On metrics and prioritization of investments in hardware security

被引:1
|
作者
Collier, Zachary A. [1 ]
Briglia, Brett [2 ]
Finkelston, Tom [2 ]
Manasco, Mark C. [3 ]
Slutzky, David L. [2 ]
Lambert, James H. [2 ]
机构
[1] Radford Univ, Radford, VA 24142 USA
[2] Univ Virginia, Charlottesville, VA USA
[3] Commonwealth Ctr Adv Logist Syst, Petersburg, VA USA
基金
美国国家科学基金会;
关键词
hardware security; key performance indicators; return on security investment (ROSI); risk management; security economics; systems engineering; CYBER RISK;
D O I
10.1002/sys.21667
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The security risks posed by electronics are numerous. There are typically a variety of risk-reducing countermeasures for a given system or across an enterprise. Each countermeasure is associated with both a level of risk reduction and its lifecycle costs. Given budgetary constraints, risk managers and systems engineers must determine what combinations of countermeasures cost-effectively maximize risk reduction, and what metrics best guide the investment process. In this paper, we seek to answer these questions through exploration of risk reduction metrics from the field of security economics, including the benefit/cost ratio, return on security investment (ROSI), expected benefit of information security (EBIS), and expected net benefit of information security (ENBIS). The results suggest that ratio-based metrics are not strongly correlated with risk reduction, while EBIS is equivalent to risk reduction and ENBIS is equal to risk reduction minus cost.
引用
收藏
页码:425 / 437
页数:13
相关论文
共 50 条
  • [41] Alternative Investments in Voluntary Pension Security
    Kowalczyk-Rolczynska, Patrycja
    Rolczynski, Tomasz
    [J]. EUROPEAN FINANCIAL SYSTEM 2016: PROCEEDINGS OF THE 13TH INTERNATIONAL SCIENTIFIC CONFERENCE, 2016, : 373 - 379
  • [42] The Roles of IT Strategies and Security Investments in Reducing Organizational Security Breaches
    Li, He
    Yoo, Sungjin
    Kettinger, William J.
    [J]. JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2021, 38 (01) : 222 - 245
  • [43] Hardware Security in IoT Devices with Emphasis on Hardware Trojans
    Sidhu, Simranjeet
    Mohd, Bassam J.
    Hayajneh, Thaier
    [J]. JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2019, 8 (03)
  • [44] Hardware Trojans and Smart Manufacturing - A Hardware Security Perspective
    Aslam, Sohaib
    Samie, Mohammad
    Jennions, Ian K.
    [J]. ADVANCES IN MANUFACTURING TECHNOLOGY XXXII, 2018, 8 : 305 - 310
  • [45] Weak and Strong Compensation for the Prioritization of Public Investments: Multidimensional Analysis for Pools
    De Mare, Gianluigi
    Granata, Maria Fiorella
    Nestico, Antonio
    [J]. SUSTAINABILITY, 2015, 7 (12) : 16022 - 16038
  • [46] A Security Perspective on Publication Metrics
    Jonker, Hugo
    Mauw, Sjouke
    [J]. SECURITY PROTOCOLS XXV, 2017, 10476 : 186 - 200
  • [47] A SECURITY METRICS FRAMEWORK FOR THE CLOUD
    Luna, Jesus
    Ghani, Hamza
    Gemianus, Daniel
    Suni, Neeraj
    [J]. SECRYPT 2011: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2011, : 245 - 250
  • [48] Quality of security metrics and measurements
    Savola, Reijo M.
    [J]. COMPUTERS & SECURITY, 2013, 37 : 78 - 90
  • [49] Designing Good Security Metrics
    Yee, George O. M.
    [J]. 2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 2, 2019, : 580 - 585
  • [50] Multi-criteria prioritization of asset management investments in the power industry
    Biard, Gabrielle
    Abdul-Nour, Georges
    Komljenovic, Dragan
    Pelletier, Stephane
    [J]. IFAC PAPERSONLINE, 2022, 55 (10): : 1804 - 1809