Title :
Information security metric integrating enterprise objectives
Author :
Karabey, Bugra ; Baykal, Nazife
Author_Institution :
Inf. Inst., Middle East Tech. Univ., Ankara, Turkey
Abstract :
Security is one of the key concerns in the domain of information technology systems. Maintaining the confidentiality, integrity and availability of such systems, mandates a rigorous prior analysis of the security risks that confront these systems. In order to analyze, mitigate and recover from these risks a metrics based approach is essential in prioritizing the response strategies against these risks. In addition to that the enterprise objectives must be focally integrated in the definition, impact calculation and prioritization phases of this analysis to come up with metrics that are useful both for the technical and managerial communities within an organization. Also the inclusion of enterprise objectives in the identification of information assets will act as a preliminary filter to overcome the real life scalability issues inherent with such threat modeling efforts. Within this study an attack tree based approach will be utilized to offer an information security risk metric that integrates the enterprise objectives with the information asset vulnerabilities within an organization. In the essential step of enterprise resource identification, the resource-based view of a company will be utilized.
Keywords :
information technology; risk analysis; security of data; enterprise objective; information security metric; information technology system; risk metric; Availability; Companies; Information filtering; Information filters; Information management; Information security; Information technology; Risk analysis; Risk management; Scalability; Information security; attack trees; enterprise objectives; resource based view; risk metrics;
Conference_Titel :
Security Technology, 2009. 43rd Annual 2009 International Carnahan Conference on
Conference_Location :
Zurich
Print_ISBN :
978-1-4244-4169-3
Electronic_ISBN :
978-1-4244-4170-9
DOI :
10.1109/CCST.2009.5335549