Quantitative Model for Economic Analyses of Information Security Investment in an Enterprise Information System

Author:

Bojanc Rok,Jerman-Blažič Borka

Abstract

AbstractThe paper presents a mathematical model for the optimal security-technology investment evaluation and decision-making processes based on the quantitative analysis of security risks and digital asset assessments in an enterprise. The model makes use of the quantitative analysis of different security measures that counteract individual risks by identifying the information system processes in an enterprise and the potential threats. The model comprises the target security levels for all identified business processes and the probability of a security accident together with the possible loss the enterprise may suffer. The selection of security technology is based on the efficiency of selected security measures. Economic metrics are applied for the efficiency assessment and comparative analysis of different protection technologies. Unlike the existing models for evaluation of the security investment, the proposed model allows direct comparison and quantitative assessment of different security measures. The model allows deep analyses and computations providing quantitative assessments of different options for investments, which translate into recommendations facilitating the selection of the best solution and the decision-making thereof. The model was tested using empirical examples with data from real business environment.

Publisher

Walter de Gruyter GmbH

Subject

Marketing,Organizational Behavior and Human Resource Management,Strategy and Management,Tourism, Leisure and Hospitality Management,Business and International Management,Management Information Systems

Reference50 articles.

1. Is there a cost to privacy breaches An event study In Workshop on the Economicsof UK Retrieved from http www heinz cmu edu acquisti papers acquistifriedman telang privacy breaches pdf;Acquisti;Information Security October,2006

2. Institute Crime Survey The th Crime Survey Retrieved th from http www gocsi com survey;January;Computer Security Computer Security Annual Computer Security,2011

3. An Empirical Analysis of Security Investment in Countermeasures Based on an Enterprise Survey in Japan In : Workshop on the Economics of InformationSecurity Cambridge Retrieved from http econinfosec org docs;Tanaka;October,2006

4. Productivity Space of Information Security in an Extension of the s Investment Model In Managing Information Risk and the Economics of US http dx doi org;Matsuura;Security,2009

5. of IT Management In of InformationSecurity US http dx org;Cavusoglu;Economics Security Economics,2004

Cited by 15 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3