R
    SOCIO-ECONOMIC PLANNING SCIENCES, 1978, 12 (05) : 277 - 284