Quantitative Model for Economic Analyses of Information Security Investment in an Enterprise Information System

被引:17
|
作者
Bojanc, Rok [1 ]
Jerman-Blazic, Borka [2 ]
机构
[1] ZZI, Pot Sejmiku 33, Ljubljana 1231, Slovenia
[2] Jozef Stefan Inst, Ljubljana 1000, Slovenia
关键词
Modelling; Security Technology; Economic metrics; Investment; Enterprise Information System;
D O I
10.2478/v10051-012-0027-z
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
The paper presents a mathematical model for the optimal security-technology investment evaluation and decision-making processes based on the quantitative analysis of security risks and digital asset assessments in an enterprise. The model makes use of the quantitative analysis of different security measures that counteract individual risks by identifying the information system processes in an enterprise and the potential threats. The model comprises the target security levels for all identified business processes and the probability of a security accident together with the possible loss the enterprise may suffer. The selection of security technology is based on the efficiency of selected security measures. Economic metrics are applied for the efficiency assessment and comparative analysis of different protection technologies. Unlike the existing models for evaluation of the security investment, the proposed model allows direct comparison and quantitative assessment of different security measures. The model allows deep analyses and computations providing quantitative assessments of different options for investments, which translate into recommendations facilitating the selection of the best solution and the decision-making thereof. The model was tested using empirical examples with data from real business environment.
引用
收藏
页码:276 / 288
页数:13
相关论文
共 50 条
  • [1] Optimal information security investment in a Healthcare Information Exchange: An economic analysis
    Huang, C. Derrick
    Behara, Ravi S.
    Goo, Jahyun
    DECISION SUPPORT SYSTEMS, 2014, 61 : 1 - 11
  • [2] Model of enterprise's information security management
    Omelchenko, Tatiana
    Umnitsyn, Mikhail
    Nikishova, Arina
    Sadovnikova, Natalia
    PROCEEDINGS OF THE IV INTERNATIONAL RESEARCH CONFERENCE INFORMATION TECHNOLOGIES IN SCIENCE, MANAGEMENT, SOCIAL SPHERE AND MEDICINE (ITSMSSM 2017), 2017, 72 : 182 - 187
  • [3] Constructiaon of Management System on the Enterprise Information Security
    Liu, Qiao-rong
    Kang, Xiao-juan
    MEMS, NANO AND SMART SYSTEMS, PTS 1-6, 2012, 403-408 : 2160 - 2163
  • [4] ENTERPRISE INFORMATION PORTAL-A TOOL TO COMBAT INSIDER ACTIVITY IN AN ENTERPRISE'S ECONOMIC SECURITY SYSTEM
    Sorbat, I. V.
    Kavun, S. V.
    FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2012, 1 (12):
  • [5] A model of return on investment for information systems security
    Al-Humaigani, M
    Dunn, DB
    Proceedings of the 46th IEEE International Midwest Symposium on Circuits & Systems, Vols 1-3, 2003, : 483 - 485
  • [6] Adaptive model of information security technique investment
    Dong, Hong
    Qiu, Wan-Hua
    Lu, Jun-Jie
    Zhang, Wen
    Kongzhi yu Juece/Control and Decision, 2008, 23 (05): : 535 - 540
  • [7] A web-enabled enterprise security management framework based on a unified model of Enterprise Information System Security
    Sengupta, A
    Mukhopadhyay, A
    Ray, K
    Roy, AG
    Aich, D
    Barik, MS
    Mazumdar, C
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2005, 3803 : 328 - 331
  • [8] Managing the investment in information security technology by use of a quantitative modeling
    Bojanc, Rok
    Jerman-Blazic, Borka
    Tekavcic, Metka
    INFORMATION PROCESSING & MANAGEMENT, 2012, 48 (06) : 1031 - 1052
  • [9] A security evaluation model and toolkit for enterprise information systems
    Yan, Q.
    FRONTIERS IN ENTERPRISE INTEGRATION, 2008, : 27 - 32
  • [10] Economic valuation for information security investment: a systematic literature review
    Daniel Schatz
    Rabih Bashroush
    Information Systems Frontiers, 2017, 19 : 1205 - 1228