EVALUATION OF INFORMATION SECURITY EFFECTIVENESS MEASURES UNDER UNCERTAINTY

被引:0
|
作者
Efimov, Evgeny [1 ]
Lapitskaya, Galina [1 ]
机构
[1] Rostov State Econ Univ, Fac Comp Technol & Informat Secur, Dept Informat Technol & Informat Protect, 69 Bolshaya Sadovaya St, Rostov Na Donu 344002, Russia
来源
关键词
information security; effectiveness; modeling; losses prevented;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
Uncertainty of information security system properties is inherent at all stages of its life cycle due to real exposure to random factors of external and internal environment. As a project is implemented, the system uncertainty tends to reduce, but its operation efficiency can never be adequately expressed and described by deterministic parameters. In this case probabilistic methods are most applicable to evaluate efficiency of implementation and operation of information security systems. In accordance with these methods, levels of system safeguards are transformed into confidence levels of corresponding estimates. Under these conditions, data to evaluate effectiveness of information security enhancement measures can be obtained by using simulation modeling. A suggested methodology for information security impact assessment at a company implies modeling of estimates of losses avoided. The value of losses avoided can be calculated on the basis of the likelihood of an information security incident and resulting possible economic losses before and after implementation of information security measures at an object. Total losses avoided resulting from the simulation covering all information security incidents enable to specify and to carry out scenario-based calculations of potential effects of such measures. The final evaluation of information security enhancement measures can be performed by any known method. Globally a standard method of cost-benefit analysis (CBA) is widely used to evaluate effectiveness of IT projects. Implementation of the suggested information security enhancements evaluation methodology has been based on the CBA method. The main advantage of the proposed information security enhancements evaluation methodology is its ability to pay due regard to the real world uncertainty thanks to simulation modeling. This enables to some extent to increase the validity of evaluation estimates.
引用
收藏
页码:51 / 57
页数:7
相关论文
共 50 条
  • [21] Information Structures in an Ordered Information System Under Granular Computing View and Their Optimal Selection Based on Uncertainty Measures
    Yini Wang
    Sichun Wang
    Hongxiang Tang
    International Journal of Computational Intelligence Systems, 2020, 13 : 1619 - 1635
  • [22] Information Structures in an Ordered Information System Under Granular Computing View and Their Optimal Selection Based on Uncertainty Measures
    Wang, Yini
    Wang, Sichun
    Tang, Hongxiang
    INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2020, 13 (01) : 1619 - 1635
  • [23] Assessment of the Effectiveness of an Information Security System
    Zegzhda, D. P.
    Saurenko, T. N.
    Anisimov, V. G.
    Anisimov, E. G.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2023, 57 (08) : 855 - 861
  • [24] Assessment of the Effectiveness of an Information Security System
    D. P. Zegzhda
    T. N. Saurenko
    V. G. Anisimov
    E. G. Anisimov
    Automatic Control and Computer Sciences, 2023, 57 : 855 - 861
  • [25] Measuring effectiveness of information security management
    Liu Hong-li
    Zhu Ying-ju
    2009 INTERNATIONAL SYMPOSIUM ON COMPUTER NETWORK AND MULTIMEDIA TECHNOLOGY (CNMT 2009), VOLUMES 1 AND 2, 2009, : 1212 - 1215
  • [26] Information structures and uncertainty measures in a fully fuzzy information system
    Li, Zhaowen (lizhaowen8846@126.com), 1600, Elsevier Inc. (101):
  • [27] Information structures and uncertainty measures in a fully fuzzy information system
    Zhang, Gangqiang
    Li, Zhaowen
    Wu, Wei-Zhi
    Liu, Xiaofeng
    Xie, Ningxin
    INTERNATIONAL JOURNAL OF APPROXIMATE REASONING, 2018, 101 : 119 - 149
  • [28] Information structures and uncertainty measures in a hybrid information system with images
    Guangji Yu
    Soft Computing, 2019, 23 : 12961 - 12979
  • [29] Information structures and uncertainty measures in a hybrid information system with images
    Yu, Guangji
    SOFT COMPUTING, 2019, 23 (24) : 12961 - 12979
  • [30] 'VALUE OF INFORMATION UNDER UNCERTAINTY'.
    Takaharu, Hirai
    Memoirs of the Kyushu University, Faculty of Engineering, 1986, 46 (01): : 31 - 48