Economic Security Metrics
نویسندگان
چکیده
This chapter surveys economic approaches for security metrics, among which we could identify two main areas of research. One has its roots in investment and decision theory and is mainly pursued in the field of information technology-oriented business administration. It has yielded a number of quantitative metrics that can be applied as guidelines in investment decisions as well as for the evaluation of existing security measures. The second area of research has ancestors in micro-economics. It deals with market concepts to gather security-relevant information and extract quantitative indicators on information security properties. 1 Metrics for Security Investments The previous chapter has demonstrated that it is essential to measure organisations’ security at different levels of detail. This also applies to the investment perspective. In the recent years, organisations see an increasing demand for determining the cost and benefit of IT security investments. Possible reasons include compliance with regulatory requirements, emerging information security threats, or increased dependence of business processes on information technology. Apart from definitions for metrics, this section will show the motivations behind metrics as well as challenges in quantifying the value of IT security investments.
منابع مشابه
Communicating the Economic Value of Security Investments; Value at Security Risk
The information and data security communities and their individual practitioners have long experienced the pedagogical difficulties in communicating to management or funding bodies the importance and relevance of sufficient investments in information and data security. Inside these communities there is almost universal agreement that companies under invest in security. One reason for this pedag...
متن کاملThe Price of Uncertainty in Security Games
In the realm of information security, lack of information about other users’ incentives in a network can lead to inefficient security choices and reductions in individuals’ payoffs. We propose, contrast and compare three metrics for measuring the price of uncertainty due to the departure from the payoffoptimal security outcomes under complete information. Per the analogy with other efficiency m...
متن کاملDrivers Metrics and Best Practices for Information Security
Information security is one of the top problems of business executive and information system managers alike. Pervasive use of information technology in all aspects of business today as well as highlighted need for regulatory compliance calls for analysis of information systems in their entirety – going beyond technical aspects and considering people and organizations as well. In my dissertation...
متن کاملNetwork Topology Vulnerability/Cost Trade-Off: Model, Application, and Computational Complexity
Technological networks (e.g. telephone and sensor networks, Internet) have provided modern society with increased efficiency, but have also exposed us to the risks posed by their vulnerability to attacks. Mitigating these risks involves designing robust network topologies in situations where resources are economically constrained. In this paper, we consider the vulnerability of network topologi...
متن کاملA unifying process capability metric
A new economic approach to process capability assessment is presented, which differs from the commonly used engineering metrics. The proposed metric consists of two economic capability measures – the expected profit and the variation in profit of the process. This dual economic metric offers a number of significant advantages over other engineering or economic metrics used in process capability...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005