DocumentCode :
1583405
Title :
Towards the Optimal Security Level: Quantification of Risks in Service-Based Information Systems
Author :
Ackermann, Tobias ; Widjaja, Thomas ; Buxmann, Peter
fYear :
2013
Firstpage :
3038
Lastpage :
3047
Abstract :
The increasing frequency and total cost of security incidents require organizations to apply proper IS risk management in order to assess the economically reasonable usage of security measures. In this paper, we contribute a model that supports risk-related investment decisions in service-based information systems. The model supports decision makers in analyzing the cost-benefit trade off related to security measures by solving the key problem of efficiently calculating the probability density function of the potential losses for a given information system. Based on the proposed model, it is possible to derive individual metrics, such as the Value at Risk, that can be used to choose the optimal security level, i.e., the most economically reasonable combination of security measures. Furthermore, we demonstrate the model´s application in the context of an existing real life e commerce system by evaluating and comparing two alternative security investments for this business process.
Keywords :
Data transfer; Investment; Loss measurement; Probability density function; Security; Decision support; IS risk management; Investment evaluation; Risk quantification; Service-based information systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
System Sciences (HICSS), 2013 46th Hawaii International Conference on
Conference_Location :
Wailea, HI, USA
ISSN :
1530-1605
Print_ISBN :
978-1-4673-5933-7
Electronic_ISBN :
1530-1605
Type :
conf
DOI :
10.1109/HICSS.2013.569
Filename :
6480209
Link To Document :
بازگشت