An economic modelling approach to information security risk management

被引:89
|
作者
Bojanc, Rok
Jerman-Blazic, Borka [1 ]
机构
[1] Univ Ljubljana, Fac Econ, Ljubljana, Slovenia
关键词
ICT security tools; risk management; technology investment;
D O I
10.1016/j.ijinfomgt.2008.02.002
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
This paper presents ail approach enabling economic modelling of information security risk management in contemporaneous businesses and other organizations. In the world of permanent cyber attacks to ICT systems, risk management is becoming a crucial task for minimization of the potential risks that can endeavor their operation. The prevention of the heavy losses that may happen due to cyber attacks and other information system failures in an organization is usually associated with Continuous investment in different security measures and purchase of data protection systems. With the rise of the potential risks the investment in security services and data protection is growing and is becoming a serious economic issue to many organizations and enterprises. This paper analyzes several approaches enabling assessment of the necessary investment in security technology from the economic point of view. The paper introduces methods for identification of the assets, the threats, the vulnerabilities of the ICT systems and proposes a procedure that enables selection of the optimal investment of the necessary security technology based on the quantification of the values of the protected systems. The possibility of using the approach for an external insurance based on the quantified risk analyses is also provided. (C) 2008 Elsevier Ltd. All rights reserved.
引用
收藏
页码:413 / 422
页数:10
相关论文
共 50 条
  • [1] Information risk and security modelling
    Zivic, P
    [J]. Data Mining, Intrusion Detection, Information Assurance, and Data Networks Security 2005, 2005, 5812 : 142 - 150
  • [2] Agile Approach with Kanban in Information Security Risk Management
    Dorca, Vasile
    Popescu, Sorin
    Munteanu, Radu, Jr.
    Chioreanu, Adrian
    Peleskei, Claudius
    [J]. PROCEEDING OF 2016 IEEE INTERNATIONAL CONFERENCE ON AUTOMATION, QUALITY AND TESTING, ROBOTICS (AQTR), 2016, : 19 - 24
  • [3] Towards a Systemic Approach for Information Security Risk Management
    Naudet, Yannick
    Mayer, Nicolas
    Feltus, Christophe
    [J]. PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 177 - 186
  • [4] The economic approach of information security
    Tsiakis, T
    Stephanides, G
    [J]. COMPUTERS & SECURITY, 2005, 24 (02) : 105 - 108
  • [5] INFORMATION SECURITY RISK MANAGEMENT: AN INTELLIGENCE- DRIVEN APPROACH
    Webb, Jeb
    Maynard, Sean
    Ahmad, Atif
    Shanks, Graeme
    [J]. AUSTRALASIAN JOURNAL OF INFORMATION SYSTEMS, 2014, 18 (03) : 391 - 404
  • [6] Implementing a risk management approach for optimizing information security systems
    Petrescu, Marius
    Stegaroiu, Ion
    Braboveanu, Mioara
    Petrescu, Anca-Gabriela
    Sirbu, Nicoleta
    [J]. BUSINESS TRANSFORMATION THROUGH INNOVATION AND KNOWLEDGE MANAGEMENT: AN ACADEMIC PERSPECTIVE, VOLS 1-2, 2010, : 304 - 309
  • [7] The Information Security Risk Management
    Semin, Valeriy G.
    Shmakova, Elena G.
    Los, Lexei B.
    [J]. PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE QUALITY MANAGEMENT,TRANSPORT AND INFORMATION SECURITY, INFORMATION TECHNOLOGIES (IT&QM&IS), 2017, : 106 - 109
  • [8] Information security and risk management
    Bodin, Lawrence D.
    Gordon, Lawrence A.
    Loeb, Martin P.
    [J]. COMMUNICATIONS OF THE ACM, 2008, 51 (04) : 64 - 68
  • [9] Towards a systematic approach for improving information security risk management methods
    Papadaki, Katerina
    Polemi, Nineta
    [J]. 2007 IEEE 18TH INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS, VOLS 1-9, 2007, : 3733 - +
  • [10] A Comprehensive Risk Management Approach to Information Security in Intelligent Transport Systems
    Vogt, Tom
    Spahovic, Edvin
    Doms, Thomas
    Seyer, Rainer
    Weiskirchner, Heinz
    Pollhammer, Klaus
    Raab, Thomas
    Rührup, Stefan
    Latzenhofer, Martin
    Schmittner, Christoph
    Hofer, Markus
    Bonitz, Arndt
    Kloibhofer, Carina
    Chlup, Sebastian
    [J]. SAE International Journal of Transportation Cybersecurity and Privacy, 2021, 4 (01):