Quantitative Model for Economic Analyses of Information Security Investment in an Enterprise Information System

被引:17
|
作者
Bojanc, Rok [1 ]
Jerman-Blazic, Borka [2 ]
机构
[1] ZZI, Pot Sejmiku 33, Ljubljana 1231, Slovenia
[2] Jozef Stefan Inst, Ljubljana 1000, Slovenia
关键词
Modelling; Security Technology; Economic metrics; Investment; Enterprise Information System;
D O I
10.2478/v10051-012-0027-z
中图分类号
C93 [管理学];
学科分类号
12 ; 1201 ; 1202 ; 120202 ;
摘要
The paper presents a mathematical model for the optimal security-technology investment evaluation and decision-making processes based on the quantitative analysis of security risks and digital asset assessments in an enterprise. The model makes use of the quantitative analysis of different security measures that counteract individual risks by identifying the information system processes in an enterprise and the potential threats. The model comprises the target security levels for all identified business processes and the probability of a security accident together with the possible loss the enterprise may suffer. The selection of security technology is based on the efficiency of selected security measures. Economic metrics are applied for the efficiency assessment and comparative analysis of different protection technologies. Unlike the existing models for evaluation of the security investment, the proposed model allows direct comparison and quantitative assessment of different security measures. The model allows deep analyses and computations providing quantitative assessments of different options for investments, which translate into recommendations facilitating the selection of the best solution and the decision-making thereof. The model was tested using empirical examples with data from real business environment.
引用
收藏
页码:276 / 288
页数:13
相关论文
共 50 条
  • [21] Enterprise Information System Design Using REA Enterprise Model
    Sevcik, Jaroslav
    Melis, Zdenek
    Zacek, Jaroslav
    Hunka, Frantisek
    STRATEGIC MANAGEMENT AND ITS SUPPORT BY INFORMATION SYSTEMS, 9TH INTERNATIONAL CONFERENCE, 2011, : 179 - 191
  • [22] Towards a formal specification method for enterprise information system security
    Sengupta, Anirban
    Barik, Mridul Sankar
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2006, 4332 : 373 - +
  • [23] Application of information leakage defendable model in enterprise intranet security
    School of Computer Information and Technology, Beijing Jiaotong University, Beijing 100044, China
    不详
    Jisuanji Yanjiu yu Fazhan, 2007, 5 (761-767):
  • [24] Optimal Information Security Investment Analyses with the Consideration of the Benefits of Investment and Using Evolutionary Game Theory
    Wang, Qin
    Zhu, Jianming
    PROCEEDINGS OF 2016 2ND INTERNATIONAL CONFERENCE ON INFORMATION MANAGEMENT (ICIM2016), 2016,
  • [25] An economic analysis of information security investment decision making for substitutable enterprises
    Li, Xiaotong
    Xue, Qianyao
    MANAGERIAL AND DECISION ECONOMICS, 2021, 42 (05) : 1306 - 1316
  • [26] After Information Security - Before a Paradigm Change (A Complex Enterprise Security Model)
    Michelberger, Pal, Jr.
    Labodi, Csaba
    ACTA POLYTECHNICA HUNGARICA, 2012, 9 (04) : 101 - 116
  • [27] Information Theory and Security: Quantitative Information Flow
    Malacaria, Pasquale
    Heusser, Jonathan
    FORMAL METHODS FOR QUANTITATIVE ASPECTS OF PROGRAMMING LANGUAGES, 2010, 6154 : 87 - 134
  • [28] Research on information security model and security system design
    Huang, Yi-Min
    Ping, Ling-Di
    Pan, Xue-Zeng
    Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science), 2001, 35 (06): : 603 - 607
  • [29] A model of the information security investment decision-making process
    Dor, Daniel
    Elovici, Yuual
    COMPUTERS & SECURITY, 2016, 63 : 1 - 13
  • [30] The dynamic analysis of investment information security using System Dynamics
    Kong, Hee-kyung
    Kim, Jong-Tae
    Proceedings of the 2005 Conference of System Dynamics and Management Science, Vol 1: SUSTAINABLE DEVELOPMENT OF ASIA PACIFIC, 2005, : 420 - 425