• DocumentCode
    2669622
  • Title

    Decision support for systems security investment

  • Author

    Beresnevichiene, Yolanta ; Pym, David ; Shiu, Simon

  • Author_Institution
    Syst. Security Lab., Hewlett-Packard Labs., Bristol, UK
  • fYear
    2010
  • fDate
    19-23 April 2010
  • Firstpage
    118
  • Lastpage
    125
  • Abstract
    Information security managers with fixed budgets must invest in security measures to mitigate increasingly severe threats whilst maintaining the alignment of their systems with their organization´s business objectives. The state of the art lacks a systematic methodology to support security investment decision-making. We describe a methodology that integrates methods from multi-attribute utility evaluation and mathematical systems modelling. We illustrate our approach using a collaborative case study with the security managers of a large organization divesting itself of its IT support services. The case study was validated against the experience and observations of the security managers and delivered, according to their judgement, useful results. Specifically, by integrating a mathematical model of system behaviour with an account of the utility of available security investment strategies, the case study has enabled them to understand better the trade-offs between the security performance and the operational consequences of their choices.
  • Keywords
    business data processing; decision making; risk management; security of data; IT support service; decision support; decision-making; information security; mathematical systems modelling; multiattribute utility evaluation; operational consequence; risk management; security measures; security performance; system behaviour; system threat; systems security investment; Bridges; Collaboration; Economic forecasting; Environmental economics; Financial management; Information security; Investments; Laboratories; Mathematical model; Predictive models; Information security; decision support; economics; risk management; systems modelling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Operations and Management Symposium Workshops (NOMS Wksps), 2010 IEEE/IFIP
  • Conference_Location
    Osaka
  • Print_ISBN
    978-1-4244-6037-3
  • Type

    conf

  • DOI
    10.1109/NOMSW.2010.5486590
  • Filename
    5486590