An Insurance Style Model for Determining the Appropriate Investment Level against Maximum Loss arising from an Information Security Breach
نویسنده
چکیده
The economic consequences of breaches in information security cannot be underestimated. According to the World Bank 2002 survey on reported cyber crime the US$ value of the effects from intrusions from a variety of sources has been increasing at an accelerating rate over the past decade. This survey contains a list of reported intrusions recording criminal and employee abuse with losses ranging from several thousand dollars to many million dollars and the victims of these security breaches are in the main players belonging to the global financial service industries. The KPMG 2002 Global Security Survey covering major international firms reported that the average expenditure on information security represented approximately 10% of the total spend on IT and that the level was expected to rise in the future. The average cost of a breach in information security was estimated at just over $100 thousand. It concludes that reporting procedures concerning hostile intrusions into the information bank were in several cases crude and the methods for formally measuring the economic consequences of breaches lacked the sophistication to provide guidance of any value. The Deloitte Touche Tohmatsu 2003 Global Security Survey makes similar conclusions. It points out that although there is a greater awareness on the increased sophistication of attacks on computer information and encouraging trends for financial institutions to treat information security seriously, greater all-round effort is still required on all aspects of information security.
منابع مشابه
Economics of Information Security Investment in the Case of Simultaneous Attacks
With billions of dollars being spent on information security related products and services each year, the economics of information security investment has become an important area of research, with significant implications for management practices. Drawing on recent studies that examine optimal security investment levels under various attack scenarios, we propose an economic model that consider...
متن کاملA new Stochastic Hybrid Technique for DER Problem
This paper presents a new Hybrid Particle Swarm optimization with Time Varying Acceleration Coefficients (HPSOTVAC) and Bacteria Foraging Algorithm (BFA) namely (PSOTVAC/BFA) base fuzzy stochastic long term approach for determining optimum location and size of Distributed Energy Resources (DERs). The Monte Carlo simulation method is used to model the uncertainties associated with long-term load...
متن کاملA new Stochastic Hybrid Technique for DER Problem
This paper presents a new Hybrid Particle Swarm optimization with Time Varying Acceleration Coefficients (HPSOTVAC) and Bacteria Foraging Algorithm (BFA) namely (PSOTVAC/BFA) base fuzzy stochastic long term approach for determining optimum location and size of Distributed Energy Resources (DERs). The Monte Carlo simulation method is used to model the uncertainties associated with long-term load...
متن کاملFarmers’ Perception and Management of Natural Hazards in Production and Security of Farm Investment in Isuikwuato, Abia State, Nigeria
This study on farmers’ perception and management of natural hazards in production and security of farm investment was carried out in Isuikwuato Local Government Area of Abia State, Nigeria. The study was sought to identify farmers’ perceived natural hazards in food production; identify adopted measures used in mitigating impacts of the hazards and determined factors that influenced farmers from...
متن کاملInformation Security Investment: Expected Utility Approach with Correlated Information Assets
This paper analyzes the information security investment decisions by a firm with two correlated information assets. When information assets are correlated, a firm may face additional losses compared to a loss from a single breach, and the probability of security breach on one set may increase the probability on the other. We model the security investment of a risk-taking firm as well as risk-ne...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2004