A Quantitative Model for Information-Security Risk Management

被引:21
|
作者
Bojanc, Rok [1 ]
Jerman-Blazic, Borka [2 ]
机构
[1] ZZI, Ljubljana, Slovenia
[2] Univ Ljubljana, Ljubljana 61000, Slovenia
关键词
Risk Management; Risk Assessment; Information Security; Optimal Investment; Quantitative Evaluation; ECONOMICS;
D O I
10.1080/10429247.2013.11431972
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Information-security risk management is becoming an increasingly important process in modern businesses. The proposed model for managing information-security risks is based on a quantitative analysis of the security risks that enable organizations to introduce optimum security solutions. The model is designed as a standard procedure to lead the organization from the initial selection of input data to the final recommendations for the selection of the appropriate solutions, which reduces a certain security risk. In analyzing the security risks, the model quantitatively evaluates the information assets, their vulnerability, and the threats to information assets. The values of the risk parameters are the basis for selecting the appropriate risk treatment and the evaluation of the various security measures that reduce security risks. Economic indicators are determined for each security measure in order to enable a comparison of the various security measures. This includes the possibility of investing in technology-security solutions, the introduction of organizational procedures, and the training and transfer of risk to an outsourcing provider or to an insurance agency. The model was tested using empirical examples with data from a real business environment.
引用
收藏
页码:25 / 37
页数:13
相关论文
共 50 条
  • [21] A Model to Assess the Maturity Level of the Risk Management Process in Information Security
    Mayer, Janice
    Fagundes, Leonardo Lemes
    [J]. 2009 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT - WORKSHOPS, 2009, : 61 - 70
  • [22] The Quantification Management of Information Security Risk
    Lao, Guoling
    Wang, Liping
    [J]. 2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 10377 - 10380
  • [23] An Ontology-Based Security Risk Management Model for Information Systems
    Arogundade, Oluwasefunmi T.
    Abayomi-Alli, Adebayo
    Misra, Sanjay
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (08) : 6183 - 6198
  • [24] A New Evaluation Model for Information Security Risk Management of SCADA Systems
    Lin, Kuo-Sui
    [J]. 2019 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER PHYSICAL SYSTEMS (ICPS 2019), 2019, : 757 - 762
  • [25] Information security risk management model for mitigating the impact on SMEs in Peru
    Carnero Garay, Daniel Felipe
    Antonio, Marcos
    Ramos, Carbajal
    Armas-Aguirre, Jimmy
    Madrid Molina, Juan Manuel
    [J]. 2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [26] An Ontology-Based Security Risk Management Model for Information Systems
    Oluwasefunmi T. Arogundade
    Adebayo Abayomi-Alli
    Sanjay Misra
    [J]. Arabian Journal for Science and Engineering, 2020, 45 : 6183 - 6198
  • [27] Including technical and security risks in the management of information systems: A programmatic risk management model
    Dillon, Robin L.
    Paté-Cornell, M. Elisabeth
    [J]. Systems Engineering, 2005, 8 (01) : 15 - 28
  • [28] Information security management: An information security retrieval and awareness model for industry
    Kritzinger, E.
    Smith, E.
    [J]. COMPUTERS & SECURITY, 2008, 27 (5-6) : 224 - 231
  • [29] From information security management to enterprise risk management
    Stoll, Margareth
    [J]. Lecture Notes in Electrical Engineering, 2015, 313 : 9 - 16
  • [30] Enterprise Risk Management and Information Systems Security Risk
    Olson, David L.
    Wu, Desheng
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON RISK MANAGEMENT & GLOBAL E-BUSINESS, VOLS I AND II, 2009, : 1 - 5