An Example Collaborative Exercise for Decision Making in Investment in Cyber Security

نویسندگان

  • Jonathan Crawford
  • Kenneth Crowther
  • Barry Horowitz
  • James Lambert
چکیده

The economics of investment in cyber security is a widely researched field. This paper describes the use of a multi-player collaborative exercise implemented on computers to help companies better understand investment decisions in cyber security. The investment model driving the collaborative exercise is an expected-value decision analysis that compares the reduction of cyber risks with other investment opportunities and accounts for the potential of government regulatory action when an integrated national impact of attacks exceeds certain acceptable levels. The exercise was implemented with over twenty live participants in June 2006 at a workshop of the Institute for Information Infrastructure Protection (I3P) addressing Process Control Systems (PCS) Security. The aim of the exercise was to illustrate the impact of potential government regulation on the complex decision process of determining appropriate investment levels for added cyber security by individual companies. At the workshop the exercise provided an opportunity for knowledgeable security professionals to collaborate and compare their investment decisions against those of other similar companies and against the results of the expected value decision analysis. This paper describes the foundations of the exercise and an hypothetical interpretation, by a company that would employ the exercise, of the results from its application at the PCS workshop.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Comparing Decision Support Approaches for Cyber Security Investment

When investing in cyber security resources, information security managers have to follow effective decision-making strategies. We refer to this as the cyber security investment challenge. In this paper, we consider three possible decision-support methodologies for security managers to tackle this challenge. We consider methods based on game theory, combinatorial optimisation and a hybrid of the...

متن کامل

Decision support approaches for cyber security investment

When investing in cyber security resources, information security managers have to follow effective decision-making strategies. We refer to this as the cyber security investment challenge. In this paper, we consider three possible decision support methodologies for security managers to tackle this challenge. We consider methods based on game theory, combinatorial optimisation, and a hybrid of th...

متن کامل

Assessment of Prospective Memory, Risky Decision-Making, Collaborative Decision-Making among Individuals with Morning and Evening Circadian Typology

Introduction: Biological aspects of personality have an influence on people psychological dimensions. The present study was aimed to compare prospective memory, risky decision-making, collaborative decision-making between individuals with morning and evening circadian typology. Methods: For this purpose, a study with quantitative methodology approach and a descriptive design was conceived. T...

متن کامل

Collaborative Data Analysis and Discovery for Cyber Security

In this paper, we present the Cyber Analyst Real-Time Integrated Notebook Application (CARINA). CARINA is a collaborative investigation system that aids in decision making by co-locating the analysis environment with centralized cyber data sources, and providing next generation analysts with increased visibility to the work of others. In current generation cyber work, tools limit analyst’s abil...

متن کامل

Arithmetic Aggregation Operators for Interval-valued Intuitionistic Linguistic Variables and Application to Multi-attribute Group Decision Making

The intuitionistic linguistic set (ILS) is an extension of linguisitc variable. To overcome the drawback of using single real number to represent membership degree and non-membership degree for ILS, the concept of interval-valued intuitionistic linguistic set (IVILS) is introduced through representing the membership degree and non-membership degree with intervals for ILS in this paper. The oper...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006