How Much Matter Probabilities in Information Security Quantitative Risk Assessment?

被引:0
|
作者
Devos, Jan [1 ]
Munteanu, Adrian [1 ]
Fotache, Doina [1 ]
机构
[1] Univ Ghent, B-9000 Ghent, Belgium
关键词
quantitative risk assessment; probabilities; empiricism; epistemology; space; time; cause; KNOWLEDGE;
D O I
暂无
中图分类号
F [经济];
学科分类号
02 ;
摘要
The starting point of this research essay is a critical review of two methods to conduct a quantitative analysis of information systems security risks: 1) Management of Risk: Guidance for Practitioners and 2) a cost model based on annual loss expectancy. We are focusing on these methods with a perspective that highlights the limits of both empiricism and the theoretical elements that underlie them. From an epistemological point of view we have considered the logical syntax of the two models, the semantics included in statements and the pragmatics of the scientific discourse: the use of models to demonstrate the risk assessment thesis, to solve the problems of risks in the human judgment versus mathematical calculus controversy. The major issues that we are discussing in this article imply various perspectives on scientific criteria, the choice among various theories and the structuring of problems proposed to be solved. We argue that the models that have been developed so far, the top-down approach (which involves well defined and well understood rules), as well as the demonstrations based on the induction method, cannot be applied in a lot of scenarios, because information systems, considered as a complex whole made up of various components, is primarily not a positivistic science solely described by mathematics. The main research question to be answered in this paper is: What are the limits of knowledge in probabilistic computations for information systems security risk assessment? Our purpose is to demonstrate the epistemological limits of the two models and the error of generalizing probability calculus using the interpretive approach.
引用
收藏
页码:45 / 57
页数:13
相关论文
共 50 条
  • [1] A new quantitative approach for information security risk assessment
    Asosheh, Abbas
    Dehmoubed, Bijan
    Khani, Amir
    [J]. 2009 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY, VOL 2, 2009, : 222 - +
  • [2] A new quantitative approach for information security risk assessment
    Asosheh, Abbas
    Dehmoubed, Bijan
    Khani, Amir
    [J]. ISI: 2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, 2009, : 229 - 229
  • [3] Methodology of quantitative risk assessment for information system security
    Lin, MQ
    Wang, QM
    Li, JH
    [J]. COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 526 - 531
  • [4] The Application of Cloud Matter - element in Information Security Risk Assessment
    Dai Zong-you
    Zhang Wen-long
    Shen Yan-an
    Wang Hai-tao
    [J]. 2017 3RD INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT (ICIM 2017), 2017, : 218 - 222
  • [5] Information security risk assessment: The qualitative versus quantitative dilemma
    Munteanu, Adrian
    [J]. Managing Information in the Digital Economy: Issues & Solutions, 2006, : 227 - 232
  • [6] HOW TO CALCULATE INFORMATION VALUE FOR EFFECTIVE SECURITY RISK ASSESSMENT
    Sajko, Mario
    Rabuzin, Kornelije
    Baca, Miroslav
    [J]. JOURNAL OF INFORMATION AND ORGANIZATIONAL SCIENCES, 2006, 30 (02) : 263 - 278
  • [7] Research on the Quantitative Methods of Classified Information System Security Risk Assessment
    Zhang, Kang
    Shao, Liping
    [J]. LISS 2014, 2015, : 571 - 575
  • [8] Pollution and coronary risk: how much does it matter?
    Muscente, Francesca
    de Caterina, Raffaele
    [J]. EUROPEAN HEART JOURNAL SUPPLEMENTS, 2022, 24 : I76 - I80
  • [9] Pollution and coronary risk: how much does it matter?
    Muscente, Francesca
    de Caterina, Raffaele
    [J]. EUROPEAN HEART JOURNAL SUPPLEMENTS, 2022, 24 : I76 - I80
  • [10] Automation of Information Security Risk Assessment
    Akhmetov, Berik
    Lakhno, Valerii
    Chubaievskyi, Vitalyi
    Kaminskyi, Serhii
    Adilzhanova, Saltanat
    Ydyryshbayeva, Moldir
    [J]. INTERNATIONAL JOURNAL OF ELECTRONICS AND TELECOMMUNICATIONS, 2022, 68 (03) : 549 - +