Title :
Process-Oriented Approach for Validating Asset Value for Evaluating Information Security Risk
Author :
Cha, Shi-Cho ; Liu, Li-Ting ; Yu, Bo-Chen
Author_Institution :
Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
Abstract :
To provide a systematic means of identifying and assessing information security risks, organizations typically adopt asset-driven (or asset-oriented) risk assessment schemes. These schemes require organizations to identify their information assets, find out potential incidents to those assets, and assess expected losses associated with those incidents. While asset value is important in determining loss expectancies for associated incidents, the accuracy of asset valuation is crucial. Although numerous guidelines exist regarding how best to evaluate asset value, current risk assessment schemes generally overlook how to validate assessments of asset value. Consequently, this work presents a process-oriented approach that organizations can employ to validate and adjust asset value. The approach presented in this study can help organizations represent their business processes and information assets used in those processes using flowcharts, and also mark dependencies among assets based on confidentiality, integrity, and availability requirements on flowcharts. Organizations can use the markings of dependencies to validate and correct results associated with asset valuation. If organizations can more accurately evaluate asset value, they can improve the effectiveness of their risk assessment. Therefore, the approach presented in this study can hopefully help improve organizational information security.
Keywords :
data integrity; flowcharting; formal specification; risk management; security of data; asset-driven information security risk assessment; asset-oriented risk assessment scheme; business process; data availability requirements; data confidentiality requirements; data integrity requirements; dependency marking; flow chart; information asset value validation; information security risk identification; information security risk management process; loss expectancy; organizational information security risk evaluation; potential incident; process-oriented approach; Availability; Cost accounting; Flowcharts; Guidelines; ISO standards; Information security; Management information systems; Performance evaluation; Risk management; Standards organizations; Information Asset Valuation; Risk Assessment; Risk Management;
Conference_Titel :
Computational Science and Engineering, 2009. CSE '09. International Conference on
Conference_Location :
Vancouver, BC
Print_ISBN :
978-1-4244-5334-4
Electronic_ISBN :
978-0-7695-3823-5
DOI :
10.1109/CSE.2009.217